client confidentiality law firm

      Is Your Law Firm’s Use Of Teams And Email Putting Client Confidentiality At Risk?

      “We use Teams and email like every other firm — so we’re fine.” It’s a reasonable assumption. These are mainstream, trusted business tools, used by millions of organisations every day.

      But here’s what that assumption misses: the default settings in everyday tools like Microsoft Teams and Outlook are not automatically configured to meet the confidentiality obligations solicitors and law firms are held to. 

      This isn’t a case for buying new software — it’s about recognising that the tools you already have are probably under-configured for what your role actually requires.

      Why Confidentiality Risk in Everyday Tools Gets Overlooked

      Because email and Teams feel routine, they don’t register as a risk the way, say, a cyberattack does. But client confidentiality obligations under the SRA Standards and Regulations — and the expectations of professional indemnity insurers — apply just as much to a quick email attachment as they do to a formal document exchange.

      (Note: this is a general compliance overview for IT-planning purposes, not legal advice — consult your compliance officer for definitive guidance on your obligations.)

      Common Ways Confidentiality Slips Through the Cracks

      1. Unencrypted email attachments: Sensitive case documents sent as plain attachments, with no encryption in transit — readable by anyone who intercepts them.

      2. Overly broad Teams permissions: Channels and files set to whole-firm visibility by default, when only the matter team actually needs access. Convenient — but a needless expansion of who could see privileged material.

      3. Forwarding chains gone wrong: A quick “forwarding for context” can unintentionally expose privileged information to someone outside the intended circle, especially in long email threads with multiple recipients.

      4. Personal devices and accounts under time pressure: When a deadline is looming, it’s tempting to fire off a document from a personal phone or account just to get it moving — bypassing whatever controls exist on firm-managed devices.

      What “Secure Enough” Actually Looks Like

      • Encryption in transit and at rest, as standard, not an opt-in extra
      • Matter-based access control — need-to-know access, not firm-wide by default
      • Audit trails — a clear record of who accessed or shared what, and when
      • Secure client portals as the default for sensitive documents, rather than email attachments

      Quick Wins You Can Implement This Week

      The good news: most of this doesn’t require new software.

      • Review and tighten Teams’ default sharing/permission settings
      • Enable the encrypted email options already built into Microsoft 365
      • Audit external sharing settings across SharePoint and OneDrive
      • Set clear guidance on when to use secure portals vs. standard email

      You likely already own the tools you need — the fix is configuration, not procurement.

      When to Bring In IT Support For A Full Review

      It’s worth a professional review of your IT if your law firm has grown recently, adopted additional systems, experienced a near-miss, or has an insurer or compliance audit approaching. What worked for a smaller firm may no longer provide the level of control and visibility needed as your practice evolves.

      An independent assessment can identify issues such as excessive permissions, unsecured sharing settings, or gaps in email and document security before they become a confidentiality incident. Just as importantly, it can provide reassurance that your existing Microsoft 365 environment is configured appropriately and supporting your firm’s confidentiality obligations without disrupting day-to-day work.

      How Akita Helps Law Firms Lock Down Confidentiality Without Disrupting Workflow

      We help firms configure the Microsoft 365 tools they already use to properly meet confidentiality expectations — without slowing fee-earners down or forcing a switch to unfamiliar software.

      Key Takeaways

      • Familiar tools aren’t automatically configured for solicitor-level confidentiality obligations.
      • The most common risks — broad permissions, unencrypted attachments, forwarding chains — are fixable without new software.
      • A quick professional review can catch gaps before they become an incident.

      Request A no-obligation review of how secure your current setup

      Most confidentiality gaps are invisible until something goes wrong. Get ahead of it. Get in touch with Akita for a free confidentiality and security review.

      Contact Us
      Back to feed