Our regular hours are Monday to Friday, 7am to 5pm MT. For emergencies we are 24/7 on the same number, and it is always answered by a person. Call (604) 813-7881 and ask Tony for your free 30-minute insurer readiness review. No pressure, no jargon.
Law society and cyber insurance readiness in BC and Alberta
What the Law Society and your insurer are likely to ask, and where IT fits
Regulators and insurers tend to ask what was in place, not what you meant to do. Here is what the BC and Alberta sources say, in plain words. This is IT guidance, not legal advice.
Ask Tony for a free 30-minute insurer readiness review.
What you can show
- Every quarteran insurer-ready evidence report, on our premium plan
- 30 days lockedbackups no one can delete early, not even us
- 24/7a person answers (604) 813-7881
What happens
Illustrative, not a client story. This is a made-up sketch that pulls together what the sources below describe. It is not about a Benson Hunt client, and it does not match any single public case.
After a bad incident, a small firm hears from two directions in the same week. Its law society wants to know what happened to client records, and whether anything left the firm’s custody or control. Its insurer wants to know what was in place on the day: sign-in protection, backups, training.
Nobody at the firm has a tidy answer. The person who set up the IT left last year, the settings live in four different places, and the last test of the backups was a while ago.
Nothing in this story is about bad intent. It is about not being able to show, quickly and calmly, what the firm had already done right.
In BC
Rules from the Law Society of BC. Cyber cover through the Lawyers Indemnity Fund.
In Alberta
Rules from the Law Society of Alberta. Cyber cover through ALIA, which says it does not cover funds transfer fraud.
Why it happens
In plain words, and with nobody to blame.
Rules talk about reasonable steps
Law society rules in BC and Alberta ask for reasonable security and competence with technology. They do not hand you a checklist, so firms are left to decide what reasonable looks like.
Insurers set their own minimums
Cyber programs can come with security conditions, such as multi-factor sign-in, that affect what you pay or can claim. The details differ between programs and change over time.
Evidence lives in many places
Sign-in settings, patch status, backup logs, training results and who has access sit in different systems. Pulling them together on a bad day is hard.
What the sources say
Read the current documents yourself, or ask your broker. Terms change, so we do not quote dollar amounts here.
In BC
- Technological competence. Since March 2024, BC Code rule 3.1-2 commentaries [4.1] and [4.2] address the level of technological competence expected of lawyers. Law Society e-brief, March 2024 and BC Code amendments
- Records and reporting. Rule 10-4 requires reasonable security for records, and an immediate written report to the Law Society if custody or control is lost. Law Society advisory
- Technology guidance. The Law Society keeps a page of technology guidance for lawyers. Lawyer technology
- Cloud. Its cloud checklist suggests informed client consent, and notice if data is stored outside Canada. Cloud checklist
- Funds transfer fraud. Steps to take, including trust shortage reporting under Rule 3-74. Law Society guidance
- Cyber cover. The Lawyers Indemnity Fund includes a cyber policy, arranged through Coalition, in the indemnity fee, with minimum security standards. LIF’s information sheet (updated March 2023, so check current terms with LIF) says the policy protects firms against various cybercrimes, including phishing and ransomware, and that multi-factor sign-in can reduce the deductible for certain claims. LIF information sheet, March 2023 and LIF FAQ
In Alberta
- Technological competence. Code rule 3.1-2, commentaries [5] and [6], requires lawyers to maintain technological competence: to understand the risks and benefits of the technology they use, and to supervise staff and consultants. Law Society of Alberta Learning Centre
- Competence and confidentiality. Code rules 3.1-2 and 3.3-1 apply the same way whether client information is on paper, on a firm server or in the cloud. The Law Society’s software considerations list questions for vendors: individual logins, multi-factor sign-in, independent testing, data stored in Canada, and export and restore. Software considerations
- Cybersecurity advice. The Law Society recommends email authentication, MFA and training against impersonation. Protecting your practice
- After a breach. “Privacy Breached: Now What?” covers telling clients and your insurer, and considering the Alberta Information and Privacy Commissioner. Read the guide The Commissioner’s guidance says PIPA section 34.1 calls for notifying the Commissioner where there is a real risk of significant harm. Whether and how that applies to your firm is a question for your own lawyer. OIPC guidance
- Cyber cover. ALIA’s universal cyber program, through Beazley, covers breach response, cyber extortion, data recovery, data and network liability, and regulatory defence. ALIA says it does not cover funds transfer or social engineering fraud, or business interruption. It recommends MFA, patching, backups, annual training, and switching off ex-employee access immediately. ALIA cyber program and social engineering fraud
Wire fraud is where BC and Alberta differ most. LIF’s March 2023 information sheet says BC’s cyber policy protects against various cybercrimes, including phishing. ALIA says Alberta’s program does not provide eCrime cover, including losses from fraudulent instructions or funds transfer fraud. So the same fake wire instruction could be treated very differently in the two provinces. Check current terms with LIF, ALIA or your broker.
Across Canada, the Federation of Law Societies’ Model Code covers technological competence in rule 3.1-2.
Who you may have to tell after a breach
A short map, not legal advice. Your own lawyer decides what applies to your firm.
- BC firms, under BC PIPA. There is no mandatory breach notification for private organizations. The BC Commissioner strongly recommends reporting breaches anyway, as a best practice. OIPC BC
- Alberta firms, under Alberta PIPA section 34.1. Notify the Commissioner without unreasonable delay where there is a real risk of significant harm to someone. OIPC Alberta guidance, April 2024
- PIPEDA, the federal law. It applies to federally regulated organizations, and to personal information that crosses provincial or national borders in commercial activity. Breaches that pose a real risk of significant harm must be reported to the federal Commissioner. PIPEDA in brief and breach reporting
- Your law society. In BC, Rule 10-4 calls for an immediate written report if records leave your custody or control. In Alberta, start with the Law Society’s Privacy Breached: Now What?
- Your insurer. LIF in BC or ALIA in Alberta, plus any private cyber policy you hold. Check each policy for how and when to report.
What we can do is work out quickly what happened technically, which is the first thing each of them will ask.
What fixes it
IT cannot make a firm compliant on its own, and we are not lawyers. What we can do is build the safeguards these sources keep pointing to, and help you show them.
- Multi-factor sign-in. ALIA and LIF both point to it, and it is one of the first things an insurer is likely to ask about.
- Patching, and Huntress Managed EDR with 24/7 monitoring. ALIA recommends patching, and we recommend a weekly schedule. Huntress Managed EDR runs on every computer we manage, and alerts go by email and SMS to our team, 24/7. Huntress, a separate security team, works alongside us.
- Microsoft 365 Business Premium, as standard for firms under 300 users. It brings Intune device management, Defender for Business, Conditional Access, message encryption and BitLocker encryption managed through Intune. What every law firm should have
- 3-2-1 backups with an offsite copy in Canada. Three copies, two kinds of storage, one offsite, held in Vancouver, BC. We do spot checks on multiple copies of the backups and a yearly disaster recovery test. ALIA and LIF both recommend backups, and a backup is only real once a test restore has proven it works.
- Awareness training. Short quizzes, a monthly report card, and management hears when someone fails a quiz. How our training works
- Access that ends when employment ends. ALIA recommends disabling ex-employee access immediately. Onboarding and offboarding
- Individual logins, not shared ones, and a Hyper-V server layout where the sign-in server and the app server are kept apart. Hyper-V for law firms
An insurer-ready evidence report, every quarter
The sources above keep asking the same thing: what was in place? On our premium plan, every quarter we hand you a short report you can pass to your insurer, your broker or your law society.
- Multi-factor sign-in status for your accounts.
- Backup test results.
- Patch and security status for your computers.
- Your team’s training report card.
- A summary of the security events Huntress and our monitoring dealt with.
It shows what is in place and what we checked. It does not replace your insurer’s questions or legal advice.
Questions we help you answer
Ask us which of these matter most for your firm.
- Could you show an insurer, a broker, a client’s security questionnaire or your law society what is in place on a given date?
- Which of your systems have multi-factor sign-in, and which do not?
- When was the last test restore, and what did it show?
- Who has access to what, and who reviews it?
- Where does each vendor keep your data, and can you get it back out?
Why it matters, in plain words
The tech behind this page, and why it’s there. See all the plain guides.
Multi-factor sign in
Why a stolen password shouldn’t open a lawyer’s inbox
Passwords leak. A second check on a phone or a security key stops most stolen passwords from working.
Immutable backups
Why ransomware goes after the firm’s backups first
Without backups, the firm has to pay or rebuild. Our copies are locked for 30 days, and no one, not even us, can delete them early.
Business firewall
Why the internet company’s router isn’t a firewall
It connects you. A business firewall inspects traffic, stops known attacks and keeps guests off the firm’s network.
Law society and insurance questions we hear
Does our cyber policy cover wire fraud?
It depends on the province and the program. ALIA says its universal cyber program does not provide eCrime cover, including funds transfer fraud and fraudulent instructions, so Alberta firms should ask ALIA or a broker about options. In BC, LIF’s March 2023 information sheet says its cyber policy protects against various cybercrimes, including phishing. Check the current terms with LIF. We cannot tell you what a policy will pay, but your broker or the fund can. How fake wire instructions work
Does multi-factor sign-in lower the deductible?
LIF’s information sheet says it can, for certain claims in BC. Check LIF’s current documents for the terms and amounts, because they change.
Do we have to tell clients or the Law Society about a breach?
That is a question for your firm’s own lawyer. The who you may have to tell list above is a starting point. What we can do is help work out quickly what happened technically, which is the first thing everyone will ask.
Is this legal advice?
No. It is IT guidance in plain words. Check the current rules and talk to your own lawyer.
