CRYPTON practical guides

Law firm IT guide

Ten practical questions about matter access, payment changes, email, devices and recovery.

Use these checks with your current IT provider. This guide is a starting point, not an audit or confirmation that your systems are secure.

Do not enter client names, matter details or confidential information.

Make my checklist

1. Changed bank details

payment redirection can look like normal matter correspondence until money has already moved.

Check: Confirm that no one can approve changed bank details from an email thread alone.

Ask your IT provider: Ask for the written release-of-funds process showing the known-number call-back and second approval.

2. Deadline access

deadline pressure is when people are most likely to use unmanaged copies, personal devices, or risky workarounds.

Check: Document the fallback path for urgent filing, settlement, or client-deadline work.

Ask your IT provider: Ask IT to demonstrate access to current email and matter documents from a second managed device.

3. Leaver access

disabling the main account does not confirm that synced files, sessions or personal devices have been cleaned up.

Check: Add personal-device and synced-data checks to the offboarding checklist.

Ask your IT provider: Ask for a recent leaver record showing account disablement, session revocation, device review, and app access removal.

4. Mailbox compromise

an overseas sign-in or forwarding rule can expose client instructions before anyone sees obvious symptoms.

Check: Confirm who monitors alerts for partners, finance, trust accounts and administrators.

Ask your IT provider: Ask who receives overseas sign-in, forwarding-rule, and risky-mailbox alerts, and what the response target is.

5. Restore confidence

a backup is only useful if the practice knows it can restore the right data quickly enough.

Check: Run a controlled restore test for one mailbox and one matter-data location.

Ask your IT provider: Ask for the last restore-test date, what was restored, and how long it took.

6. Admin safeguards

trusted admin access still needs limits, logging, and review because admin misuse or compromise has broad impact.

Check: Review admin accounts with the provider and remove access that is no longer needed.

Ask your IT provider: Ask for the current administrator list, MFA status, separate administrator accounts and security log retention.

7. Devices with client data

lost, stolen, and personal devices can keep client documents outside the systems everyone thinks are protected.

Check: Close any gap between firm-managed devices and personal-device access.

Ask your IT provider: Ask for device encryption, remote-wipe coverage, and whether personal devices can sync client documents.

8. AI use

AI can improve drafting, summaries, research, and admin work, but staff need clear boundaries for client and matter information.

Check: Define two or three useful AI uses and the information that must not be entered.

Ask your IT provider: Ask for the approved AI tools, allowed use cases, and data rules given to staff.

9. Security alert handling

assuming the provider sees every alert is risky unless alerts, ownership, and response times are documented.

Check: Confirm which Microsoft 365 and device-security alerts are enabled and reported.

Ask your IT provider: Ask for the alert list, who receives each alert, and the last monthly security summary or ticket sample.

10. Urgent support

urgent matter work needs a defined support path if the normal response is too slow.

Check: Agree what counts as urgent and who takes over when matter work is blocked.

Ask your IT provider: Ask what counts as urgent, who to contact and the target response time for practice-blocking issues.

Talk to CRYPTON

Tell us where IT gets in the way of your work. We can discuss the findings and a sensible next step.

Request this guide by email