- Home
- Solicitors
IT support for solicitors and law firms that protects client work, not just devices
Remedian supports law firms across Manchester and the North West with helpdesk support, Microsoft 365, cyber security, backup, legal applications, onsite engineering and clear technical ownership.
The aim is practical: keep confidential information controlled, staff productive, systems recoverable and suppliers accountable without pretending that an IT product alone makes a firm compliant.
See what legal IT support includes Book a legal IT review
01
Legal IT support has to understand confidentiality, deadlines and money movement
A law firm does not simply hold ordinary office files. It handles client correspondence, identity documents, evidence, financial information, property transactions, court deadlines and privileged material. A support process that treats every incident as a generic laptop problem misses the real business risk.
The SRA Code requires firms to keep current and former clients’ affairs confidential. Technology cannot meet that obligation on its own, but poor identity controls, unmanaged devices, broad permissions and weak email security can undermine it quickly.
Support should follow the matter, not just the machine
When a fee earner cannot access a case-management system, a conveyancing completion email looks suspicious or a shared mailbox exposes more information than intended, the support team needs to understand the operational impact and escalate accordingly.
Remedian combines the service-desk process explained on our Managed IT Support page with controls and planning suited to regulated professional services. Firms based locally can also use our IT Support Manchester team for onsite requirements.
02
What IT support for solicitors and law firms should include
A useful agreement covers the user, device, identity, application, network and recovery layers together. It should also make clear where Remedian’s responsibility ends and where a legal software vendor, telecoms supplier or compliance adviser takes over.
Support for Outlook, Microsoft 365, devices, printers, access problems and daily faults, with escalation from first-line triage to senior engineering.
Hands-on work for networks, servers, Wi-Fi, new offices, meeting rooms, installations, audits and physical faults that cannot be solved remotely.
Microsoft Entra ID, multi-factor authentication, role-based permissions, privileged accounts and documented joiner, mover and leaver processes.
Exchange Online, Teams, SharePoint, OneDrive, retention, secure sharing, licensing, mail flow and tenant security settings.
Endpoint protection, email security, patching, firewall management, vulnerability work, awareness and support towards Cyber Essentials.
Agreed backup scope, monitoring, retention, immutable or isolated copies where suitable, restore testing and recovery priorities through secure backup.
Support for the environment around case-management, document-management, e-bundling and time-recording systems, with vendor coordination where product expertise is required.
Open actions, recurring faults, security gaps, supplier renewals, project planning, budget visibility and a roadmap management can follow.
Permissions, data access, approved-tool policy and practical guidance before staff use Microsoft Copilot, ChatGPT, Claude or other AI tools with client work. See AI Solutions.
Servers, switches, Wi-Fi, firewalls, broadband and leased lines coordinated through one support route, including server support where needed.
03
Confidentiality depends on identities, permissions and managed devices
Encryption is useful, but it does not fix an account that too many people can access. The starting point is knowing who has access to what, why they need it and how quickly that access is removed when a role changes.
Protect email, Microsoft 365 and remote access with methods appropriate to the account risk, rather than relying on passwords alone.
Separate normal user accounts from administration, reduce standing privileges and review access to sensitive matters, finance systems and shared locations.
Apply patching, endpoint protection, encryption, screen-lock, software and device controls consistently across laptops and desktops.
Create, change and revoke accounts through a documented process that includes mailboxes, legal applications, shared folders, mobile devices and supplier portals.
Use controlled links, expiry, permissions and appropriate collaboration locations instead of unmanaged attachments and personal file-sharing accounts.
Keep useful sign-in, email, device and administrative logs so unusual activity can be investigated and decisions can be evidenced.
A compliance boundary worth stating clearly
Remedian can implement and document technical controls. The firm remains responsible for its professional obligations, data-protection decisions, policies, supervision, retention rules and advice from its legal or compliance specialists.
04
Microsoft 365 and legal applications need one ownership model
Many law firms rely on Microsoft 365 alongside a case-management platform, document-management system, e-bundling service, time-recording tool, dictation software and third-party portals. Problems often sit between suppliers rather than inside one product.
We support the environment and coordinate the vendor
For systems such as LEAP, Clio, Proclaim and other legal platforms, we can support devices, identities, Microsoft 365, network access, email integration, printing, browser requirements, backups and permissions. Where the fault is inside the application, we work with the vendor and keep the support ticket moving.
We do not claim to be every software vendor. During onboarding we record the application owner, support contact, licence details, authentication method, integration points, backup responsibility and escalation route.
Microsoft 365 should be configured around legal work
- Exchange Online and shared mailbox permissions.
- Teams and SharePoint access for departments and matters.
- OneDrive, secure external sharing and mobile access.
- Retention, audit and security settings aligned with the firm’s policies.
- Copilot readiness based on the permissions users already hold.
05
For a law firm, the expensive attack is a changed bank account, not a locked server
Ransomware gets the headlines. The incident that actually empties a client account is quieter: a completion statement arrives with different bank details, someone pays it, and the money is gone within the hour.
These attacks work because they arrive inside a real conversation. The attacker has been reading the mailbox for days. They know the matter reference, the completion date, the names of both solicitors and the tone the firm writes in. Nothing about the email looks wrong, because almost nothing about it is.
One set of stolen credentials without multi-factor authentication gives an attacker months of correspondence to work from. Most firms find out from the client, not from a security alert.
After a mailbox is taken, the first move is usually a rule that moves replies out of the inbox so the real owner never sees the conversation. We alert on new forwarding and redirect rules rather than waiting for someone to notice.
A registered domain one character away from the firm's own, used to continue a thread from the outside. We monitor for the obvious variants and block them at the mail gateway.
A genuine old email quoted underneath a new malicious one. Awareness training that only teaches staff to spot bad spelling does not help here.
SPF, DKIM and DMARC configured and actually enforced, so a message claiming to come from your domain is rejected rather than delivered to the junk folder and fished back out.
Clear visual marking on mail from outside the firm, plus impersonation protection for partners, cashiers and anyone who signs off payments.
The control that stops this is a phone call, not a product
Every technical control above narrows the odds. None of them removes the need for a documented verbal check on bank details, made to a number the firm already held, before any transfer. Our job is to make sure the check is easy to follow and that the systems around it do not quietly undermine it. The check itself belongs to the firm.
Firms working towards Cyber Essentials already cover several of these controls. For a firm that wants the configuration tested rather than assumed, penetration testing is the next step.
06
Microsoft 365 is not a backup, and most firms find that out at the worst moment
Microsoft runs the service and keeps it available. Microsoft does not undertake to give you back a mailbox a leaver deleted eight months ago, or a SharePoint library someone overwrote. Retention settings help, but they are a policy, not a backup, and they can be changed by anyone with the right admin role.
A law firm holds material it may need to produce years after a matter closes. Backup scope and retention should be set against how long the firm actually keeps files, which is a decision for the firm, not a default we pick.
| What needs protecting | Typical approach | What we check |
|---|---|---|
| Exchange Online mailboxes | Daily backup with retention set to the firm's own file-retention period | Restore of a single item and a full mailbox, not just a green tick in a dashboard |
| SharePoint, OneDrive and Teams | Versioned backup covering document libraries, channel files and permissions | Whether permissions come back with the data, which is where most restores disappoint |
| Case and document management | Scope agreed with the application vendor, since responsibility varies by product and hosting | Who holds the backup, where it sits, and how a restore is actually requested |
| Servers and on-premises data | Local copy for speed plus an offsite copy that cannot be reached from the production network | Recovery time against what the firm can tolerate on a completion day |
An isolated copy is the part that matters
Modern attackers look for the backup before they encrypt anything. A backup reachable with the same administrator credentials as the live environment is not a recovery position. Immutable or network-isolated copies, with separate credentials, are what turn an incident into an inconvenience.
Isolate affected accounts and devices, revoke sessions and tokens, and stop the spread before anything else is attempted.
Capture logs and evidence before rebuilding. A firm that wipes and reinstalls immediately loses the ability to establish what was accessed.
Bring services back in the order the firm needs them, working from the recovery priorities agreed in advance rather than decided under pressure.
Confirm which systems, mailboxes and files were reached, so the firm can make its own decisions about notification with real information.
Where our responsibility ends
We handle the technical response and give the firm the facts it needs. Whether an incident is reportable to the ICO, what the SRA needs to know, what clients are told and when, and how the firm's insurer is engaged are decisions for the firm and its advisers. We support that process. We do not own it.
Backup scope, retention and restore testing are described further on our secure backup page.
07
Fee earners work from home, from court and from client sites, and the controls have to follow them
Legal work stopped being an office activity some years ago. A solicitor might open a matter file at home on Monday, take a hearing bundle to court on Tuesday and sit in a client's boardroom on Wednesday. The security model has to assume the network is untrusted, because most of the time it is.
Control the identity and the device, not the location
Rather than trying to define a safe network, we set conditions on access: the account has passed multi-factor authentication, the device is known to us, it is encrypted and patched, and the sign-in does not look unreasonable. Access is granted on that basis wherever the person happens to be.
That approach also handles the awkward cases honestly. A consultant on their own laptop, a locum covering a caseload for six weeks, or a partner checking mail on a personal phone each need a decision made in advance rather than an exception granted quietly.
Personal devices need a stated position
- Which applications may be used on an unmanaged device, and which may not.
- Whether firm data can be stored locally or only viewed.
- What happens to firm data on that device when someone leaves.
- How a lost or stolen device is reported and what we do when it is.
Most firms we speak to have never written this down. It takes an afternoon and removes a recurring argument.
08
Your COLP should not have to reconstruct the IT position from invoices
Law firms are asked to evidence their technical controls more often than most businesses. Cyber insurance renewals ask. Panel applications ask. Larger clients send security questionnaires before they instruct. A firm that has to chase its IT provider for answers each time is paying for support twice.
A dedicated account manager keeps a current picture and brings it to a scheduled review rather than assembling it on request.
What the firm owns, who uses it, how old it is, what it costs and when it stops being supported. This is the document that makes budgeting possible.
Tickets grouped by cause rather than counted. Ten tickets about the same printer is one problem, and it should be fixed rather than reported monthly.
Multi-factor coverage, admin accounts, patch status, backup success and restore tests, stated plainly enough for a partners' meeting.
When a client or insurer sends a security questionnaire, we answer the technical sections with evidence rather than leaving the firm to guess.
Licences, connectivity contracts, hardware warranties and application renewals tracked so nothing auto-renews unnoticed.
What needs doing, what it will cost, what the risk is of leaving it, and which financial year it should land in.
Logging is what turns a suspicion into an answer
When a firm needs to establish whether a mailbox was accessed or a file was copied, the answer depends entirely on what was being logged at the time and how long it was kept. Default retention in Microsoft 365 is shorter than most firms assume. We set this deliberately at onboarding rather than discovering the gap during an incident.
09
Firms stay with a provider they have outgrown because the handover looks risky
It usually is risky, but not for the reason people expect. The danger is not the cutover itself. It is discovering afterwards that the old provider still holds the domain, that the Microsoft tenant was created under their account, that nobody has the case management vendor's support contact, or that a backup everyone assumed was running was cancelled two years ago.
We take that in a fixed order and write down what we find, including the things we cannot get.
We request access, documentation and system ownership from the outgoing provider, and set a date by which the firm knows what has and has not been supplied.
We confirm the firm owns its Microsoft tenant, domains, DNS, backups, licences and application accounts. Ownership sitting in a provider's name is the single most common problem we find.
Support routes go live, urgent faults are cleared and monitoring is deployed before the previous provider steps back, not after.
We produce the first roadmap, so the change gives the firm a better position rather than a different helpdesk number.
A risk register, not a reassurance
Where information is missing or an account cannot be recovered, it goes on a written register with an owner and a date. Firms find this more useful than being told everything went smoothly, because it tells them what is still exposed while it is being fixed.
What the firm should own at the end
- The Microsoft 365 tenant, in the firm's name, with the firm holding a global administrator account.
- The domain registration and DNS control.
- Direct contractual relationships with the case management and document management vendors.
- Backups the firm can have restored on request, with retention it has agreed.
- Documentation good enough for a third provider to pick up if the firm ever leaves us.
The same principle runs through our Managed IT Support service. If we are doing the job well the firm will not want to leave. If we are not, it should not have to fight us to.
10
What clients across professional services say about working with Remedian
These are firms who rely on us for the same things a law firm does: responsive support, a named engineer who knows the site, and someone taking responsibility when something breaks.
'As a long-term client of Remedian, Ashworth Electrical Services have nothing but the highest praise for their assistance in managing our IT systems.'
'Remedian have been our IT support providers now for almost 6 years. During that time they have demonstrated a high level of customer service and value for money support and IT equipment.'
'Remedian have helped us grow into the company we are today. The standard of service and expertise Remedian provide us with is second to none, whether it is remote helpdesk support or onsite maintenance.'
'The service Remedian provide is professional and efficient. The staff are always helpful and friendly.'
11
Book a legal IT review
A working session, not a sales call. We look at how the firm is actually set up and tell you what we find, including the parts that are fine.
- Microsoft 365 configuration, admin roles, multi-factor coverage and sharing.
- Backup scope, retention and whether a restore has ever been tested.
- Email security and the controls around payment instructions.
- Device management, remote access and leaver processes.
- Who currently owns your tenant, domains and application contracts.
You get a written summary of the gaps, ranked by risk, with an honest note on which ones cost money to fix and which ones are a configuration change.
Or call 0330 66 00 281 and ask for the business team.
12
IT support for solicitors: FAQs
References and useful links
- Solicitors Regulation Authority, SRA Code of Conduct for Solicitors, RELs and RFLs
- National Cyber Security Centre, Small Business Guide to Cyber Security
- Information Commissioner's Office, Reporting a personal data breach
- NCSC, Cyber Essentials
- Remedian, Managed IT Support
- Remedian, Cyber Security
- Remedian, Cyber Essentials
- Remedian, Penetration Testing
- Remedian, Secure Backup
- Remedian, IT Support Manchester

.png?width=150&height=64&name=output-onlinepngtools%20(2).png)
.png?width=229&height=97&name=output-onlinepngtools%20(2).png)