Bastani Security
Book the Fire Drill
Free resource · For Ontario law firms · Toronto & GTA

The trust account is the target. This is how your firm protects it.

Most trust-account losses don't come from a clever hack - they come from a believable email at the worst moment, and a payment that went out before anyone called to confirm. This is the checklist we built for small and boutique GTA firms: a verify-before-you-wire routine, a confidentiality-incident plan with your LSO and LawPRO duties in mind, and the email tells that give a fake "client" or "opposing counsel" away. Print it, walk it through at your next firm meeting, and pin it by the desk where the money moves.

  • A trust-account payment-verification SOP your clerk and your lawyers can follow the same way, every time
  • A confidentiality-incident checklist built with LSO and LawPRO duties in mind - who you tell, and when
  • The fake-counsel and fake-client email tells that the spoof gets wrong
  • Works with the tools you already run - Clio, PCLaw, Worldox and your bank's portal
Email me the editable pack

Yours free - no signup wall. Want the editable templates or a hand rolling it out? Just ask.

01

The trust-account payment-verification SOP

The single habit that stops most trust-account wire fraud is a phone call your firm makes the same way, every time - to a number you already had, not the one in the email. Adopt this as a written rule, not a good intention. Every person who can release funds should be able to recite it.

Treat any new or changed payment instruction - bank, transit, institution number, payee name, or a switch from cheque to wire - as unverified until a human confirms it out-of-band.
Verify by calling back on a number you already had on file (the engagement letter, the matter intake, a prior statement), never the number or reply-to in the request email or its signature block.
Confirm the change by speaking to a known person and reading the full account details back to them - don't accept a one-word "yes" or a confirmation that arrives only by email.
Hold the standard for everyone equally: opposing counsel, your own client, a referring lawyer, and an internal "I'm in court, just send it" message all get the same callback before any release.
Build a deliberate pause into closing day - funds moving under deadline pressure is exactly when the spoofed "updated wiring details" email lands, so the verification step is non-negotiable, not skippable when you're busy.
Record the verification on the matter file in Clio or PCLaw - who you called, the number, the time, and who confirmed - so the firm can show it was done and so the next person sees it too.
Set a firm-wide dollar threshold above which a second authorized person independently re-verifies before release; large trust balances are the prize, so two sets of eyes on the big ones.
Name a fallback: if you cannot reach a known contact to verify, the funds wait. "We couldn't confirm, so we held it" is always the right answer.
02

The confidentiality-incident checklist (LSO and LawPRO aware)

If a mailbox is compromised, a privileged file leaves the building, or a wire goes to a thief, the first hour matters and panic is the enemy. This is practical readiness so your firm moves in order instead of freezing - it is not legal advice, and it does not replace your own counsel, LSO guidance, or your LawPRO obligations. Decide these answers now, while it's calm.

Write down, in advance, who gets called first: the responsible lawyer, the managing partner, your IT provider, and the person who can freeze a payment at the bank - names and after-hours numbers on one page.
If money has moved, call the bank immediately to attempt a recall; the window is measured in hours, so the call comes before the post-mortem.
Preserve evidence before you clean up: don't delete the suspicious emails, don't wipe the mailbox - capture and keep them, because they tell you what the attacker saw and touched.
Reset credentials and enable or re-check MFA on the affected mailbox and anyone who shares access, then check inbox rules and forwarding for the quiet auto-forward an attacker leaves behind.
Scope the confidentiality exposure honestly: which client matters were in that mailbox or that document-management system, and whose privileged information may have been seen.
Know your reporting paths before you need them - when a real or suspected loss of trust funds or a privacy breach triggers obligations to the client, the Law Society of Ontario, and your LawPRO coverage - and confirm the specifics with counsel and your insurer, not from memory.
Notify LawPRO early rather than late; reporting a circumstance that might become a claim protects coverage, and the time to learn the process is not mid-crisis.
Keep a short, factual written timeline as you go - what happened, when, what you did - because you'll need it for the client conversation, the LSO, and the insurer, and reconstructing it later is far harder.
Decide who speaks to the affected client and what they'll say; clients forgive a fast, honest "here's what happened and what we're doing" far more readily than silence.
03

Fake-counsel and fake-client email tells

The spoof is good, but it's never perfect - it borrows your firm's credibility and gets small things wrong. Teach the whole firm, lawyers and admin alike, to slow down on anything that moves money or releases a file and to look for these specific tells. None of them is proof on its own; two or three together means verify out-of-band before you act.

The reply-to or sender address is almost-but-not-quite right: a swapped letter, a .net for a .com, a look-alike firm domain, or a display name that doesn't match the actual address when you hover over it.
A payment instruction changes at the last minute - "our bank had an issue, please use these updated details" - timed precisely to a closing or a trust release.
Urgency and secrecy travel together: "I'm heading into a hearing," "handle this quietly," "don't loop in the clerk" - pressure designed to skip your verification step.
The request pushes you off your normal channel - a wire where you'd usually cut a cheque, a personal phone number for confirmation, a request to take the conversation to text.
A "client" or "opposing counsel" email lands in an existing thread but the tone, sign-off, or phrasing is subtly off - the attacker has been reading the thread and is impersonating someone in it.
A link to "review the closing documents" or a fake DocuSign or Worldox login that asks you to sign in again - go to the source you already use, never the link in the message.
An attachment or instruction arrives from a real, known contact whose account may be compromised - familiarity is not verification; the callback rule still applies.
The email asks for SINs, banking details, or a full client file "to confirm," or asks a junior staffer to bypass the lawyer responsible for the matter.
04

Rehearse it before it's real

A checklist on the wall changes behaviour only if the firm has actually practised it under a little pressure. That's what The Cyber Fire Drill does - a live, on-site, real-but-safe rehearsal of the exact attacks above, run with your real team, under NDA, with no malware, no real client files, and no one named and shamed. People remember what they lived through, not what they skimmed.

The Heist puts your lawyers, clerks and admin through a safe trust-account wire-fraud scenario, tuned to your matters and your tools, so the verification habit is muscle memory when it counts.
You leave with a scored readiness snapshot and a written, prioritized 30-day action plan you can act on the next morning - not a dashboard nobody logs into.
Run by practitioners who train for this - with certified senior partners for the deep technical work, named in every contract, and a facilitator who makes it land. Right-sized for a small GTA firm.
If you need the policies, risk register and evidence behind your LSO and LawPRO duties on paper, our GRC practice picks up where the training leaves off.
Start with this free checklist today; when you're ready to rehearse the attack before it's real, book a Cyber Fire Drill for your firm - contact@bastani.org or (647) 835-6368.
How to use this

Built for small and boutique Ontario law firms. Print this, walk it through at your next firm meeting, and pin the verification SOP by the desk where trust funds move. This is practical readiness, not legal advice - confirm your specific LSO, LawPRO, and privacy obligations with counsel and your insurer.

A checklist is a start. A drill makes it stick.

The Cyber Fire Drill runs these exact attacks against your team - safely - so the habits in this checklist become muscle memory. Three hours, on-site, with a scored 30-day plan.

Book the Fire Drill See the law firms page →
Is this legal advice on our LSO or LawPRO obligations?

No. This is practical security readiness, written to be useful the day you read it - a verification routine, an incident checklist, and the email tells your team should know. It's built with LSO and LawPRO duties in mind, but your specific obligations on trust-account losses, breach reporting, and notifying your client or insurer should be confirmed with counsel and with LawPRO, not taken from a checklist.

We use Clio, PCLaw and Worldox - does this fit how we actually work?

Yes. The verification SOP is written to attach to your real process - record the callback on the matter in Clio or PCLaw, and treat any "sign in again" prompt for Worldox or your document system as something to reach through your normal login, never a link in an email. The habits work the same whichever platform you run.

What's the difference between this checklist and the Cyber Fire Drill?

This checklist tells your firm what to do. The Cyber Fire Drill makes your team actually do it - a live, on-site, real-but-safe rehearsal of trust-account wire fraud and confidentiality attacks, run with your real people under NDA, that leaves you with a scored 30-day plan. The checklist is free and earns its place on the wall; the drill is how the habit sticks.

More resources in the resource library · questions? contact@bastani.org