Managed IT for Australian Law Firms
Privacy Act compliance, Legal Professional Privilege protection, AML/CTF obligations from 1 July 2026, and Essential Eight alignment. Built for Australian legal practices between 5 and 100 staff.
Why legal IT requires specialist handling
Law firms are not typical small businesses. You hold client money in trust accounts. You handle sensitive personal information under the Privacy Act. Your communications are protected by Legal Professional Privilege. From 1 July 2026, many firms become regulated entities under the AML/CTF Amendment Act.
A cyber incident at a law firm is not just a business interruption. It can trigger regulatory investigations, loss of privilege, disciplinary action from state law societies, and civil liability from affected clients.
Generic MSPs often miss these nuances. They apply standard SMB security baselines that do not account for trust accounting, privilege protection, or law society reporting obligations. This guide covers what Australian law firms specifically need.
Compliance requirements for Australian law firms
Five regulatory frameworks that shape your IT requirements. Non-compliance carries financial penalties, disciplinary action, and reputational damage. SMB1001 certification for law firms maps these obligations onto a certifiable standard your clients and insurers can verify.
| Regulation | Requirement | Applies To | Penalty |
|---|---|---|---|
| Privacy Act 1988 (Cth) | Australian Privacy Principles. APP 11 requires reasonable security steps for personal information. Health, financial, and legal data = highest protection. | All firms handling client personal data | Up to $62.5 million for serious/repeated breaches (2026) |
| AML/CTF Amendment Act 2024 | Designated services from 1 July 2026. Customer identification (KYC), ongoing monitoring, suspicious matter reporting to AUSTRAC within 24 hours, AML/CTF program documentation. | Firms providing conveyancing, trust services, buying/selling real estate, managing client money | Civil penalties up to $50 million, criminal offences for directors |
| Legal Professional Privilege | Maintain confidentiality of client communications and work product. IT systems must protect privileged material from unauthorised access. | All legal practices | Loss of privilege, disciplinary action, reputational damage, civil liability |
| State Law Society Requirements | VLSB+C Minimum Cybersecurity Expectations (Vic), NSW Law Society Cybersecurity Guide, QLD Law Society requirements. All require MFA, encryption, backup, training, incident response. | Practising certificate holders in all Australian jurisdictions | Disciplinary action, suspension, conditions on practising certificate, professional misconduct findings |
| Notifiable Data Breaches Scheme | Report eligible breaches to OAIC and affected individuals within 30 days of becoming aware. | All firms with personal data | Investigation, enforceable undertakings, civil penalties, reputational damage |
VLSB+C Minimum Cybersecurity Expectations
The Victorian Legal Services Board and Commissioner sets minimum cybersecurity expectations that apply to all Victorian practitioners. Non-compliance can constitute professional misconduct. Similar guidance exists in NSW (Law Society Cybersecurity Guide), Queensland, and other states.
Expectations include: MFA on all accounts (SMS acceptable but app-based preferred), encrypted devices with remote wipe, secure backup with immutable copies, annual staff cybersecurity training, documented incident response plan, and quarterly access reviews. Your IT systems must evidence these controls on request for audits or after a breach.
Six common IT gaps in Australian law firms
These gaps appear repeatedly in law firm security assessments. Each carries regulatory, privilege, or liability risk.
No multi-factor authentication on email or practice management
Risk: Account takeover via phishing. Client data exposed. Privilege potentially waived. Microsoft enforcing MFA for all admin sign-ins from Feb 2026.
Fix: Enforce MFA on all accounts. Use Microsoft Authenticator app or FIDO2 keys, not SMS.
Shared mailboxes with no MFA
Risk: Departing staff retain access. Client communications intercepted. No audit trail of who accessed what.
Fix: Convert to user mailboxes with individual credentials. Apply MFA. Review access quarterly.
Practice management system accessible from personal devices
Risk: Data exfiltration via unsecured devices. No encryption. No remote wipe. No audit trail.
Fix: Intune App Protection Policies. Block access from non-compliant devices. Encrypted laptops only.
Client files stored on personal OneDrive or Google Drive
Risk: Files leave with staff. No version control. No backup. No access controls. Privilege waived.
Fix: Migrate to SharePoint with departmental sites. Apply retention policies. Audit access quarterly.
No documented incident response plan
Risk: Delayed containment. Regulatory breach. Client notification failures. OAIC 30-day clock starts immediately.
Fix: Document first-hour response. Include OAIC notification timelines. Test annually with tabletop exercise.
Backup without immutability
Risk: Ransomware encrypts backup. No recovery option. ACSC says immutable backup is the single most effective ransomware control.
Fix: Immutable backup with 90-day retention (ACSC ML2). Test restores quarterly. Include trust accounting data.
Essential Eight alignment for law firms
The ACSC Essential Eight is the baseline for Australian cyber security. Law firms should target Maturity Level 2 as a minimum. Insurers and state law societies increasingly expect this.
Application Control
Windows Defender Application Control (WDAC) or AppLocker policies. Block execution from user-writable paths (C:Users, C:Temp, C:ProgramData). Allow-list approved software: LEAP/Clio, Adobe Acrobat, Microsoft Office, browser. Prevents ransomware and unauthorised cloud sync tools (personal Dropbox, Google Drive).
Patch Applications
Microsoft Intune or SCCM for deployment. Patch Adobe Acrobat, Chrome/Edge, Microsoft Office within 48 hours of critical updates. Automate with Intune Update Rings. Test on pilot group (5-10 users) before firm-wide deployment.
Configure Microsoft Office Macros
Group Policy: "Block macros from internet" enabled. Allow only signed macros from trusted publishers. VBA projects password-protected. Macro execution logged via Office 365 audit. Critical for preventing macro-based ransomware (e.g., Emotet, TrickBot).
User Application Hardening
Disable Flash (EOL 2020), Java browser plugins, unnecessary browser extensions. Edge/Chrome policies: block sideloading extensions, enforce Safe Browsing. Reduce attack surface for browser-based exploits.
Restrict Administrative Privileges
No daily-use accounts with local/admin rights. Separate Azure AD accounts for IT staff (e.g., "admin.john@firm.com.au"). Just-In-Time (JIT) access via PIM (Privileged Identity Management) for elevated tasks. Local admin passwords managed via LAPS (Local Administrator Password Solution).
Patch Operating Systems
Windows 10/11 Enterprise with Windows Update for Business. Feature updates deferred 90 days, quality updates deferred 7 days. Critical/security patches within 48 hours (ACSC ML2). Intune or SCCM for deployment. Linux servers (if any) patched via Ansible or Spacewalk.
Multi-Factor Authentication
MFA on email (Exchange Online), practice management (LEAP/Clio SSO), SharePoint/OneDrive, ATO portals. Microsoft enforcing MFA for all admin sign-ins from Feb 2026. Use Microsoft Authenticator app (number match) or FIDO2 keys (YubiKey), not SMS. Conditional Access: require MFA for all cloud apps, block legacy authentication.
Daily Backup
Veeam Backup & Replication or Altaro VM Backup. Immutable backup with 90-day retention (ACSC ML2). 3-2-1 rule: 3 copies, 2 different media, 1 offsite. Test restores quarterly (document results). Include trust accounting data, matter files, email (all user mailboxes). Store backups separate from production network (different VLAN or cloud). Object lock enabled on S3/Azure Blob for immutability.
Practice management system security
Your practice management system holds client files, trust accounting, and billing. Common platforms in Australia include LEAP, PracticePanther, Clio, and MYOB Legal. Security must extend beyond the platform itself.
Access Control
Individual Azure AD user accounts only. No shared logins. MFA enforced via Conditional Access policies. Role-based access groups aligned to matter involvement (e.g., "Matter-12345-Read", "Matter-12345-Edit"). Review access quarterly via Azure AD Access Reviews and on staff departure via automated offboarding runbooks.
Device Management
Microsoft Intune MDM on all devices accessing the system. Windows 11/10 Pro with BitLocker encryption (XTS-AES 256-bit). macOS with FileVault. Compliance policies require OS minimum versions, encryption enabled, firewall on, and antivirus active. Non-compliant devices blocked via Conditional Access. Remote wipe configured for lost/stolen devices.
Data Export Controls
Microsoft Purview DLP policies restrict bulk export of client files from SharePoint/OneDrive. Audit export events via Microsoft 365 Unified Audit Log. Power Automate flows alert on bulk downloads (>50 files in 1 hour). Personal email forwarding blocked via Exchange transport rules. USB storage blocked via Intune device restrictions.
Backup and Retention
Platform backup (LEAP/Clio) is not sufficient. Veeam or Altaro backup of local data stores with immutable copies (object lock enabled). Azure Blob Storage with WORM (Write Once Read Many) configuration for 7-year retention (NSW Law Society) or 15 years (QLD). Test restores quarterly. Document recovery time objectives (RTO < 4 hours, RPO < 1 hour).
Trust Accounting
Separate Azure AD security groups for trust accounting functions (e.g., "Trust-Accounting-Users"). Dual approval for transactions >$10,000 via workflow automation. Audit trail maintained in practice management system and reviewed monthly by finance manager. Export logs to SIEM (Microsoft Sentinel) for anomaly detection.

Remote Support