IT Support for Law Firms Canada: What Every Firm Needs After the VIQ Breach | Tecbound

política de ciberseguridad en su computadora portátil dentro de una oficina moderna
IT Support for Law Firms Canada

A Canadian Legal Tech Company Just Had a Major Data Breach. Here’s What Every Canadian Law Firm Should Do Right Now.

In February 2026, VIQ Solutions, a publicly traded Canadian technology company providing transcription services to courts and law firms, disclosed that a subcontractor had accessed thousands of sensitive legal records without authorization. The files included domestic violence proceedings, child custody cases, covert police operations, and national security hearings. Internal staff had flagged concerns six months earlier. Management dismissed them.

The breach resulted in a formal complaint to Canada’s privacy commissioner, an investigation by Australian federal authorities, and the eventual voluntary administration of VIQ’s Australian subsidiary.

The company was Canadian. The data was legal. The failure was vendor oversight. And the warning signs were ignored.

For Calgary law firms managing client data, trust account information, and privileged communications through a chain of software platforms, cloud providers, and IT vendors, the VIQ breach is not an edge case. It is a preview.

Why Law Firms in Canada Are High-Value Targets

Law firms are among the most targeted professional services organizations in Canada. The reason is straightforward: they hold concentrated, highly sensitive data—client financial records, litigation strategy, intellectual property, personal injury details, criminal defence communications—and they often invest significantly less in IT security than financial institutions or healthcare organizations with comparable data exposure.

“74% of law firm breaches involve human error, phishing, stolen credentials, or misuse of access.” — Sikich Legal Technology Guide, 2026

Business email compromise targeting trust accounts is now among the most financially damaging cyber threats to the Canadian legal sector. A convincing email arrives appearing to be from a client, opposing counsel, or real estate agent, redirecting a wire transfer. The funds leave the trust account. By the time the fraud is detected, recovery is rarely complete.

Ransomware presents a different but equally serious threat. A ransomware incident can put a law firm in an immediate bind. If files are encrypted, email is unavailable, practice management tools are offline, or billing systems are inaccessible, the firm may struggle to function. Legal work is time-sensitive in ways that make downtime disproportionately damaging; court dates, limitation periods, closing deadlines, and client commitments cannot simply pause while systems are restored.

“The Canadian National Cybercrime Coordination Centre received more than 2,000 assistance requests between 2021 and 2023, with roughly 55% involving ransomware.” — CN4C / Uptime Legal, cited 2026

What the Law Society of Alberta Expects

Canadian law societies have moved from guidance to expectation. Law societies across Canada require lawyers to maintain competence in the use of technology relevant to their practice and to take reasonable precautions to protect client confidentiality in electronic systems.

For Alberta firms specifically, the Law Society of Alberta has issued guidance on cloud computing and electronic client records that addresses data residency, vendor selection, and confidentiality obligations. Alberta lawyers using cloud services are expected to understand where their data is stored, what security measures the provider uses, and how to access records if the provider’s service is discontinued.

In practice, “reasonable precautions” in 2026 means:

  • A written cybersecurity policy covering acceptable use, password requirements, MFA, data handling, and incident response
  • Documented security awareness training for all lawyers and staff, dated and updated
  • A tested incident response plan that specifies who is notified, in what sequence, and what the LSAA reporting obligations are
  • Vendor due diligence for any cloud provider or software platform processing client data, including data residency confirmation
  • A documented breach notification procedure with template communications ready before they are needed

The LSAA has also publicly reported a surge in cyberattacks targeting its website and infrastructure and has recommended that Alberta legal organizations work with cybersecurity partners to review federal threat bulletins and implement additional precautions.

What the VIQ Breach Actually Teaches Canada Law Firms

The threat didn’t come from a hacker. It came from a vendor.

The moment you hand sensitive data to a third party, you are responsible for what happens to it, including what that third party does with it next. VIQ’s contracts explicitly prohibited offshoring client data. The prohibition was in writing. It still wasn’t enforced.

Every law firm in Calgary uses third-party software. Practice management platforms like Clio, PCLaw, LEAP, and Cosmolex. Document management systems. Cloud storage. E-signature platforms. Video conferencing tools. Accounting software. Each of these is a vendor with access to client data. Each of them has sub-processors and infrastructure dependencies that the law firm has almost certainly never reviewed.

Internal warnings were dismissed because they weren’t treated as IT governance.

VIQ’s breach was not inevitable. It was a deliberate choice to cut costs, and to ignore the people inside the company who raised concerns about it. Signing a vendor contract is not the same as managing vendor risk.

Most law firms don’t have a formal vendor risk management process. They select software based on functionality and price, sign terms of service, and move on. The cybersecurity due diligence that a managed IT provider would conduct — data residency confirmation, security certification review, sub-processor disclosure, breach notification clause assessment — simply doesn’t happen.

The breach affected clients who had no idea their data was at risk.

The individuals whose court files ended up with an unauthorized offshore contractor had no knowledge it was happening. They could not prevent it. Their exposure was entirely due to vendor management failures at a company they had never directly engaged.

For a Calgary law firm, the equivalent scenario is a breach at a cloud vendor, practice management platform, or IT provider—one that exposes client files your firm is obligated to protect under solicitor-client privilege, PIPEDA, and LSAA professional conduct standards. The firm’s culpability under those obligations does not diminish because the breach originated with a vendor.

What Basic IT Support Doesn’t Cover and What Managed IT for Law Firms Does

Most law firms in Calgary use some form of IT support. The gap is between break-fix IT maintenance—someone to call when something stops working—and managed IT services designed for the legal sector’s specific risk environment.

IT Requirement What Basic IT Support Covers What Managed IT for Law Firms Covers
Email security Setup and password resets Anti-phishing, BEC detection, MFA enforcement, suspicious login alerts
Data backup Backup configured and scheduled Tested recovery, offsite + cloud redundancy, documented RTO/RPO for legal deadlines
Vendor access Not typically reviewed Documented vendor inventory, access scoped to minimum necessary, contract review
Incident response Called when something breaks Documented procedure: who calls whom, in what order, what the LSAA reporting timeline is
Trust account protection General network security BEC-specific controls, dual-approval workflows, wire transfer verification protocols
Compliance documentation Not included Written security policy, LSAA-aligned controls, cyber insurance questionnaire support

Many law firms rely on basic IT support: a local provider who fixes computers, resets passwords, and manages email. That’s not cybersecurity. That’s maintenance. The distinction matters because the LSAA’s competence obligation, cyber insurance questionnaires, and client procurement requirements are all asking about the second column, not the first.

The Five IT Controls Every Calgary Law Firm Needs Before September

  1. Multi-factor authentication on every account that touches client data. This is non-negotiable. MFA on your email, practice management platform, document storage, and remote access. Not optional for lawyers who travel or work from home. Most law firm trust account compromises begin with a credential theft that MFA would have stopped.
  2. A tested backup with a documented recovery time objective. Not a backup that runs — a backup you have actually restored from, with a measured understanding of how long full recovery takes. If your firm has a court date in 48 hours and your systems go down tonight, your recovery process needs to be faster than your deadline. Most firms don’t know their recovery time until they need it.
  3. A vendor access inventory. List every cloud platform, software tool, and third-party contractor with access to client data. For each one: confirm data residency (Canada only, or disclosed offshore), review the security documentation, and ensure the contract includes a breach notification clause. The VIQ breach would have looked entirely different if its clients had conducted this exercise before signing.
  4. A written incident response plan aligned to LSAA obligations. The plan needs to specify: who is responsible for declaring an incident, what the LSAA reporting timeline is, what the PIPEDA breach assessment process looks like, what communication goes to affected clients and when. A general IT plan is not the same as a legally aware incident response plan. The two documents serve different purposes.
  5. Canada-resident data storage. Every cloud vendor your firm uses should be able to confirm that client data is stored in Canada. For Alberta firms, data residency is both a Law Society expectation and, under PIPEDA, a due diligence obligation. “We use reputable cloud providers” is not a satisfactory answer to the LSAA or to a client whose matter involves confidential business information.

Not every law firm needs or wants to outsource all IT to an external provider. Many firms have internal administrative staff who handle day-to-day IT tasks, password resets, device setup, and software licences. Co-managed IT services for law firms preserve that internal capacity while adding the cybersecurity layer that general IT support doesn’t provide.

What Co-Managed IT Has Accelerated for a Law Firm

Password resets, device setup, software licences. Co-managed IT services for law firms preserve that internal capacity while adding the cybersecurity layer that general IT support doesn’t provide.

In a co-managed arrangement, your internal staff continues to handle routine support. A managed IT partner handles security monitoring, patch management, backup verification, vendor risk review, incident response planning, and compliance documentation. The result is that a Data Recovery answer the insurance questionnaire and the LSAA compliance inquiry from documented evidence, not from assumptions about what the IT person set up three years ago.

For Calgary law firms between 5 and 75 lawyers, this is usually the right model. The economics of a full in-house cybersecurity function don’t work at that scale. The risk of no cybersecurity function at all is now demonstrably unacceptable.

Cloud Computing for Calgary Law Firms: What to Look For

Cloud adoption in the legal sector has accelerated significantly. Practice management platforms like Clio are now the dominant choice for Canadian SMB firms precisely because cloud infrastructure offers reliability and accessibility that on-premises servers cannot match for a firm whose lawyers work from multiple locations.

The cloud computing questions that matter for a Calgary law firm are not about whether to use the cloud — that decision is largely made — but about how to use it within the LSAA’s framework:

  • Where is data stored? Data recovery is required for most law firm client files. Confirm with each vendor in writing.
  • What are the vendor’s security certifications? SOC 2 Type II, ISO 27001, and CSA STAR are the relevant standards for cloud providers used by legal practices.
  • What happens to your data if the vendor’s service is discontinued? The LSAA guidance specifically requires a plan for data retrieval in the event a cloud provider shuts down.
  • What are the sub-processor disclosures? The VIQ breach was caused by a subcontractor, not Canadianor directly. Every cloud platform uses sub-processors. You need to know who they are and where they operate.

Data Backup and Recovery for Law Firms in Calgary: Why Testing Matters More Than Running

The standard question firms ask about backup is: “Does it run?” The right question is: “How long does recovery actually take, and have we tested it recently?”

For a Calgary law firm facing a ransomware incident, the practical constraint is not whether a backup exists — it’s whether the firm can recover data before a court date, a limitation period, or a closing deadline passes. Recovery time is a legal exposure, not just an IT metric.

Managed IT services for Canadian law firms should include quarterly backup restoration tests with documented results, offsite and cloud backup redundancy, and a defined recovery time objective specific to your practice’s most time-sensitive work. A network security services engagement that doesn’t include this is incomplete.

Conclusion: The VIQ Breach Is a Scenario Every Canadian Law Firm Should Plan For

VIQ Solutions was a Canadian company. It served courts and legal organizations. It had contracts in place. It had staff who raised concerns. The breach happened anyway because vendor oversight wasn’t treated as a governance responsibility until after the damage was done.

Every cloud vendor your firm uses for practice management, document storage, email, and e-signature should be able to confirm Canadian data residency in writing.

Managed IT services for law firms in Canada are not a cost centre. They are the documented, operational infrastructure that allows a managing partner to answer, with confidence, when the insurer, the regulator, or the client asks: “How are you protecting this information?”

If your firm hasn’t reviewed its vendor access, tested its backups, or documented its incident response plan in the past 12 months, that’s where to start. Contact Tecbound at tecbound.com/contact-us — we work with law firms and professional services organizations in Canada and across Canada.

Frequently Asked Questions

What IT support do law firms in Calgary actually need?

Calgary law firms need IT support that goes beyond break-fix maintenance. The Law Society of Alberta expects firms to maintain documented cybersecurity policies, MFA on all systems containing client data, tested data backup and recovery, vendor due diligence for cloud providers, and a written incident response plan. General IT support, password resets, device setup, and email management do not cover these requirements. Managed IT services for law firms include all of these as part of an ongoing engagement, with documentation that supports LSAA compliance, cyber insurance renewals, and client procurement questionnaires.

Why are cyberattacks targeting law firms?

Law firms hold concentrated, highly sensitive client data, financial records, litigation strategy, intellectual property, and personal information, and trusted accounts that hold client funds. They are often less protected than banks or healthcare organizations with comparable data exposure, making them high-value targets relative to the investment required to compromise them. Business email compromise targeting trust accounts and ransomware that encrypts practice management systems are the two most common and financially damaging attacks on Canadian law firms in 2026.

What are the Law Society of Alberta’s IT requirements?

The LSAA requires Alberta lawyers to maintain competence in the technology they use and to take reasonable precautions to protect client confidentiality in electronic systems. In practice, this means a written cybersecurity policy, documented staff training, vendor due diligence for cloud services (including Canadian data residency confirmation), a tested incident response plan, and breach notification procedures. The LSAA has also issued specific guidance on cloud computing and electronic records, and has publicly flagged a surge in cyberattacks targeting Alberta legal organizations.

How does managed IT differ from co-managed IT for a law firm?

Fully managed IT means your IT provider handles all technology support and cybersecurity; your firm has no internal IT function. Co-managed IT means your internal staff handles routine day-to-day tasks; synchronously, the managed IT partner handles security monitoring, patch management, backup verification, vendor risk reviews, incident response planning, and compliance documentation. Most Canadian law firms between 5 and 75 lawyers are better served by co-managed IT; it preserves internal capacity while adding the security layer that general IT support doesn’t provide.

What is business email compromise and how does it affect trust accounts?

Business email compromise (BEC) is a fraud in which an attacker impersonates a trusted contact—a client, opposing counsel, real estate agent, or financial institution—and redirects a wire transfer or payment. In law firms, trust accounts are the primary target because they hold client funds and transfers are routine. A convincing fraudulent email instructs the firm to send funds to a new account. By the time the fraud is identified, recovery is rarely complete. BEC-specific controls, including dual-approval workflows for transfers, wire transfer verification protocols, and anti-impersonation email security, are a core part of managed IT services for law firms.

What does Canadian data residency mean for Canadian law firms?

Data residency refers to where data is physically stored. The Law Society of Alberta expects lawyers using cloud services to confirm where their client data is stored and what happens to it if the provider’s service is discontinued. For most Alberta law firms, client data must be stored in Canada. Under PIPEDA, transferring personal information to a foreign jurisdiction without appropriate safeguards creates privacy compliance exposure. Every cloud vendor your firm uses for practice management, document storage, email, and e-signature should be able to confirm Canadian data residency in writing.

How long does data recovery take for a law firm after a ransomware attack?

Recovery time depends on whether your firm has tested its backup restoration process, not just whether backups are running. Most firms don’t know their actual recovery time until they need it. For a law firm with a court date in 48 hours, “we’re not sure” is not an acceptable answer. Managed IT services for Calgary law firms should include quarterly backup restoration tests with documented recovery times, offsite and cloud redundancy, and recovery objectives specific to your most time-sensitive legal work. A backup that has never been tested is not a recovery plan.

What should a Calgary law firm do after learning about the VIQ Solutions breach?

The VIQ breach is a practical checklist. Review every vendor with access to client data and confirm their data residency, security certifications, and breach notification clauses. Verify that internal staff have a process for flagging vendor security concerns — and that those concerns reach decision-makers. Confirm that your practice management platform, cloud storage, and transcription or document services have documented sub-processor disclosures. If you haven’t done a vendor access review in the past 12 months, that is the first conversation to have with your IT provider.

Join Our Weekly Cybersecurity Tips

Get A FREE Subscription To Weekly Cybersecurity Tips So Your Company Doesn’t Become The Next Victim.

 

 

Table of Contents

Share:

Related Posts

Cybersecurity risk assessment