IT Checklist for Law Firms: Users, Devices, Security, Vendors, and Client Data
September 9, 2026
Law firm IT works best when support, identity, devices, security, vendors, and client data all have clear ownership. Use this checklist as a practical baseline.
.webp)
Law firm IT is unusually dependent on reliability, confidentiality, and clear ownership. Attorneys and staff need fast access to email, documents, case-management systems, billing platforms, and client communications while the firm also protects sensitive information across offices, homes, courts, and travel.
This checklist is a practical IT baseline, not legal or regulatory advice. Specific professional, ethical, contractual, or compliance obligations should be reviewed with the appropriate advisors.
Identity and account security
- Require MFA for Microsoft 365, remote access, and other important systems where supported
- Limit administrative roles
- Review shared accounts and legacy credentials
- Use a documented onboarding and offboarding process
- Remove former employees and vendors promptly
Identity is especially important because email and document systems often provide access to sensitive client information.
Microsoft 365 administration
Many firms depend on Exchange Online, Outlook, Teams, SharePoint, and OneDrive. Review mailbox ownership, shared mailboxes, external sharing, guest access, licensing, administrative roles, and recovery expectations.
Our Microsoft 365 security checklist provides a deeper tenant-level review.
Device management
Firm-owned laptops and desktops should have a known inventory, supported operating systems, patching, endpoint protection, encryption where appropriate, and remote support capability.
Remote or traveling attorneys create additional risk when devices regularly leave the office environment.
Email and phishing readiness
Law firms can be attractive phishing targets because attackers know employees routinely exchange documents, invoices, settlement information, and financial instructions.
Train employees to verify unusual payment requests, unexpected file shares, password prompts, and messages that impersonate clients or firm leadership.
Case-management and line-of-business applications
Document the firm's practice-management, document-management, timekeeping, billing, e-discovery, phone, scanning, and other core platforms. Know who owns administration, licensing, vendor support, backups, integrations, and escalation.
Backup and recovery
Understand how critical file, application, server, and cloud data is protected. Document what the firm expects to recover after accidental deletion, hardware failure, ransomware, or provider outage.
Do not assume a cloud application automatically meets every recovery requirement.
Secure remote work
Define how attorneys and staff access firm systems outside the office. Avoid informal remote-access methods that bypass identity or device controls.
Remote employees should receive the same helpdesk, device-management, and security coverage as office users whenever possible.
Vendor access
Law firms often depend on multiple vendors: practice management, billing, document systems, phone providers, internet providers, e-discovery, copier vendors, cloud platforms, and outside consultants.
Keep an inventory of important vendors, who owns the relationship, what systems they can access, and how that access is removed when no longer needed.
New-hire onboarding
New attorneys and staff should have accounts, hardware, approved applications, MFA, permissions, email, and support information ready before they begin working with client matters.
Role-based checklists are more reliable than setting up each employee from memory.
Employee offboarding
Coordinate account disablement, session revocation, device recovery, mailbox and file handling, practice-management access, shared accounts, vendor access, and licensing.
Offboarding should happen on an agreed timeline between HR, leadership, and IT.
Incident response
The firm should know who is contacted after suspected account compromise, ransomware, lost equipment, suspicious payment requests, or other security events.
Technical containment may need to happen immediately while legal, insurance, ethical, or client-notification questions are evaluated separately.
Helpdesk ownership
Attorneys should not have to determine whether an issue belongs to Microsoft, the internet provider, the practice-management vendor, or a hardware manufacturer. A mature support model owns the ticket and coordinates escalation.
Quarterly IT review questions
- Are all active users and devices accounted for?
- Are former users fully removed?
- Are critical systems patched and supported?
- Are backup failures being reviewed?
- Have important vendors or contracts changed?
- Are there recurring support issues that need a permanent fix?
- Are upcoming hires, office changes, or software projects planned?
Two Factor provides Managed IT for Law Firms across helpdesk, Microsoft 365, devices, cybersecurity, vendors, and technology planning so those responsibilities do not have to be coordinated separately.