A client sits across from you and hands over a passport, a medical history, bank statements, employment records, their children's names, and the reason they left the one place they called home.
They do it because they have to. They also do it because they trust you. That file is not a set of documents. It is a person's whole story, and for the length of the matter, your firm is the only thing standing between it and everyone else. Which raises a question most firms have never been asked directly. Where does that story end up?
Follow one passport scan
A client emails you a scan of their passport. Here is the usual path.
It arrives in an inbox, and it stays there. Someone opens it on a laptop, so now there is a copy in a downloads folder. It gets filed into the document management system, which is the copy the firm knows about. That system syncs to the cloud, so there is another. A clerk forwards it to a colleague to check a detail, and now it is in a second inbox and a second downloads folder. The nightly backup picks up all of it.
One email, and that passport now lives in 6 or 7 places. Most firms can account for 2 of them.
This is not carelessness. It is how digital practice works, and it happens the same way at a 4-person firm and a 40-person firm. But it leads somewhere uncomfortable: you cannot protect a document you cannot locate, and you cannot answer a client's question about their data if you do not know where it is.
Confidentiality and security are not the same thing
Every lawyer understands confidentiality. It is a professional obligation, and firms take it seriously in the ways they can see: what gets discussed where, who sits in on which meeting, what leaves the office.
Security is the set of technical controls that make confidentiality possible in a system where files copy themselves as a side effect of ordinary work. A firm can be scrupulous about the first and have real gaps in the second, and the gap is usually invisible until something goes wrong.
4 ways the story gets out
These are the patterns that come up repeatedly in legal services.
Ransomware, timed badly. Ransomware encrypts files and holds them. For most businesses that means downtime. For an immigration practice it can mean losing access to case files in the days before an IRCC deadline, where the consequence lands on a client's status rather than the firm's calendar.
An invoice that is not an invoice. An attacker reading a firm's email for a few weeks learns the tone of its correspondence, which matters are active, and when a client is expecting to send money. The message redirecting that payment does not look like an attack. It looks like business.
The email that went one address too far. Immigration work moves identity documents constantly. A misdirected message, a link shared with permissions set too broadly, or an intercepted attachment puts a client's passport somewhere it should never be, and there is no recalling it.
A password that was reused. When staff credentials appear in a breach somewhere else and the same password protects firm systems, nobody has to break in. They sign in, and it looks like a normal Tuesday. Firms often find out months later.
What keeps it contained
No single product solves this. A small number of controls, applied consistently, does most of the work.
Find the data first. Sensitive data discovery locates client information across files, endpoints, and cloud systems, including the copies nobody remembers making. Every other control depends on knowing what you hold and where.
Protect against the email that looks like business. The dangerous message is often the one with no link and no attachment, just a plausible request. Protection has to weigh intent and context rather than scan only for known threats.
Make backups something you have tested. A backup nobody has restored is an assumption. Offline, monitored backups turn a ransomware incident from a crisis into an inconvenience.
Watch for credentials before someone uses them. Dark web monitoring surfaces exposed staff credentials while changing a password still fixes the problem.
Have someone accountable at 3 AM. Detection without response is a notification. If something starts on a Saturday night, the question is not whether an alert fired. It is who acted on it, and how fast.
Compliance is the floor
Canadian firms handling personal information fall under PIPEDA, and immigration practices handle a great deal of it. Meeting those obligations matters. It is also worth saying plainly that compliance is a minimum standard rather than a security strategy. A firm can satisfy every documentation requirement and still be one reused password away from a bad month.
What we help firms build is evidence the controls are real: policy, implementation, monitoring, and reporting you can put in front of a client or a regulator without hedging.
Come find us at CILA
Your firm exists to protect your clients' futures, not to run a security operation. That is our role.
We are exhibiting at the CILA Conference in Toronto on October 5, and we are sponsoring the reception at 5:00 PM. Stop by either one.
Quick Intelligence is a Canadian managed security and IT provider. We have operated since 2011 and run a security operations centre 24 hours a day.
Experience technology humanized.