Managed IT for legal practices
IT Support for Law Firms in Melbourne and on the Peninsula
A practice is judged on its files. Privilege, confidentiality and the duty to keep a client's affairs secure all come down, in the end, to who can open a document and whether anyone can prove it. That is a technology question long before it is a legal one.
Want the number first? Our pricing is published: AgileCORE from $85 and AgileCOMPLETE from $130 per user per month ex GST, plus the AgileSECURE add-on at $44, which we strongly recommend for a practice holding privileged material. Estimate your monthly figure in two minutes, or book a conversation.
What the duty actually requires
Confidentiality is a continuing obligation, and it outlives the matter
The duty does not end when a matter closes, and it does not distinguish between a document left on a train and a document left in a mailbox that a former employee can still reach. Three things decide whether a practice can meet it.
Who can open the file
Access that reflects the matter and the role, not the history of who once helped on something. Conflicts and information barriers are a professional obligation, and they are enforceable in the system or they are not enforced at all.
Whether you can prove it
If a client, an insurer or a regulator asks who accessed a matter and when, the answer has to exist. Logging and retention are decided when the system is set up, not when the question arrives.
Whether it survives
Retention periods for closed files run for years. A backup that has never been restored from is not a retention policy, it is an assumption that nobody has tested.
We are not your compliance adviser and we will not pretend to be. What we do is make sure the environment can actually support the obligations your practice already has. Our compliance obligations page sets out what applies to Victorian businesses, and AgileSECURE is aligned to the SMB1001 maturity framework.
The question is not whether your practice has a security policy. It is whether somebody could tell you, this afternoon, who has access to a closed matter from 2019.
The attack aimed specifically at you
Settlement funds are the reason your practice is a target
Practices move other people's money on known dates, which is exactly what makes them worth attacking. The method is rarely sophisticated. Somebody reaches a mailbox, watches a conveyancing or settlement thread, waits, and sends revised account details from inside the conversation at the moment they are expected.
Training helps and will not be enough on its own, because the email that arrives is genuine, from the right address, in the right thread. The controls that matter are technical and procedural together.
What we put in place
- Multi-factor authentication on every account, with no standing exemptions
- Alerting on mailbox rules and forwarding, which is how this always starts
- Monitoring for sign-ins that do not fit the person or the place
- Access reviewed when people join, change role and leave
What stays with the practice
- Verifying account details by a channel other than the email thread
- A rule that the verification call goes to a number already on file
- Deciding who is permitted to authorise a change, and recording it
We will help you write these, but they are yours to own. Every AgileMANAGED engagement puts that split in writing in a Responsibility and Accountability Matrix.
Scope
What we take responsibility for
Agreed in writing on day one, so it is clear what sits with us and what sits with the practice.
| Area | What that means for a practice |
|---|---|
| Microsoft 365 | Licensing, mailboxes, document structure, retention settings and the security controls most practices never turn on. |
| Access and identity | Multi-factor, role-based access that can support an information barrier, and reviews when people move or leave. |
| Devices | Standardised, encrypted and monitored, including the laptop that goes to court and the one that goes home. |
| Backup and retention | Backups that are tested by restoring from them, with the result written down and a recovery time you have actually seen. |
| Vendors | We deal with the practice management and connectivity suppliers, so your practice manager is not the integration layer. |
Published pricing
AgileMANAGED: structured IT from $85 per user / month
We publish our pricing because a practice that budgets properly deserves to know the number before the first meeting, not after the third.
AgileCORE
Remote support, monitoring, security baselines and Microsoft 365 management. Suits a practice that is well set up for remote delivery.
View AgileCORE →AgileCOMPLETE
Everything in CORE, plus onsite support, managed servers with 24/7 monitoring, and quarterly business reviews.
View AgileCOMPLETE →Where we work
Based in Mornington, acting across the south east
Agile IT Solutions has been based in Mornington since 2007. We work with practices from the suburban firms through Dandenong and the south eastern corridor to chambers and boutique firms in town. Most issues are resolved remotely, and onsite support across our service area is included with AgileCOMPLETE.
We should be straight with you about depth: our longest-standing work is with accounting, financial services and operational businesses rather than legal practices. The technology underneath a law firm is not unusual, and the obligations are ones we work to every day, but if you want a provider who has done nothing but legal for twenty years, that is not us, and we would rather say so now.
Questions
IT questions from legal practices
Can you support our practice management system?
We do not write your practice management system and we are not its consultant. We take responsibility for everything underneath it: devices, the Microsoft 365 tenancy, access control, connectivity, backup and the vendor relationships, so the system has a stable base and somebody to call when it is not behaving. When the fault sits with the software vendor, we deal with them rather than handing you a ticket number.
How do we stop settlement funds being redirected?
With technical controls and a process rule together, because neither works alone. Technically: multi-factor authentication, alerting on mailbox rules and forwarding, and monitoring for unusual sign-ins. Procedurally: account details are verified by calling a number already on file, never a number supplied in the email thread, and only a named person can authorise a change. We implement the first and help you write the second.
Can you enforce an information barrier between matters?
Yes, within Microsoft 365, by structuring documents and permissions so access follows the matter and the role rather than the whole practice. It needs a decision from you about who should see what, which is a professional judgement rather than a technical one. Once that is decided, we implement it and review it when people change role.
How long should we keep closed matters, and where?
The retention period is a question for your practice and your insurer, not for us. What we make sure of is that whatever you decide is actually what happens: that closed matters are retained in a governed location rather than a personal drive, that retention is configured rather than manual, and that you could restore from it, because we have tested that rather than assumed it.
Are we too small for this?
We work best with businesses of roughly 5 to 50 staff, and smaller teams growing into that range. A sole practitioner with a laptop that works does not need us. The point at which this becomes worthwhile is usually when technology decisions start waiting because nobody owns them.
How do we get started?
A discovery conversation. We look at what the practice runs on today, how it is managed and where the gaps are, then set out what a structured managed service would look like. No obligation and no quote pushed at you in the first meeting.