Call Book the Fire Drill
For law firms · Toronto & GTA

Your trust account is the most attractive target in the building.

Your lawyers and staff rehearse those exact attacks - safely - so the trust account and the file hold when it’s real. Because large balances, time-pressured closings, and a duty of confidentiality make the firm a prime target for wire fraud and client-data theft, and the defence is a habit, not a product.

  • Run a safe trust-account wire-fraud scenario with your lawyers and staff
  • Build the verification habit that protects the trust account and the file
  • Leave with a verification SOP and a scored 30-day plan, LSO and LawPRO in mind

A 20-minute scoping call, then one flat quote. No jargon, no pressure.

A law-firm professional
Built for law firms like yours
What your firm walks away with

Live and on-site for your whole team - then a plan you can act on the next morning.

  • A trust-account / payment verification SOP
  • A confidentiality-incident response checklist
  • A firm-wide phishing routine for lawyers and staff
  • A scored 30-day plan, prioritized by real risk
Book the Fire Drill

20-minute call · no obligation · flat quote after.

The Cyber Fire Drill
live · on-site · GTA
Insured & authorized in writing - certified senior partners for deep technical work Safe & authorized - no malware, no shaming Built around trust-account fraud and confidentiality - a law firm’s two biggest exposures Toronto & the GTA
The attack that targets you

The trust-account wire switch

A law firm holds money and secrets, and both are under deadline pressure. That combination is exactly what business email compromise is built to exploit.

  1. 1
    The foothold

    An attacker gets into one mailbox at the firm or on the other side of a deal - often a single reused password or a convincing login page is enough.

  2. 2
    The study

    They read quietly: the closing, the parties, the trust-account language, the way your firm phrases a request. They learn to sound exactly like you.

  3. 3
    The switch

    As funds are due to move, “updated” wiring or trust-account details arrive - to a client, to opposing counsel, or to your own clerk. Everything looks normal.

  4. 4
    The fallout

    The money is gone, and now it’s a trust-account problem, a client-confidentiality problem, and an LSO and LawPRO problem - all at once.

No software is breached - the attacker borrows the firm’s own credibility at the worst moment. The defence isn’t a product; it’s a verification habit every lawyer and clerk shares, and that is what we drill.

Rehearse it before it’s real
In the room

What your firm will face in the room

We run the attacks that actually hit law firms - authorized, safe, and under NDA. We never touch real client files, run no malware, and never name-and-shame anyone.

Trust-account wire fraud

The signature scenario: a last-minute change to trust or closing wiring, timed to a live matter. The firm learns to verify funds out-of-band, every single time.

Confidentiality breach & exfiltration

How one compromised inbox can quietly leak privileged files - and the handling habits that keep a client’s matter from leaving the building.

Fake-counsel & fake-client email

A message that looks like opposing counsel, a client, or the court - carrying a malicious link or a bad instruction. Your team learns to go to the source.

Ransomware on the DMS

A locked document-management system the morning of a filing. A guided tabletop on what the firm does in the first hour - before panic sets in.

What you walk away with

Not a slide deck. A plan, and new habits.

Every Fire Drill ends with something you can use the next morning - written down, scored, and built for how your team actually works.

A trust-account / payment verification SOP the firm adopts immediately
A confidentiality-incident response checklist, LSO and LawPRO aware
A plain-English leadership readout: where you stand and what to fix first
A scored 30-day action plan, and a follow-up office hour to keep it moving
Simple pricing
Fire Drill 90 (live team training) from $1,800 +HST

The Cyber Fire Drill, tailored to law firms. One flat fee, on-site, under NDA, for your whole firm. See the full offer ladder - from the $750 baseline checkup to the Cyber Readiness Day - on the pricing page.

Book the Fire Drill See all pricing
Questions

The things teams in your sector ask first.

Is this safe and confidential?

Yes. We work under an NDA, never touch real client files, run no malware, and don’t harvest credentials. Every scenario is a controlled, authorized exercise designed to build skill, not to expose anyone.

Does this help with our LSO and LawPRO obligations?

It supports them. You leave with a trust-account verification SOP and a confidentiality-incident checklist built with those duties in mind. It’s practical readiness, not legal advice - and our insurance-readiness service can formalize policies if you need them.

We have a managed IT provider - why this?

They secure the systems; we train the people. Trust-account fraud and confidentiality breaches almost always start with a human, not a server. Your IT provider is welcome to join the session.

How long is it, and who should attend?

About three hours for the whole firm - partners, associates, clerks and admin, anyone who touches the trust account, client files or email. We schedule around your matters, evenings included.

When you need proof on paper
Firms that need confidentiality on paper

We build the confidentiality and security policy pack and the questionnaire evidence that sit behind your LSO and LawPRO duties - practical readiness, not legal advice - with vetted specialist partners for formal advisory when a matter calls for it.

See insurance readiness

Rehearse the attack before it’s real.

Book a 20-minute scoping call. We’ll tailor the drill to your law firms, send one flat quote, and get a date on the calendar.

Book the Fire Drill (647) 835-6368

Not ready to book? Grab the free Law firm trust-account checklist

contact@bastani.org · WhatsApp