Law firms have unique IT requirements — SRA compliance, client confidentiality, email security. Here's what to look for when choosing an IT provider.
If you run a law firm, your IT isn't just a convenience — it's a compliance obligation. The Solicitors Regulation Authority expects you to protect client data, and if something goes wrong, "our IT provider didn't set it up properly" is not a defence the SRA is interested in hearing.
The problem is that most general IT support companies don't understand the regulatory environment law firms operate in. They'll set up your email, install antivirus, and call it done. Meanwhile, your client communications are unencrypted, your staff are accessing case files from personal devices with no controls, and your email domain has no authentication configured — leaving you wide open to spoofing.
Choosing IT support for a law firm isn't about finding someone who can fix printers. It's about finding a provider who understands why your requirements are different from a marketing agency or a retail shop.
What to Look For
1. SRA Compliance Awareness
Your IT provider should know what the SRA expects regarding data protection and information security. That means they should be able to talk fluently about the SRA's requirements around client confidentiality, data handling, and cybersecurity — not just nod along when you mention compliance and then Google it afterwards.
Ask them directly: have they worked with other law firms? Can they explain what SRA compliance means for your IT setup? If the answer is vague, keep looking.
2. Proper Email Security (DMARC, DKIM, SPF)
Email is still the primary communication channel for most law firms — and it's the primary attack vector too. Your IT provider should configure your email domain with SPF, DKIM, and DMARC as a baseline. These three protocols stop attackers from sending emails that appear to come from your domain.
Without them, a criminal can send an email that looks exactly like it came from your firm — requesting bank details for a completion, for example. This has happened to real firms, with real losses in the hundreds of thousands.
If you don't know whether your domain has DMARC configured, ask your IT provider. If they don't know what DMARC is, that tells you everything you need to know about their suitability for a law firm.
3. Conditional Access and Device Control
Your staff probably work from home some of the time. Maybe they check email on their personal phones. That's fine — but only if there are proper controls in place. Conditional Access policies in Microsoft 365 let you enforce rules like: only allow access from managed devices, require multi-factor authentication when logging in from outside the office, block access from countries you don't operate in.
Without these controls, a compromised personal device becomes a direct route into your client files. A good IT provider will set this up as standard, not as an optional extra you have to ask for.
4. Data Loss Prevention
Law firms handle some of the most sensitive information any business touches — financial records, medical information, confidential agreements, privileged communications. Your IT setup should include data loss prevention (DLP) policies that stop sensitive information from being accidentally emailed to the wrong person, shared externally, or uploaded to unauthorised cloud services.
Microsoft 365 has built-in DLP capabilities, but they need to be configured and tuned for your firm. An IT provider who knows legal will set these up as part of onboarding.
5. Secure Document Management
Case files, contracts, and client correspondence need to be stored securely with proper version control and access permissions. Whether you use a dedicated case management system like Clio, LEAP, or Actionstep, or rely on SharePoint and Teams, your IT provider should ensure that documents are organised, backed up, and accessible only to the right people.
Ask how they handle permissions. If the answer is "everyone has access to everything," that's a problem — both practically and from a compliance perspective.
6. Cyber Essentials Certification Support
Many law firms now need Cyber Essentials certification, either because the SRA recommends it or because clients and insurers require it. Your IT provider should be able to get your infrastructure to the point where certification is straightforward — and ideally, they should manage the technical submission for you.
Red Flags to Watch For
- They've never worked with a law firm. Legal IT has specific requirements. General IT knowledge isn't enough.
- They can't explain their approach to compliance. If they treat compliance as a checkbox rather than an ongoing requirement, your firm is at risk.
- No mention of email security. If DMARC, DKIM, and SPF aren't part of their standard setup, they're behind.
- They don't offer device management. In a profession where staff regularly work remotely, unmanaged devices are a liability.
- Slow response times with no SLA. When a fee earner can't access their files, every hour costs money. Your provider should guarantee response times in writing.
Questions to Ask Before Signing
Before you commit to an IT provider, ask these five questions:
- Which other law firms do you currently support?
- How do you handle SRA compliance requirements in your IT setup?
- What email security protocols do you configure as standard?
- How do you manage access from personal and remote devices?
- What happens if we have a data breach — what's your incident response process?
The answers will tell you quickly whether they understand legal IT or are just a general IT company hoping to figure it out on the job.
Key takeaway: Law firms need IT support that understands SRA compliance, email security, and client confidentiality at a technical level — not just a helpdesk that resets passwords. The consequences of getting it wrong are regulatory, financial, and reputational.
Senri works with law firms across London to provide IT support that meets SRA requirements from day one. If you want to see how we approach it, take a look at our IT support for solicitors page, or read more about our cybersecurity services.
Related Reading
Want to talk about this?
Book a free 15-minute call and we'll discuss how this applies to your business.
Get IT tips in your inbox
Practical advice for small businesses. No spam.
