The firm’s hard drive was stolen from its IT provider’s vehicle.
Missing control: Nothing recorded — including whether the drive was encrypted
Source: Decision P2020-ND-137
You hold privileged client files, trust-account details and matters that would be devastating in the wrong hands — without a security team of your own. That is the gap we fill.
A staff mailbox at an Alberta real-estate practice was quietly set to forward every incoming message somewhere else. It ran for six weeks. The attacker was reading property files — addresses, purchase prices, mortgage amounts, a client's voided cheque — and the firm only found out when a scam email arrived asking it to deposit funds. 181 people had to be told.
Read the regulator’s decision — and what the firm only found out six weeks in →
Missing control: Nothing recorded — including whether the drive was encrypted
Source: Decision P2020-ND-137
Missing control: Nothing stopping the firm’s own address being used, and no way to notice it
Source: Decision P2020-ND-033
Missing control: Nothing watching for a mail-forwarding rule on a staff account
Source: Decision P2021-ND-027
Anyone on the internet can send an email that looks exactly like it came from the managing partner — 73% of Canadian law firms with a website publish nothing that tells a receiving mail server to refuse it. And the question is coming from the other side too — the association of in-house counsel publishes a ready-made security schedule for its members to impose on the firms they retain, with a 24-hour breach-reporting window.
It is one of the first things the free Snapshot checks — from the outside, nothing to install.
See what we’d find on your domain — get the free Security Snapshot →
The rulebook below says what you owe. It does not say what to have. Your insurer does — in writing, on the form you fill in before it will quote you. These four come up on every one of them, and putting them in and keeping them there is most of what the retainer is.
Not offered — enforced, and separately on each of email, remote access and privileged accounts. It is the first control on the Canadian questionnaire and the one an insurer is most likely to check after a claim.
An Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. The rollout had started; it had not finished.
At least weekly, covering all sensitive or business-critical data, and held where an intruder inside your network cannot reach them. A backup nobody has restored from is an assumption, not a control.
Anything reachable from outside — the mail service, the remote-access gateway, the portal — carries known, published weaknesses within days of their disclosure. Insurers ask whether you actively manage and install critical patches across those systems.
Who is called, in what order, with what authority to disconnect something. Written down and rehearsed before the morning you need it, not drafted during it.
And the one no form asks about: knowing it happened at all. Most of the duties below start running when you find out — and in almost every case we document, no system caught the intruder; the firm learned of it from someone else, weeks or months later. Cases →
Law Society of Ontario · LawPRO
If your retainer does not meet three conditions, a social-engineering claim is capped at $250,000 instead of $1 million.
| The rule | Who it binds | If you don’t | Source |
|---|---|---|---|
| The sublimit, and the condition attached to it | Every Ontario lawyer in private practice | $250,000 per claim instead of $1,000,000 | LAWPRO 2026 Policy Book, Part III (k) |
| Condition (i) — tell clients in writing, and give them a number to call | The firm, in its written retainer | Missing it drops the limit to $250,000 | LAWPRO 2026 Policy Book, Part III (k)(i) |
| Condition (ii) — verify changes out of band | The firm and its staff, on every change request | Missing it drops the limit to $250,000 | LAWPRO 2026 Policy Book, Part III (k)(ii) |
| Condition (iii) — keep the record in writing | The firm | Missing it drops the limit to $250,000 | LAWPRO 2026 Policy Book, Part III (k)(iii) |
| And it is not only about money | Interpretation of the whole sublimit | The cap can apply to a data or credential disclosure, not just a wire | LAWPRO 2026 Policy Book, Part V (Definitions) |
| Report a breach that could seriously harm someone | Every organisation subject to PIPEDA | Knowingly failing to report is an offence under PIPEDA s.28 — a fine of up to $10,000 on summary conviction, or up to $100,000 as an indictable offence. The same section covers the record duty below. | PIPEDA s.10.1(1) — report to Commissioner |
| Notify the people affected | Every organisation subject to PIPEDA | The duty is separate from reporting to the regulator, and it applies whether one person is affected or a thousand. | Privacy Commissioner of Canada |
| Keep a record of EVERY breach for two years | Every organisation subject to PIPEDA | Most firms keep none. It applies whether or not anything was ever reportable, so a regulator’s request finds a gap that cannot be filled retroactively — and knowingly contravening it is the same s.28 offence. | Breach of Security Safeguards Regulations, s. 6(1) |
| Make those records good enough to audit | Every organisation subject to PIPEDA | A record that does not show how you assessed the risk does not discharge the duty — the regulator has to be able to check your reasoning, not just see a log entry. | Privacy Commissioner of Canada |
| Satisfy your insurer before you need to claim | Any firm that wants cyber cover | A condition you have not met is a claim your policy may refuse — an Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. | Coalition Insurance Solutions Canada — cyber questionnaire |
| Answer your client’s regulator, not just your own | Any firm holding a federally regulated client’s data | A firm that cannot answer a third-party risk assessment is a firm its regulated clients now have to explain — which is a procurement problem long before it is a security problem. | OSFI — Guideline B-10, Third-Party Risk Management (in force 1 May 2024) |
other than to provide an INSURED with a SUBLIMIT OF LIABILITY of $250,000 per CLAIM and in the aggregate per POLICY PERIOD … for any CLAIM in any way related to or arising out of SOCIAL ENGINEERING, unless the INSURED: …
LAWPRO 2026 Policy Book, Part III (k)
Most of these start running the moment you find out — which is the whole reason the date you notice matters as much as the breach itself. The rest are conditions you meet beforehand: what your insurer asks before it will quote you, and what your regulated clients are now required to verify about you.
These three conditions are retainer drafting and verification discipline — they are not technical controls, and meeting them is work for the firm and its lawyers rather than for us. We publish them because a $750,000 swing in your own coverage is worth knowing about, whoever closes it.
No cost, no obligation — you keep the findings either way.
One short form. No access to your systems, no software to install.
Passive, publicly observable checks only — the same view an attacker gets.
Your top findings in plain English — one page, no meeting required.