Law firms

IT support for law firms, built around the trust account

We look after IT for Perth law firms and legal practices. Trust banking and settlements protected from fraud, privileged files kept confidential and practice software that works, with a Perth service desk that answers in about 25 seconds.

Principal of a law practice reviewing a matter on a tablet
ISO 27001 certifiedWhat your clients' security teams ask for
  • 7 yearsMinimum period trust records must be kept under the Legal Profession Uniform Law
  • 24/7Monitoring for mailbox takeover and ransomware on SecureShield plans
  • WAHosted systems and primary backups stay in Perth datacentres
  • MonthlyAgreements that run month to month, with no lock in

01The risks

Where law firms get caught out

Law firms hold client money and privileged information, which is exactly what attackers want. The Legal Practice Board of WA had a cyber incident of its own in May 2025, and the 2023 attack on HWL Ebsworth put around a million stolen documents on the dark web.

  1. A settlement is paid to a fraudster

    An attacker takes over a mailbox, watches a property or business settlement, then sends new bank details at the last minute. The Legal Practice Board reminds practices that there is no such thing as a forged cheque in an online transaction.

    FixPhishing resistant MFA, email security that flags impersonation and trust payments that need a second authorised approver.

  2. Trust banking passwords are shared

    Online trust transfers are authorised by a password, and the Board says handing that password to a bookkeeper or office manager is not acceptable. Shared logins are still common in small practices.

    FixIndividual logins for everyone, a password manager and banking approval settings that match the Board's guidance.

  3. Privileged files leak through email and links

    Matter documents end up in personal inboxes, public sharing links and laptops that left with a former employee.

    FixPermissions by matter, sharing controls, data loss prevention and encrypted devices we can wipe remotely.

  4. Records are kept badly, or not at all

    Trust records must be kept for at least seven years, and client documents can generally only be destroyed after seven years. Files on an old server or a single USB drive put both at risk.

    FixRetention settings in Microsoft 365 and your document system, with immutable backups and an archive you can search.

03Trust money

Four controls that protect trust money

Technology makes mailbox takeover harder, but process is what stops trust money leaving on the wrong instructions. These are the controls we help practices put in place.

  1. 01
    Call on a number from the file

    Confirm any change to bank details by phone, using a number already on the file, never one in the email asking for the change.

  2. 02
    A second authorised approver

    Trust payments and new payees need a second authorised person in online banking and your trust accounting software.

  3. 03
    No shared banking logins

    Every person who can create or approve a transfer has their own login, protected with MFA and a password manager.

  4. 04
    Tell clients at engagement

    Say in your engagement letter and email signature that your bank details will never change by email.

We set up the technical side and give your accounts team a short written procedure.

Email security

04Your obligations

The rules your IT has to support

Most of these are professional obligations rather than IT rules, but each one depends on how your systems are set up.

Obligations for WA law firms and how Austin Technology helps
ObligationWhat it asks of youHow we help
Legal Profession Uniform LawApplied in WA since 1 July 2022. Trust records must be kept for at least seven yearsRetention settings and immutable backups that outlast the seven years
Legal Practice Board of WAOnline trust transfers are authorised by password, so trust banking passwords must not be handed to a bookkeeper or office managerIndividual accounts, MFA and approval settings that match the Board's guidance
Solicitors' Conduct RulesClient information stays confidential, and client documents can generally be destroyed only after seven yearsAccess by matter, encryption and logs that show who opened what
AML/CTFSince 1 July 2026, firms providing designated services, such as property and company transactions or holding money for a transaction, are reporting entities. They had to enrol with AUSTRAC by 29 July 2026Secure storage and access controls for identification and due diligence records
Privacy ActFirms over $3 million turnover, and small firms for their AML/CTF work, must protect personal information and notify eligible data breachesControls, logging and an incident response plan that covers each step

We handle the technical controls and evidence. For legal interpretation you have the best advisers in the building, and we work alongside them and AUSTRAC guidance.

05Proof

Security your clients can check

Corporate and government clients now ask their law firms how they protect client data. These are the answers we help you give.

/01

Security that won the work

Palisades, a professional services firm, rebuilt a legacy setup around Intune, conditional access and the Essential Eight, met a prospective client's security requirements and won the work.

Read the case study
/02

Certified and onshore

We are ISO 27001 certified, and hosted data and primary backups stay in Perth, which answers two of the first questions on most client security questionnaires.

Security and governance
/03

Reporting partners can read

A quarterly report on service, security and backups, with your Essential Eight score, written for partners rather than engineers.

Essential Eight

Related industries

06Questions

Law firm IT questions

What principals and practice managers ask us most. Anything else, call 1300 787 429.

01

Do you support LEAP and other legal practice software?

Yes. Whether you run LEAP, Actionstep, Smokeball or another practice management system, we look after the Microsoft 365, devices, network, integrations and access it depends on, and work with the vendor on application issues.

02

How do we stop settlement and trust payment fraud?

Combine technology and process. MFA and email security make mailbox takeover much harder. A rule to confirm any bank detail change by phone on a number from the file, plus a second approver for trust payments, stops most of the rest.

03

What do the AML/CTF reforms mean for our IT?

If your firm provides designated services such as property or company transactions, you became a reporting entity on 1 July 2026 and now hold identification and due diligence records that must be kept securely. Small firms must also follow the Privacy Act for that work. We set up storage, access controls and logging for those records.

04

How long should we keep files and backups?

Trust records must be kept for at least seven years under the Uniform Law, and client documents can generally only be destroyed after seven years unless instructions or the law say otherwise. We set retention in Microsoft 365 and your document system to match your policy, and keep backups that cannot be altered.

05

Can lawyers work securely from court or home?

Yes. Managed, encrypted laptops, MFA and secure access to matter files and practice software let lawyers work and file through the eCourts Portal from anywhere, without copying client files to personal devices.

06

What does IT support cost for a law firm?

A monthly fee per user covers support, monitoring and security, with projects quoted before we start. Agreements run month to month, and a free IT audit gives you a fixed quote.

07Law firms

Protect the trust account
before someone tests it.

Start with a free IT audit. You get a plain English view of your email security, banking controls, systems and costs.

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.
Scroll to Top