The Alberta Law Firm IT Self-Assessment
Fifteen things worth checking in the technology your practice runs on — written for firms that would rather find the gaps themselves than discover them during an incident. We don't record anything that identifies you or your firm.
Fifteen sections. One number you can act on.
Work through the same fifteen sections as our printed self-assessment, ticking each item you can confirm is true today. Each section scores itself 0, 1 or 2 from what you tick, for a total out of 30 — and no email is required to see your result.
Not sure about an item? Leave it unticked — “unsure” is a finding in itself. Your answers save in this browser, so you can check with a colleague and finish later.
Optional — add your firm size & region to help our anonymous Alberta research ▾
Prefer to print it? Download the PDF guide.
Read it twice, at two different heights
Each of the fifteen sections opens with a single statement for whoever signs off on firm decisions, followed by the specific things an office manager or IT provider can actually go and verify. You can read the first part in a few minutes and hand the rest to someone else.
Nothing here requires you to become technical. Every item is phrased as something you can ask for, look at, or request in writing. Tick what you can confirm; each section scores itself 0, 1 or 2, and the scorecard collects all fifteen into a single number out of 30 you can act on. Prefer paper? Download the printable edition (PDF) — the same fifteen sections and scorecard, designed for a partner meeting.
This self-assessment is deliberately practical rather than exhaustive. It reflects what we see repeatedly in small and mid-sized Alberta practices — not a theoretical maximum.
What the fifteen sections cover
The areas that surface after an incident, during a cyber-insurance renewal, or in a client security questionnaire — each opening with the one line that matters:
Technology as a practice management issue
Where your regulator already weighs in
Your regulator already treats technology as part of competence itself — the Code of Conduct expects every lawyer to develop “an understanding of, and ability to use, technology relevant to the nature and area of the lawyer’s practice” (Rule 3.1-2, Commentary [5]).
Where your client data actually lives
The mapping exercise
Most firms cannot answer “where is our client data?” in under a minute — and you cannot protect, back up or hand over what you have never mapped.
Identity and access
Why “we have MFA” isn’t the whole story
Having multi-factor authentication switched on is not the same as having it enforced — accounts are regularly compromised by routes that never produce a prompt at all.
Email, phishing and payment fraud
The expensive failure
For a law firm the expensive failure is usually not encrypted servers — it is a payment sent to the wrong account on instructions that looked entirely legitimate.
Devices and the security baseline
Encryption, patching, disposal
Every device holding client material should be firm-managed and encrypted — otherwise you are trusting a laptop you cannot see, update or wipe.
Your network and the office itself
The oldest thing in the firm
The office network is usually the oldest thing in the firm and the least documented — often still running on equipment nobody has logged into since it was installed.
Documents, drives and paper
Finding a closed file in five minutes
A shared drive organised by whoever happened to create the folder becomes unsearchable within a few years, and a paper room is a confidentiality and continuity risk nobody has budgeted for.
Getting files to clients safely
Beyond the email attachment
Unencrypted email attachments remain the default at most firms, and this is the easiest item on the list to fix properly.
Working outside the office
The home office is part of the firm
The Law Society has published specifically on protecting client confidentiality while working remotely — treat every home office as part of the firm’s footprint.
Your domain, website and certificates
The foundation nobody checks
Your domain name is the root of trust for your firm’s email and identity — and a surprising number of firms don’t fully control their own.
Vetting a cloud provider and your vendors
Questions to put in writing
The Law Society of Alberta’s cloud computing guidance directs lawyers to due diligence material prepared by the Law Society of British Columbia — there is no Alberta-specific checklist, so the diligence falls to you.
Backup, continuity and succession
Proving the backup works
The Law Society publishes a business continuity and succession planning guide and checklist — and most of what it asks for has a technology dependency underneath it.
AI in the practice
Where confidentiality actually breaks
The risk is rarely the technology itself — it is privileged material being pasted into a consumer account whose terms you have never read.
What good IT support looks like
Agree it before the incident
Most firms discover what their IT provider is really worth during an incident — which is precisely when it is too late to renegotiate the terms.
Cyber insurance and the controls behind it
The application is the audit
Every Alberta lawyer in private practice already carries base cyber coverage through ALIA — what varies is whether anyone knows what it covers, whether the limits fit the firm, and whether the controls attested to on any commercial policy are real.
Fifteen questions, one number
Every section resolves to a score of 0, 1 or 2, derived from the items you tick. The total is out of 30. The point is not the score itself — it is which items came back as zeros.
0–14
Material gaps that would be difficult to explain after an incident — or to an insurer. Start with items scored zero in sections 03, 04, 11 and 15.
15–22
A reasonable foundation with specific weak points. The fixes are usually small and the sequencing matters more than the spend.
23–30
Strong. Focus shifts to evidence and review cadence — being able to demonstrate the position, not only hold it.
A low score is not unusual and is not a judgement on the firm. Almost every practice we review scores zero on at least one item, and the most common is section 12. Knowing which one is the entire value of the exercise.
Next step
We will do this with you, once, at no cost.
If you would rather not run through the fifteen sections alone, we will do it with you — a structured review of your environment against this scorecard. You leave with the Alberta Law Firm IT Guide for your firm: what to fix and in what order, written against your own scores. No obligation to change providers, and the guide is yours to keep either way. It takes about thirty minutes. Most of that is us listening.
01 · Book
Thirty minutes, at your office or on a call.
02 · Review
We walk the fifteen sections with you and look at the systems behind them.
03 · Your guide
The IT Guide for your firm: findings, priorities, and what each fix takes.
An Alberta IT firm, writing about Alberta firms
AltaCom is a Calgary-based managed IT and cybersecurity company with a local Alberta team, supporting businesses across the province through managed services, project work and federal digital-adoption programs since 2011. Everything here comes from reviews we have run — the same fifteen questions, asked in real offices.
2011
Serving Alberta businesses since
Microsoft
Partner — Microsoft 365 and Azure
CDAP Advisor
Approved digital advisor, Canada Digital Adoption Program 2022–2024
“AltaCom’s team is exceptionally responsive, knowledgeable, and proactive. More importantly, they’re a true partner to our firm. They don’t just solve problems when they arise — they actively help us identify and implement technologies that improve efficiency, streamline operations, and create real value.”
Chetan Shory · Partner, Shory Law LLP · Google review
Everything above, from the source
Where this self-assessment refers to Law Society, ALIA or privacy material, here is the material itself — published by the source, free to access.
Law Society of Alberta
The Basics of Cloud Computing
Referenced in sections 01 and 11. Includes the two LSBC documents the Law Society of Alberta points lawyers to.
lawsociety.ab.ca → Resource Centre → Practice ManagementProtecting Client Confidentiality and Data Security While Working Remotely
Referenced in section 09.
lawsociety.ab.ca → Practice ManagementBusiness Continuity and Succession Plan Guide and Checklist
Referenced in section 12. A printable full version and templates are available on the same page.
lawsociety.ab.ca → Practice ManagementAnnual Reporting — Trust Safety Accounting Upload
Referenced in section 07. Where the current list of approved accounting software vendors is maintained.
lawsociety.ab.ca → Trust Accounting and SafetyThe Generative AI Playbook
Referenced in section 13. Includes a model use policy firms can adapt.
lawsociety.ab.ca → Professional ConductPractice and Equity Advisors
A free and confidential service for Alberta lawyers, articling students and legal support staff.
lawsociety.ab.ca → Lawyers and Students
Law Society of British Columbia
Cloud Computing Due Diligence Guidelines
Referenced in section 11 — one of the two documents the Law Society of Alberta directs Alberta lawyers to.
lawsociety.bc.ca → Practice Resources
ALIA and privacy
Universal Cyber Coverage Program — ALIA
Referenced in section 15. Certificates and claims via the Lawyer Portal.
alia.ca/for-lawyers/cyber-coverage-programOIPC of Alberta — PIPA breach reporting
Referenced in section 15 — Alberta’s own breach-notification duty under the Personal Information Protection Act.
oipc.ab.ca
Paths are current as of publication; if one no longer resolves, search the published title on the source site. Nothing here should be read as a statement of your professional obligations — the source documents govern. This self-assessment is general information for law firm management and is not legal, compliance or insurance advice; obligations under the Rules of the Law Society of Alberta and the Code of Conduct should be confirmed with the Law Society’s Practice and Equity Advisors.
Related from AltaCom
Law firm IT self-assessment
Frequently asked questions
Yes — completely free, online and as a printable PDF. You do not need to enter an email to see your score, your band, or the specific items to close. An optional emailed copy of your report is the only thing an email address is used for.
About five minutes online. There are fifteen sections; in each one you tick the items you can confirm are true today. Your answers save in your browser as you go, so you can pause to check something with a colleague and finish later.
Each of the fifteen sections scores itself 0, 1 or 2 from what you tick — nothing ticked scores 0, everything ticked scores 2, anything in between scores 1. The total is out of 30: 0–14 signals material gaps, 15–22 a reasonable foundation with specific weak points, and 23–30 a strong position where the focus shifts to evidence. The point is not the score itself — it is which sections came back as zeros.
Fifteen areas drawn from real reviews of Alberta practices: technology governance, where client data lives, identity and MFA, email and payment fraud, device security, the office network, documents and records, secure client file exchange, remote work, your domain and website, vendor due diligence, backup and continuity, AI use, what good IT support looks like, and cyber insurance including ALIA’s universal coverage.
Your answers are recorded anonymously — no name, firm name, email, IP address or precise timestamp is attached to them. Entering an email to receive your PDF report is a separate, optional step, and it is never stored alongside your answers.
It is written to be read at two heights: each section opens with a single statement for whoever signs off on firm decisions, followed by the specific items an office manager or IT provider can actually go and verify. A managing partner can complete it alone in a few minutes, or hand the detailed checks to someone else — no technical knowledge is needed.
Yes. It is built around what Alberta firms actually face: the Code of Conduct’s technological-competence expectation (Rule 3.1-2, Commentary [5]), the Law Society of Alberta’s guidance on cloud computing and remote work, the Trust Safety approved-software list, ALIA’s universal cyber coverage, and Alberta’s Personal Information Protection Act.
Yes. The complete self-assessment is available as a designed, printable PDF — the same fifteen sections, checklists and scorecard — so you can run it on paper at a partner meeting or hand it to your office manager. The download is free and requires no email.