AltaCom — Managed IT Services Calgary
Free · Private · No email required

How mature is your firm's IT?

Twelve questions, scored 0–2, for Alberta law firms. You'll get an instant maturity band and specific next steps for anything that scores low. We don't record anything that identifies you or your firm.

Score each of the twelve items below from 0 to 2. Your running total, band and feedback appear instantly — no email required to see your result.

Not sure on an item? Your answers are saved in this browser, so you can check with a colleague and finish later.

Optional — skip if you prefer
  1. Item 1: Is there a named person accountable for IT, with a budget and an annual review?

    Is there a named person accountable for IT, with a budget and an annual review?

    Is one person clearly responsible for IT decisions — with a set budget and a yearly review — or does it just happen ad hoc?

  2. Item 2: Could you produce a current map of every place client data lives?

    Could you produce a current map of every place client data lives?

    Think of every place client files sit: your practice system, email, cloud drives, staff laptops and phones, and backups.

  3. Item 3: Is MFA policy-enforced, with legacy protocols blocked and exemptions reviewed?

    Is MFA policy-enforced, with legacy protocols blocked and exemptions reviewed?

    MFA is a second step at login (like a phone prompt). “Enforced” means required for everyone, with older sign-in methods that skip it switched off.

  4. Item 4: Is there an enforced callback rule for all payment instructions?

    Is there an enforced callback rule for all payment instructions?

    The habit of calling a known number to confirm any change to banking or payment details before money goes out.

  5. Item 5: Are all devices encrypted, managed and centrally reported on?

    Are all devices encrypted, managed and centrally reported on?

    Encryption scrambles a device’s data if it’s lost or stolen; “managed” means IT can see, update and remotely wipe it.

  6. Item 6: Can any authorised person retrieve a closed file quickly, without asking a colleague?

    Can any authorised person retrieve a closed file quickly, without asking a colleague?

    If a closed matter were needed right now, could anyone authorised find it themselves — or does it depend on one particular person?

  7. Item 7: Is there a secure client exchange method that staff and clients genuinely use?

    Is there a secure client exchange method that staff and clients genuinely use?

    A portal or encrypted method for sending client documents, rather than plain email attachments.

  8. Item 8: Is there a written remote work standard covering access, printing and disposal?

    Is there a written remote work standard covering access, printing and disposal?

    A written rule for working outside the office — how staff connect, print, and dispose of client material at home.

  9. Item 9: Do you have written answers to the provider due diligence questions on file?

    Do you have written answers to the provider due diligence questions on file?

    The security questions clients and insurers ask about your IT — do you have your providers’ written answers on hand?

  10. Item 10: Has a documented test restore been completed in the last twelve months?

    Has a documented test restore been completed in the last twelve months?

    Not just that backups run, but that you’ve actually restored from one in the last year and kept a record of it.

  11. Item 11: Is there a written AI use policy with firm-provisioned tools?

    Is there a written AI use policy with firm-provisioned tools?

    Whether staff have a firm-approved AI tool AND a written policy on what client information may be entered into it.

  12. Item 12: Do you receive regular reporting and written incident follow-up?

    Do you receive regular reporting and written incident follow-up?

    Regular updates on your IT’s health, plus a written summary after any security incident.

0/ 24

0 of 12 answered. Your band and next steps unlock when all twelve are scored — no email needed.

What the law firm IT self-assessment covers

The assessment scores your firm across twelve areas that matter most for an Alberta law practice — the ones that surface after a breach, during a cyber-insurance renewal, or in a client security questionnaire. They group into five themes:

Governance & accountability

  • A named, budgeted owner for IT with an annual review
  • Written answers to provider due-diligence questions
  • Routine reporting and written incident follow-up

Data protection

  • A current, written map of where client data lives
  • Encrypted, centrally-managed and monitored devices
  • A secure client file-exchange method staff actually use

Access & fraud prevention

  • Policy-enforced MFA with legacy sign-in blocked
  • A verified callback rule for every payment instruction

Continuity

  • Fast, self-serve retrieval of any closed file
  • A documented, tested backup restore in the last year

Modern risk

  • A written remote-work standard (access, printing, disposal)
  • A written AI-use policy with firm-provisioned tools

Why Alberta law firms use it

Alberta firms hold some of the most sensitive information in the province — client funds, privileged files, and personal data covered by PIPEDA and the Law Society of Alberta’s expectations. When something goes wrong, the question is rarely whether you had good intentions; it’s whether you can show the controls were in place.

Most gaps aren’t exotic. They’re an MFA setting that was never enforced, a wire payment that was changed by a convincing email, or a backup no one had ever tested. This assessment turns those into a clear, honest picture in a few minutes — and shows you the smallest next step for each one. For the bigger picture of how we support legal practices, see IT for Alberta law firms.

What you get

  • An instant maturity band. Your total out of 24 and a banded result appear on screen as you answer — no email, no gate.
  • A specific next step for every weak area. Not just a score. Each item you rate low comes with a concrete, plain-language action.
  • An optional personalised PDF. Emailed only if you ask for it — with the booking option placed next to your three lowest-scoring items.

Related from AltaCom

Law firm IT self-assessment

Frequently asked questions

Yes — it is completely free, and you do not need to enter an email to see your score, your maturity band, or the per-item feedback. An optional emailed PDF report is the only thing an email is used for.

About five minutes. Your answers are saved in your browser as you go, so you can pause to check something with a colleague and come back to finish later.

Your answers are recorded anonymously — no name, firm name, email, or other identifying details are attached to them. Entering an email to receive the PDF report is a separate, optional step, and it is never stored alongside your answers.

Twelve areas Alberta law firms are measured against after an incident or during a cyber-insurance renewal: IT accountability, a client-data map, enforced MFA, payment-fraud controls, device security, closed-file retrieval, secure client exchange, remote-work standards, provider due diligence, tested backups, an AI-use policy, and routine reporting.

Managing partners, office managers, and IT leads at Alberta law firms of any size — from solo practices to firms with 25+ lawyers. No technical knowledge is needed; each question includes plain-language guidance.

An instant maturity band out of 24, a specific recommended next step for every area you scored low, an optional personalised PDF report, and — only if you want it — a no-obligation call to walk through your three lowest-scoring items.

Yes. It is built around the obligations Alberta firms actually face, including Law Society of Alberta expectations, PIPEDA, client-confidentiality and privilege duties, and the security questionnaires cyber-insurers now require.

No. The assessment runs entirely in your web browser, and the PDF report is generated on your own device.

Get a Free IT Audit →