Law firms and accounting practices hold some of the most sensitive client data of any business type - financial records, legal strategies, estate details, and business structures that clients have shared in confidence. IT failures in professional services don't just cause inconvenience; they can result in regulatory breaches, professional conduct complaints, and lasting damage to client trust.
The Professional Obligation to Protect Client Data
Perth lawyers are bound by the Legal Profession Uniform Law and professional conduct rules that include obligations to protect client confidentiality. Accountants operate under APES 110 (Code of Ethics for Professional Accountants) and the Privacy Act. Both professions face professional sanction - not just legal liability - if client data is compromised due to inadequate security measures.
The Australian Cyber Security Centre has identified professional services as a priority target sector for cybercriminals, specifically because of the high-value client data held and the reputational leverage it creates for ransomware attacks.
Practice Management and Document Management Systems
Most Perth law firms run a practice management system - LEAP, Actionstep, FilePro, or similar. Accounting practices typically use Xero Practice Manager, MYOB Practice, or Karbon. These systems are the operational core of the business and need to be:
- Backed up continuously - matter files, time entries, trust ledgers, and client documents should be backed up multiple times daily
- Access-controlled - staff should only access client matters they are working on; unrestricted access to all client files across the practice is a security and confidentiality risk
- Integrated with document storage - correspondence, contracts, and client documents stored in a structured, searchable way rather than scattered across individual staff desktops
Email Security Is Critical for Legal and Financial Advice
Business Email Compromise (BEC) attacks specifically target professional services firms because the financial transactions they facilitate are large. A criminal who intercepts or impersonates a lawyer's email at the point of settlement can redirect hundreds of thousands of dollars in a single instruction.
Essential email security controls for Perth law and accounting firms:
- DMARC enforcement - prevents criminals from sending emails that appear to come from your firm's domain
- MFA on all email accounts - a compromised email password is useless without the second factor
- Email encryption for sensitive client communications - particularly for documents containing financial or legal advice
- Client verification procedures - a written policy requiring verbal confirmation of any changed bank details or payment instructions, regardless of how legitimate the email appears
Trust Account Security for Law Firms
Trust account breaches carry the most severe consequences for law firms - up to striking off. Any system with access to trust account operations requires the highest level of security: dedicated access controls, MFA on banking portals, dual-authorisation for transactions above a threshold, and regular reconciliation with independent review.
Your IT provider should understand that trust accounting systems are not ordinary financial software and apply appropriate controls around access and monitoring.
Remote Working for Legal and Accounting Staff
Many Perth law and accounting firms now support hybrid working. The security challenge is ensuring that client files accessed from home are as secure as they are in the office. This requires:
- Company-managed devices with full-disk encryption and endpoint protection
- Conditional Access policies that block sign-in from unmanaged or non-compliant devices
- No download of client documents to personal devices or personal cloud storage
- VPN access for any systems that remain on-premises rather than cloud-hosted
Regulatory and Cyber Insurance Requirements
Professional indemnity and cyber insurance policies for Perth professional services firms increasingly require evidence of specific security controls as a condition of coverage - or as a factor in premium calculation. Common requirements include: MFA on all systems, documented backup and recovery procedures, endpoint protection, and staff security awareness training. Having managed IT with documented controls makes insurance renewals significantly smoother.
Frequently Asked Questions
Are law firms and accounting practices legally required to protect client data in specific ways?
Lawyers operate under professional conduct rules that include confidentiality obligations, and accountants work under a professional code of ethics alongside the Privacy Act, so both professions can face professional consequences on top of any legal ones if client data is compromised through inadequate security. The specifics depend on your profession and situation, so it's worth confirming exact obligations with your professional body or compliance adviser.
What is Business Email Compromise and why does it matter for professional services?
BEC is where a criminal intercepts or impersonates a firm's email, often at the point of a settlement or large transaction, to redirect a payment to their own account. Professional services firms are a common target because the transactions they facilitate tend to be large, which is why controls like DMARC, MFA, and a written policy requiring verbal confirmation of any changed bank details matter so much here.
Why does trust account access need extra security beyond normal IT controls?
Trust account breaches carry some of the most serious consequences a law firm can face, so any system touching trust operations generally warrants dedicated access controls, MFA on banking portals, and independent reconciliation. It's worth treating trust accounting software as a different category from ordinary financial software, not folding it into general IT policy.
Does cyber insurance require specific security controls for law and accounting firms?
Increasingly, yes, insurers are asking for evidence of things like MFA across all systems, documented backup procedures, endpoint protection, and staff training as part of underwriting or renewal. Requirements vary by insurer and policy, so it's worth checking your specific policy wording rather than assuming standard controls will automatically satisfy it.
We have a dedicated IT service page for Perth law firms and accounting practices - covering trust account security, BEC prevention, and compliance.
View Legal & Accounting IT Services →Need IT support built for a Perth law firm or accounting practice?
Call 0433 087 091 - we understand the confidentiality obligations and security requirements of professional services firms.
Book a Confidential IT ReviewFor related reading, see our guides to IT Support for Accountants in Perth and IT Support for Dental Clinics in Perth.