IT support for a law firm in Dubai is built around confidentiality. Documents are organised by matter with access limited to the team on it, email is hardened against impersonation and payment fraud, clients receive files through controlled sharing, partners work securely while travelling, backups are tested, and access is reviewed whenever people join, move or leave.
What is different about IT for a law firm?
A law firm's IT has to protect privileged and confidential client information while lawyers work quickly, often away from the office. An ordinary office can tolerate loose folder permissions or a shared inbox; a firm handling disputes, transactions and client funds cannot.
Client confidentiality and legal privilege are professional obligations, and the rules that apply depend on where the firm is licensed and who regulates its lawyers. This page does not give legal advice. It explains the IT controls that usually support those obligations; confirm what your firm is actually required to do with your own compliance or professional-conduct adviser.
Firms in DIFC face extra expectations around data protection and client due diligence. Our IT security guide for DIFC firms covers that baseline in depth, so this page concentrates on how a practice of any location should set up day-to-day support.
How should a law firm organise documents and permissions?
Organise documents by client and matter, and grant access by matter team rather than giving everyone the whole file share. In Microsoft 365 this usually means SharePoint sites or libraries structured around practice areas or clients, with Microsoft 365 groups controlling who can open each one.
The aim is simple: a trainee on one matter should not be able to browse an unrelated client's documents. Where the firm needs ethical walls between teams, permissions must be set deliberately and checked, not inherited by accident.
- A standard folder template for every new matter, so documents land in predictable places.
- Access requested and approved when someone joins a matter team, and removed when the matter closes.
- Inheritance of permissions broken only where there is a documented reason.
- Sensitive matters kept in separate sites rather than hidden subfolders.
- Old network drives migrated or locked, so files do not live in two places.
Why is email the biggest risk for a law firm?
Email is where attackers reach lawyers, clients and accounts staff, and a single convincing message can redirect client funds. Payment-diversion fraud typically involves a compromised or spoofed mailbox sending changed bank details just before a settlement, completion or fee payment.
Technical controls reduce the risk: multi-factor authentication on every account, email authentication records (SPF, DKIM and DMARC) on the firm's domain, warnings on external and lookalike senders, and blocking of automatic forwarding to outside addresses. A process control matters as much: any change to bank details is confirmed by phone on a number already on file, never one in the email. Our cybersecurity services set up and monitor these controls.
| Risk for law firms | Control that addresses it |
|---|---|
| Mailbox takeover used to send false payment instructions | MFA on all accounts, sign-in alerts, blocked external forwarding and call-back checks on bank detail changes |
| Spoofed or lookalike sender impersonating a partner or client | SPF, DKIM and DMARC on the domain, external sender tags and staff awareness training |
| Staff opening documents from unrelated matters | Matter-based SharePoint permissions and periodic access reviews |
| Confidential files sent as email attachments to the wrong person | Controlled sharing links with expiry and named recipients |
| Lost or stolen laptop or phone while travelling | Encrypted, managed devices that can be locked or wiped remotely |
| Deleted or encrypted matter files | Separate, tested backups of Microsoft 365 and any on-site data |
| Former staff keeping access | A leaver checklist that disables accounts and recovers devices on the last day |
How can a law firm share files securely with clients?
Use controlled sharing from the document system instead of large attachments or personal file-transfer sites. SharePoint and OneDrive can share a specific file or folder with a named external person, require them to verify their email, set an expiry date and prevent download where that is appropriate.
For larger matters, a dedicated client or deal site keeps all exchanged documents in one place, and access is removed when the matter ends. External sharing settings should be set once at firm level so individual lawyers cannot create open links that anyone can use.
How should IT support partners who travel and work remotely?
Partners should get the same protection on the road as at their desk, without depending on the office network. That means managed, encrypted laptops and phones enrolled in Intune, conditional access that checks the device before allowing sign-in, and Microsoft 365 apps rather than files copied to personal storage.
Hotel and airport Wi-Fi should be treated as untrusted. Firms that still run on-site systems need a secure remote access method, and partners need a helpdesk they can reach by phone, WhatsApp or email. With remote support, a lawyer's locked account or failed sign-in is fixed without waiting for an office visit.
What should retention, backup and access reviews look like?
Keep matter records for as long as your firm's policy and obligations require, back them up separately from Microsoft 365, and review who has access at least whenever people change roles. Retention periods are a decision for the firm and its advisers; IT's job is to apply them consistently with retention policies and to make sure deleted items can be recovered.
Microsoft 365 is not a backup on its own. A separate backup of mailboxes, SharePoint and OneDrive, plus any on-site NAS or server, should be restore-tested on a schedule. Access reviews should run when staff join, move between practice groups or leave, and again on a regular cycle, with the results recorded.
- Leavers: account disabled, mailbox access handed over, devices recovered and wiped, shared links reviewed.
- Movers: old matter and practice-group access removed, not just new access added.
- Regular review: partners confirm who can see their clients' sites.
How do you answer client security questionnaires?
Keep an evidence pack ready so questionnaires take hours rather than weeks. Corporate and financial clients often ask firms to describe their security controls before instructing them, and the same questions come up repeatedly.
A practical pack includes the network diagram, asset register, account list, MFA and device management reports, backup and restore test records, the incident response plan and the dates of recent access reviews. Your IT provider should produce and update this documentation as part of normal support. Firms should still have a responsible person check answers before they are sent to a client.
How Listonics helps with IT support for law firms
For law firms in Dubai, Listonics acts as one accountable team for the network, laptops, Microsoft 365, security and backup. Engineers work on site across Dubai and remote support covers the UAE. Practice-management and document software stays supported: we keep the servers, workstations and integrations it depends on patched and backed up, and work with the software vendor when an issue sits on their side.
Support runs under a managed IT support plan with written response times and a fixed monthly fee. See how our IT support in Dubai works, or book a free IT assessment of your firm's current setup.
Frequently asked questions
No. Confidentiality and privilege obligations depend on your licensing, regulators and client terms, so confirm them with your compliance or professional-conduct adviser. Once you know what is required, we set up and document the IT controls that support it, such as matter-based permissions, MFA, device encryption, backup and access reviews.
For most small and mid-sized firms, yes, when it is configured properly. SharePoint can hold matter files with permissions by team, retention policies and controlled external sharing. The risk comes from default settings left unchanged, so external sharing, MFA, device checks and a separate backup should be set up deliberately.
Yes, at the infrastructure level. We keep the server or cloud connection, workstations, user accounts, backups and integrations with Microsoft 365 working, and we raise and follow up issues with the software vendor. Application-specific configuration and licensing remain with the vendor, and we coordinate so you make one call.
Combine technical and process controls. Enforce MFA, block automatic forwarding, set up DMARC on your domain and flag external senders. Then require every bank detail change to be confirmed by a phone call to a number already on file, and never act on urgency in an email alone.
Review access whenever someone joins, changes practice group or leaves, and run a wider review on a regular cycle agreed with your compliance lead. Partners should confirm who can see their clients' sites, and the result should be recorded so you can show it to clients who ask.
Yes. We start with an audit and documentation of the existing setup, fix urgent gaps such as missing MFA or untested backups, then move the firm onto managed support. Equipment is replaced only where it is genuinely needed, and the handover is planned to avoid disruption to fee earners.
Last reviewed September 13, 2026 by the Listonics engineering team.