Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Incident response · Professional services

Incident Response Planning for Law Firms

An incident response plan tells your firm exactly who acts, who is called and what is documented in the first hours after ransomware, a fraudulent wire or a stolen laptop. Law firms need their own version because the notification stack is unlike any other business: insurer, law society, privacy regulators, clients and sometimes opposing parties, in the right order. We build the plan around your matters, systems and provinces, then keep it current as the rules move.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What a law firm's incident plan has to cover

A generic template collapses on contact with privilege and trust accounting. The plan we draft is organized around the four things a compromised firm must protect at once.

Privilege during the response

Deciding what to tell clients, courts and opposing counsel about a breach is itself a matter of professional judgment. The plan defines who makes those calls and how external responders are engaged without widening disclosure.

Trust funds mid-flight

Closings do not pause for an incident. Runbooks cover freezing disbursements, verifying pending wires by phone and contacting the trust account's bank within minutes rather than days.

The systems that run the practice

Isolation steps are written for your actual stack: the practice-management platform, the DMS, email, accounting and whatever your MSP administers, with after-hours contacts for each.

The record of the incident

Regulators expect documentation, and PIPEDA requires keeping records of every breach of safeguards for two years. The plan builds the log as you respond instead of reconstructing it afterwards.

Regulatory map

The law-firm notification stack, mapped in advance

Which duties fire depends on where the firm practises and whose information was hit. The plan encodes each obligation with its trigger and deadline, so nobody is researching statutes at midnight.

LSO steps in Ontario

The Law Society of Ontario's cybersecurity checklist directs firms to isolate systems, notify the insurer, report risk to client property or confidentiality by submitting a complaint in LSO Connects, and promptly notify affected clients.

Primary source →

PIPEDA breach reporting

Where a breach creates a real risk of significant harm, the firm reports to the OPC and notifies affected individuals as soon as feasible, and it remains accountable when the breach happened at a service provider.

Primary source →

Quebec's register and the CAI

Confidentiality incidents go to the CAI and affected persons where there is a risk of serious injury, and the firm keeps an incident register for at least five years. A Montreal office puts these duties in scope.

Primary source →

Alberta's PIPA s.34.1

Alberta requires reporting to the OIPC without unreasonable delay where a real risk of significant harm exists, a distinct clock from the federal one that Calgary and Edmonton offices must track.

Primary source →

BC's different baseline

BC PIPA currently imposes no statutory breach-notification duty, but LSBC record-security rules, client contracts and insurer conditions still demand a documented response. The plan reflects that asymmetry honestly.

Primary source →

What goes wrong

The incidents this plan is rehearsed against

We draft runbooks for the scenarios that actually hit Canadian practices, not hypothetical nation-state drama.

  • Extortion aimed at your clients

    At MBC Law in Ottawa, the intruder emailed clients, other lawyers and opposing parties two weeks after detection to force payment, and recovery to full function took about four weeks. The plan assumes the attacker will talk to your clients before you do.

    Source →

  • A wire out of trust

    Redirected closing funds are usually discovered when the real payee calls asking where the money is. The runbook front-loads bank recall, insurer notice and fraud-centre reporting because every hour narrows recovery.

    Source →

  • A device gone from a car or courtroom

    A lost laptop or phone triggers a fast fork: encrypted and remotely wiped means containment; unencrypted means notification analysis begins immediately. The plan scripts both branches.

  • Your vendor's breach, your duty

    The MOVEit file-transfer compromise reached client files held by major professional-services firms. When your DMS or transfer vendor is hit, your plan, not theirs, governs what clients and regulators hear from you.

    Source →

Our incident response for law firms

What the incident response planning engagement delivers

This is a policy-development engagement with teeth: documents your people can execute under stress, tailored to the firm rather than adapted from a corporate template.

Modern and luxury office
  1. The core plan

    Roles, escalation thresholds, decision authority and communication rules for the managing partner, administrator, MSP and external counsel, in a format short enough to use during an outage.

  2. A notification matrix by province

    Every obligation, from LAWPRO or ALIA and the law society through the OPC, CAI and OIPCs to clients and courts, with its trigger, deadline and owner on one page.

  3. Scenario runbooks

    Step-by-step sequences for ransomware, business email compromise, trust wire fraud, lost devices and vendor breaches, each ending in the documentation the regulators expect.

  4. Vendor and MSP coordination

    Contact paths, contractual notice obligations and evidence-preservation requests for the practice-management, DMS and IT providers who will be inside the response.

  5. A working session and updates

    We walk the named responders through the plan against a realistic scenario, then revise the documents as laws, systems and staff change so the plan stays executable.

How the engagement runs

Building the plan with your firm

  1. Step 1

    Inventory scenarios and obligations

    We map your offices, practice areas, systems and vendors to the specific regulators, insurers and law societies that would be involved in each incident type.

  2. Step 2

    Draft with the responders

    The plan and runbooks are written with the administrator, MSP and a designated partner, so the steps match how the firm genuinely operates after hours.

  3. Step 3

    Walk it through

    A tabletop-style session runs the team through a trust-fraud or ransomware scenario and exposes gaps in contacts, authority and timing before reality does.

  4. Step 4

    Maintain it

    Annual refreshes, plus updates when you add an office, change MSPs or when notification law shifts, keep the plan from becoming shelf-ware.

What it costs

Pricing an incident response plan for a firm

Effort depends on how many provinces you practise in, how many systems and vendors sit in scope, whether trust volume justifies a dedicated wire-fraud runbook, and whether you want the facilitated walkthrough included. A single-office Ontario boutique is a compact project; a firm with Toronto, Calgary and Montreal offices carries three regulators' worth of mapping.

Firms on the Virtual Privacy Office retainer already receive an incident management protocol as part of the monthly service, so ask us which route fits before commissioning a standalone plan. A short scoping call is enough to price the work.

Law Firms: Incident response questions, answered

Containment comes before any call: isolate affected systems so the damage stops growing. The insurer is typically the first external contact, because coverage decisions and approved breach counsel flow from that call, and LAWPRO's cybercrime coverage has its own conditions. Law society reporting, in Ontario through LSO Connects where client property or confidentiality is at risk, and OPC or provincial reporting where harm thresholds are met, follow in the sequence the plan lays out. The point of planning is that this ordering is decided calmly, in advance.

Possibly, and the Ottawa extortion case shows why it matters: the attacker contacted opposing parties directly, so silence handed the narrative to a criminal. Whether formal notice is owed depends on whose personal information was compromised and which statutes apply, while professional courtesy and litigation strategy add their own weight. The plan pre-builds the analysis: what was in the mailboxes, who is identifiable, which duties attach, and who in the firm decides what is said to whom.

It turns on what was on the device and how it was protected. Full-disk encryption with a prompt remote wipe often means no real risk of significant harm, which changes the analysis under PIPEDA and Alberta PIPA; an unencrypted laptop holding matter files pushes toward regulator reports, client notification and, in Ontario, the checklist's law society step. Either way the incident is documented, kept in the two-year PIPEDA record and, for Quebec practices, entered in the five-year register.

Speed decides the outcome. The runbook starts with the receiving and sending banks for a recall attempt, then police and the Canadian Anti-Fraud Centre, then the insurer, since cybercrime coverage and its $250,000 sublimit come into play. From there the firm addresses clients whose funds were touched, its law society obligations around the trust account, and the email compromise that usually enabled the fraud. Everything is timestamped, because recovery and coverage both depend on the record.

Yes, and for a SaaS-dependent firm this is essential. Under PIPEDA your firm stays accountable for personal information a processor loses, so the plan includes each key vendor's breach contacts, the notice clauses in their contracts, what evidence to demand, and how to communicate with clients while a provider controls the facts. It also covers the awkward scenario where the MSP itself is compromised and cannot be trusted as the response channel.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.