Skip to main content
Industry · Legal Firms

IT support for Brisbane law firms — privilege, trust accounts and court deadlines

Managed IT and cybersecurity for Australian legal practices, built around the things that actually bite: client legal privilege, trust account controls, matter-centric documents and a filing deadline that does not move because your server is down.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

What we hear from legal firms

The IT problems specific to your sector

A deadline that does not negotiate

Court filing deadlines and limitation periods do not extend because your systems were down. Uptime in a legal practice has a direct professional-liability dimension that most industries do not carry.

Client legal privilege as a security requirement

Privileged material demands controls that go beyond ordinary confidentiality. Who can access which matter, whether that access is logged, and whether a breach would be defensible all become questions with professional consequences.

Trust account exposure

Trust accounts make law firms a specific target for payment redirection fraud. A settlement figure altered in an email is the single highest-loss scenario in the profession and it is an email security problem, not an accounting one.

Matter-centric documents, not folders

Legal work organises around matters, not departments. A generic file structure fights the way the firm actually works and produces documents nobody can find under time pressure.

Conflicts, ethical walls and access separation

Some matters require staff to be genuinely unable to see them. That is a technical access control problem, and most small-firm systems cannot demonstrate it was enforced.

Long retention with real consequences

Files retained for years after a matter closes, in a form that remains readable and produceable. Storage is the easy part; being able to find and produce it is not.

Most industries lose money when IT fails. Law firms can lose a matter.

A filing deadline that passes, a limitation period missed, a settlement that does not complete — these are not operational inconveniences, they carry professional and liability consequences. That changes what “acceptable downtime” means, and it is the reason a legal practice should not be running the same recovery objectives as a business where a lost afternoon is just a lost afternoon.

The settlement fraud problem

If a Brisbane law firm reads one section of this page, this is the one.

Payment redirection around settlement is the highest-loss attack against the profession, and it works because nothing about it looks wrong. The attacker compromises a mailbox — frequently the client’s or the other side’s rather than yours — reads a genuine conveyancing thread, waits for the moment settlement figures are exchanged, and sends revised account details from a real address in a real conversation.

The money moves because a competent person followed what appeared to be legitimate instructions.

Three controls address it, and none are exotic. Verify account details by voice against a number you obtained independently, never one from the email. Enforce MFA so mailbox compromise is harder. Alert on inbox rule creation, because a hidden forwarding rule is the tell that a mailbox is already compromised.

Documents organised around matters

Legal work is matter-centric and most generic file structures are not. A firm forced to file matter documents into a departmental folder tree ends up with material scattered, duplicated and hard to produce.

Whether that structure lives in your practice management system or in SharePoint depends on the platform, but the principle is the same: the structure should match how the firm thinks, and the permissions should follow the matter.

That also makes ethical walls implementable. If access is granted at matter level through groups, separating a conflicted matter is a configuration change that can be evidenced. If access is granted ad hoc file by file, it cannot.

Practice management platforms

LEAP, Actionstep and Smokeball are cloud-hosted, which means the IT work around them is identity, integration, document handling and the environment they run in rather than server administration.

That is a better division than it used to be. It does mean the security questions move to your Microsoft 365 tenant and your access control, which is where we focus.

Retention that stays produceable

Long retention is straightforward as a storage problem and awkward as a findability problem. Material kept for seven years in a structure nobody maintained, in formats that have moved on, with the person who filed it long gone, is technically retained and practically lost.

Deciding retention deliberately — by matter type, against your actual obligations — and keeping the structure intact is what makes production possible when it is eventually requested.

Legal Firms IT support FAQs

What is the biggest cyber risk to a law firm?

Payment redirection around settlement, without much competition. The pattern is consistent: an attacker compromises a mailbox — often at the other side's firm or the client's, not yours — watches a genuine conveyancing or settlement conversation, and sends revised account details at exactly the right moment. The amounts are large, the payment is authorised by a person who believed they were following instructions, and recovery is rare. The defences are practical: verify account details by phone against an independently obtained number, enforce MFA, alert on mailbox rule creation, and train staff on the specific pattern rather than phishing in general.

Can you support LEAP, Actionstep or Smokeball?

Yes. These are cloud-hosted practice management platforms, so the IT work is identity, access control, integration with Microsoft 365 and document handling rather than running the application. We handle the environment they sit in, and where a deep configuration question is genuinely for the vendor we will say so and coordinate rather than guess on your time.

How should a law firm handle document retention?

Deliberately, with a policy that reflects your professional obligations and the matter types you run rather than a default. The two failure modes are keeping nothing long enough and keeping everything forever — the second increases what is exposed in a breach and what is discoverable. What matters technically is that retained material remains findable and produceable years later, which is a structure and metadata problem more than a storage one.

Do we need ethical walls implemented in our systems?

If you run matters where a conflict requires separation, then yes, and it needs to be enforced technically rather than by policy alone. Access restricted at the document management level, logged, and demonstrable. A firm that cannot show who could access a matter is in a difficult position if the question is ever asked formally.

Is cloud storage appropriate for privileged material?

Yes, when configured properly — and in most cases it is more secure than a server in a cupboard that nobody patches. What matters is the configuration: enforced MFA, conditional access, appropriate data residency, access logging, and knowing where the data physically sits. Microsoft 365 tenants can be provisioned with Australian data residency, which addresses the question most often raised by clients and insurers.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote