The trust account is the target. This is how your firm protects it.
Most trust-account losses don't come from a clever hack - they come from a believable email at the worst moment, and a payment that went out before anyone called to confirm. This is the checklist we built for small and boutique GTA firms: a verify-before-you-wire routine, a confidentiality-incident plan with your LSO and LawPRO duties in mind, and the email tells that give a fake "client" or "opposing counsel" away. Print it, walk it through at your next firm meeting, and pin it by the desk where the money moves.
- A trust-account payment-verification SOP your clerk and your lawyers can follow the same way, every time
- A confidentiality-incident checklist built with LSO and LawPRO duties in mind - who you tell, and when
- The fake-counsel and fake-client email tells that the spoof gets wrong
- Works with the tools you already run - Clio, PCLaw, Worldox and your bank's portal
Yours free - no signup wall. Want the editable templates or a hand rolling it out? Just ask.
The trust-account payment-verification SOP
The single habit that stops most trust-account wire fraud is a phone call your firm makes the same way, every time - to a number you already had, not the one in the email. Adopt this as a written rule, not a good intention. Every person who can release funds should be able to recite it.
The confidentiality-incident checklist (LSO and LawPRO aware)
If a mailbox is compromised, a privileged file leaves the building, or a wire goes to a thief, the first hour matters and panic is the enemy. This is practical readiness so your firm moves in order instead of freezing - it is not legal advice, and it does not replace your own counsel, LSO guidance, or your LawPRO obligations. Decide these answers now, while it's calm.
Fake-counsel and fake-client email tells
The spoof is good, but it's never perfect - it borrows your firm's credibility and gets small things wrong. Teach the whole firm, lawyers and admin alike, to slow down on anything that moves money or releases a file and to look for these specific tells. None of them is proof on its own; two or three together means verify out-of-band before you act.
Rehearse it before it's real
A checklist on the wall changes behaviour only if the firm has actually practised it under a little pressure. That's what The Cyber Fire Drill does - a live, on-site, real-but-safe rehearsal of the exact attacks above, run with your real team, under NDA, with no malware, no real client files, and no one named and shamed. People remember what they lived through, not what they skimmed.
Built for small and boutique Ontario law firms. Print this, walk it through at your next firm meeting, and pin the verification SOP by the desk where trust funds move. This is practical readiness, not legal advice - confirm your specific LSO, LawPRO, and privacy obligations with counsel and your insurer.
A checklist is a start. A drill makes it stick.
The Cyber Fire Drill runs these exact attacks against your team - safely - so the habits in this checklist become muscle memory. Three hours, on-site, with a scored 30-day plan.
Is this legal advice on our LSO or LawPRO obligations?
No. This is practical security readiness, written to be useful the day you read it - a verification routine, an incident checklist, and the email tells your team should know. It's built with LSO and LawPRO duties in mind, but your specific obligations on trust-account losses, breach reporting, and notifying your client or insurer should be confirmed with counsel and with LawPRO, not taken from a checklist.
We use Clio, PCLaw and Worldox - does this fit how we actually work?
Yes. The verification SOP is written to attach to your real process - record the callback on the matter in Clio or PCLaw, and treat any "sign in again" prompt for Worldox or your document system as something to reach through your normal login, never a link in an email. The habits work the same whichever platform you run.
What's the difference between this checklist and the Cyber Fire Drill?
This checklist tells your firm what to do. The Cyber Fire Drill makes your team actually do it - a live, on-site, real-but-safe rehearsal of trust-account wire fraud and confidentiality attacks, run with your real people under NDA, that leaves you with a scored 30-day plan. The checklist is free and earns its place on the wall; the drill is how the habit sticks.
More resources in the resource library · questions? contact@bastani.org