August 28, 2026

What Boise Law Firms Should Ask an IT Provider About Client Data Security

A law firm's obligations around client information are set by the rules of professional conduct and by your bar, not by your IT provider. What an IT provider is responsible for is the technical control environment that makes meeting those obligations possible. These are the questions worth asking to find out whether a provider can actually support that.

This article covers IT controls only. For questions about your professional responsibilities, consult the Idaho State Bar or your own counsel.

Who can see our client files, and how do you prove it?

Ask for a written access model, not a verbal assurance. A firm should be able to see which accounts have access to which matter files, whether access is granted by role or by individual, and how quickly access is removed when someone leaves.

Follow up: does your IT provider's own staff have standing access to firm data, and is that access logged? Many do. That is not automatically wrong, but you should know it and it should be recorded.

How is client data protected in transit and at rest?

Encryption in both states is the baseline, and the answer should be specific. Which systems, which method, and who holds the keys.

Ask specifically about laptops and mobile devices. Full disk encryption on firm laptops is straightforward to implement and is one of the more common gaps we see.

How do we share files with clients and opposing counsel?

If the honest answer is email attachments, that is worth addressing. A secure portal or an encrypted transfer method should be available and should be easy enough that people actually use it. Controls that create friction get worked around, and a workaround is worse than the original problem.

What happens in the first 24 hours of a suspected breach?

You want a specific sequence, not a reassurance. Who gets called, who preserves evidence, who determines what data was involved, and how quickly you receive information you can act on.

Your notification duties are a legal question for your counsel and your bar. What your IT provider owes you is fast, accurate information about scope, because you cannot make those decisions without it.

How long is our data retained, and where?

Retention is a decision the firm makes and the IT provider implements. Ask where backups physically live, how long they are kept, and whether data can be deleted on request when a retention period ends. Confirm the answer covers backups, not just the live system.

Which of your vendors touch our data?

Most IT providers use third-party tools for backup, monitoring, email filtering, and documentation. Ask for the list and what each one can see. A provider who cannot produce that list on request has not thought about it carefully.

How do you handle remote and mobile access?

Attorneys work from courthouses, home, and travel. Ask how devices are authenticated, whether multifactor authentication covers remote access and not only email, and what happens when a phone is lost.

What a good answer sounds like

The pattern to listen for is specificity. A provider who answers with a product name is describing a purchase. A provider who answers with a process, a responsible party, and a way to verify it is describing a control.

Working with firms in the Treasure Valley

IDACOMP has supported Idaho businesses since 2002 as part of Bytagig, founded 2009. Managed clients see a 15-minute average first response, measured from ticket data rather than offered as a contractual promise. We work from CIS Controls and provide documentation firms can keep.

If your firm is reviewing its IT arrangements, we are glad to walk these questions with you, including the ones about our own access and our own vendors.

An accounting professional reviewing paperwork at a desk in a bright modern office.
By John Jackson August 28, 2026
The FTC Safeguards Rule requires tax and accounting firms to maintain a written information security plan. What belongs in it and where Boise firms commonly fall short.
A business owner reviewing insurance paperwork at a desk in a bright modern office.
By John Jackson August 28, 2026
Cyber insurance carriers verify controls, not just attestations. What Boise businesses should have in place before an audit or renewal, and where gaps usually appear.
Two IT colleagues working together at a desk with laptops in a bright modern office.
By John Jackson August 28, 2026
Co-managed IT keeps your internal IT person in charge while an outside team adds depth, after-hours coverage, and security. How the split works in the Treasure Valley.
A desk phone and open laptop on a tidy office desk in warm natural light.
By John Jackson July 28, 2026
Why Boise businesses get Microsoft 365 and hosted VoIP from one provider, what breaks when vendors are split, and how to choose between Teams Phone and hosted VoIP.
Two business people reviewing printed insurance documents across a desk in a bright office.
By John Jackson July 28, 2026
What cyber insurance carriers ask Idaho small businesses about MFA, backups, EDR and incident response, what each control means, and how to close gaps before renewal.
A manufacturing worker in a hard hat inspecting equipment on a factory production floor.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise manufacturers. Keep production running, secure office IT and the shop floor, and protect designs from ransomware and theft.
A diverse group of nonprofit team members and volunteers collaborating around a table.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise nonprofits. Stretch limited budgets, protect donor data, and keep your team running so you can focus on your mission.
An architect reviewing building blueprints and a scale model at a desk in a modern studio.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise architecture and engineering firms. Support demanding CAD and BIM workloads, protect design data, and keep teams in sync.
A financial advisor meeting with a client across a desk in a bright modern office.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise financial advisors. Protect client data, align with GLBA and SEC expectations, and keep systems running for clients.
An attorney reviewing documents at a desk with shelves of legal volumes behind them.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise law firms. Protect privileged client data, meet cyber insurance requirements, and keep systems running for every deadline.