Incident response · Professional services
Incident Response Planning for Law Firms
An incident response plan tells your firm exactly who acts, who is called and what is documented in the first hours after ransomware, a fraudulent wire or a stolen laptop. Law firms need their own version because the notification stack is unlike any other business: insurer, law society, privacy regulators, clients and sometimes opposing parties, in the right order. We build the plan around your matters, systems and provinces, then keep it current as the rules move.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What a law firm's incident plan has to cover
A generic template collapses on contact with privilege and trust accounting. The plan we draft is organized around the four things a compromised firm must protect at once.
Privilege during the response
Deciding what to tell clients, courts and opposing counsel about a breach is itself a matter of professional judgment. The plan defines who makes those calls and how external responders are engaged without widening disclosure.
Trust funds mid-flight
Closings do not pause for an incident. Runbooks cover freezing disbursements, verifying pending wires by phone and contacting the trust account's bank within minutes rather than days.
The systems that run the practice
Isolation steps are written for your actual stack: the practice-management platform, the DMS, email, accounting and whatever your MSP administers, with after-hours contacts for each.
The record of the incident
Regulators expect documentation, and PIPEDA requires keeping records of every breach of safeguards for two years. The plan builds the log as you respond instead of reconstructing it afterwards.
Regulatory map
The law-firm notification stack, mapped in advance
Which duties fire depends on where the firm practises and whose information was hit. The plan encodes each obligation with its trigger and deadline, so nobody is researching statutes at midnight.
LSO steps in Ontario
The Law Society of Ontario's cybersecurity checklist directs firms to isolate systems, notify the insurer, report risk to client property or confidentiality by submitting a complaint in LSO Connects, and promptly notify affected clients.
PIPEDA breach reporting
Where a breach creates a real risk of significant harm, the firm reports to the OPC and notifies affected individuals as soon as feasible, and it remains accountable when the breach happened at a service provider.
Quebec's register and the CAI
Confidentiality incidents go to the CAI and affected persons where there is a risk of serious injury, and the firm keeps an incident register for at least five years. A Montreal office puts these duties in scope.
Alberta's PIPA s.34.1
Alberta requires reporting to the OIPC without unreasonable delay where a real risk of significant harm exists, a distinct clock from the federal one that Calgary and Edmonton offices must track.
BC's different baseline
BC PIPA currently imposes no statutory breach-notification duty, but LSBC record-security rules, client contracts and insurer conditions still demand a documented response. The plan reflects that asymmetry honestly.
What goes wrong
The incidents this plan is rehearsed against
We draft runbooks for the scenarios that actually hit Canadian practices, not hypothetical nation-state drama.
Extortion aimed at your clients
At MBC Law in Ottawa, the intruder emailed clients, other lawyers and opposing parties two weeks after detection to force payment, and recovery to full function took about four weeks. The plan assumes the attacker will talk to your clients before you do.
A wire out of trust
Redirected closing funds are usually discovered when the real payee calls asking where the money is. The runbook front-loads bank recall, insurer notice and fraud-centre reporting because every hour narrows recovery.
A device gone from a car or courtroom
A lost laptop or phone triggers a fast fork: encrypted and remotely wiped means containment; unencrypted means notification analysis begins immediately. The plan scripts both branches.
Your vendor's breach, your duty
The MOVEit file-transfer compromise reached client files held by major professional-services firms. When your DMS or transfer vendor is hit, your plan, not theirs, governs what clients and regulators hear from you.
Our incident response for law firms
What the incident response planning engagement delivers
This is a policy-development engagement with teeth: documents your people can execute under stress, tailored to the firm rather than adapted from a corporate template.

The core plan
Roles, escalation thresholds, decision authority and communication rules for the managing partner, administrator, MSP and external counsel, in a format short enough to use during an outage.
A notification matrix by province
Every obligation, from LAWPRO or ALIA and the law society through the OPC, CAI and OIPCs to clients and courts, with its trigger, deadline and owner on one page.
Scenario runbooks
Step-by-step sequences for ransomware, business email compromise, trust wire fraud, lost devices and vendor breaches, each ending in the documentation the regulators expect.
Vendor and MSP coordination
Contact paths, contractual notice obligations and evidence-preservation requests for the practice-management, DMS and IT providers who will be inside the response.
A working session and updates
We walk the named responders through the plan against a realistic scenario, then revise the documents as laws, systems and staff change so the plan stays executable.
How the engagement runs
Building the plan with your firm
Step 1
Inventory scenarios and obligations
We map your offices, practice areas, systems and vendors to the specific regulators, insurers and law societies that would be involved in each incident type.
Step 2
Draft with the responders
The plan and runbooks are written with the administrator, MSP and a designated partner, so the steps match how the firm genuinely operates after hours.
Step 3
Walk it through
A tabletop-style session runs the team through a trust-fraud or ransomware scenario and exposes gaps in contacts, authority and timing before reality does.
Step 4
Maintain it
Annual refreshes, plus updates when you add an office, change MSPs or when notification law shifts, keep the plan from becoming shelf-ware.
What it costs
Pricing an incident response plan for a firm
Effort depends on how many provinces you practise in, how many systems and vendors sit in scope, whether trust volume justifies a dedicated wire-fraud runbook, and whether you want the facilitated walkthrough included. A single-office Ontario boutique is a compact project; a firm with Toronto, Calgary and Montreal offices carries three regulators' worth of mapping.
Firms on the Virtual Privacy Office retainer already receive an incident management protocol as part of the monthly service, so ask us which route fits before commissioning a standalone plan. A short scoping call is enough to price the work.
Law Firms: Incident response questions, answered
Containment comes before any call: isolate affected systems so the damage stops growing. The insurer is typically the first external contact, because coverage decisions and approved breach counsel flow from that call, and LAWPRO's cybercrime coverage has its own conditions. Law society reporting, in Ontario through LSO Connects where client property or confidentiality is at risk, and OPC or provincial reporting where harm thresholds are met, follow in the sequence the plan lays out. The point of planning is that this ordering is decided calmly, in advance.
Possibly, and the Ottawa extortion case shows why it matters: the attacker contacted opposing parties directly, so silence handed the narrative to a criminal. Whether formal notice is owed depends on whose personal information was compromised and which statutes apply, while professional courtesy and litigation strategy add their own weight. The plan pre-builds the analysis: what was in the mailboxes, who is identifiable, which duties attach, and who in the firm decides what is said to whom.
It turns on what was on the device and how it was protected. Full-disk encryption with a prompt remote wipe often means no real risk of significant harm, which changes the analysis under PIPEDA and Alberta PIPA; an unencrypted laptop holding matter files pushes toward regulator reports, client notification and, in Ontario, the checklist's law society step. Either way the incident is documented, kept in the two-year PIPEDA record and, for Quebec practices, entered in the five-year register.
Speed decides the outcome. The runbook starts with the receiving and sending banks for a recall attempt, then police and the Canadian Anti-Fraud Centre, then the insurer, since cybercrime coverage and its $250,000 sublimit come into play. From there the firm addresses clients whose funds were touched, its law society obligations around the trust account, and the email compromise that usually enabled the fraud. Everything is timestamped, because recovery and coverage both depend on the record.
Yes, and for a SaaS-dependent firm this is essential. Under PIPEDA your firm stays accountable for personal information a processor loses, so the plan includes each key vendor's breach contacts, the notice clauses in their contracts, what evidence to demand, and how to communicate with clients while a provider controls the facts. It also covers the awkward scenario where the MSP itself is compromised and cannot be trusted as the response channel.
More for law firms
Other services for this niche
About this service
Answers & guides
- Do you need an incident response plan, and what should it include?
- What should I do after a data breach?
- When should you hire a privacy breach response consultant?
- Writing an Incident Response Plan Your Team Will Actually Use
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- PIPEDA Breach Notification and Record-Keeping: What to Get Right
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.