What the Law Society of NSW Expects From Your IT If You Manage a Trust Account

If your practice holds trust money, the Law Society of NSW now expects specific protections around it. In June 2026, the Law Society’s Chief Trust Account Investigator set out the baseline in the Law Society Journal, making principals responsible for having effective safeguards in place to protect trust accounts from unauthorised access, cyber threats and data compromise.

Most of these expectations are everyday IT controls. This article goes through each of the five areas, what it means in practice and what your IT provider should be doing about it.

Who is responsible for trust account security?

The principal is. The guidance puts the responsibility on principals to make sure the safeguards exist, even when the day-to-day work is done by a practice manager, a bookkeeper or an outside IT provider.

In practice, a principal should be able to explain what protections are in place and who checks that they are still working.

1. Preventing unauthorised access

Phone with a padlock symbol representing secure logins

The first area covers the basics that stop someone getting into your systems in the first place:

  • Security updates applied promptly, ideally through an automated process
  • Strong, unique passwords for every system, with no shared logins
  • Multi-factor authentication on critical systems, including online banking
  • Security software, such as antivirus, endpoint protection and firewalls, that is actively monitored

In your office, that means every staff member has their own Microsoft 365 account, multi-factor authentication is switched on for email, practice management software and banking, and computers update automatically rather than whenever someone remembers.

Shared passwords belong in a password manager such as 1Password, so they can be used without being written down or emailed around.

2. Restricting access to trust money

Access to the trust account should be limited to the people whose role needs it, and those permissions should be reviewed regularly. The guidance also covers secure device setup, encryption where appropriate, and secure storage and sending of trust account information.

In practice, this looks like:

  • A current list of who can view the trust account and who can authorise payments
  • Access removed on the day someone leaves or changes role
  • Encrypted laptops, so a lost device does not expose client and trust information
  • Trust records kept in your practice management system or Microsoft 365, rather than in email attachments or on personal devices

3. Verifying instructions and preventing fraud

This is the area where most trust account losses happen. The Law Society expects verification procedures before acting on any instruction to transfer trust money, with bank details checked independently using trusted methods rather than email alone.

It also expects ongoing staff training on phishing and email compromise, and clear communication to clients that your bank details will not change by email.

IT can lower the risk, but it cannot replace the procedure. Email filtering, multi-factor authentication and phishing training make it harder for a scammer to get into a mailbox or send a convincing fake. The call-back check, made to a number you already hold for the client, is what stops the payment. We cover this in more detail in How to stop payment redirection fraud in a law firm.

4. Responding to cyber incidents

Practices are expected to have a documented incident response plan, staff who know how to report a problem, and a process to disable accounts and contact the bank quickly if a breach is suspected.

For a small practice, a useful incident plan fits on one or two pages. It should say who to call first (usually your IT provider and your bank), how to lock a compromised account, who decides whether the matter is reported, and where your reporting obligations sit.

The Law Society has guidance on reporting trust account irregularities, which is worth reading alongside your plan.

5. Maintaining data integrity

Close up of a server used for backups

The final area covers backups. The guidance expects regular backups of critical systems, stored securely offsite or in the cloud, and periodic testing to confirm they can be restored.

Two points are easy to miss. Microsoft 365 email and files need their own separate backup, because Microsoft keeps the service running but does not keep a long-term copy of everything that is deleted. A backup is also only useful if someone has restored from it recently, so ask your IT provider when they last tested a restore.

A quick self-check for principals

  • Does every staff member have their own login, with multi-factor authentication switched on?
  • Are security updates applied automatically on every computer?
  • Do you know exactly who can authorise a trust payment, and when that list was last reviewed?
  • Is there a written call-back check before any change to bank details is acted on?
  • Do you have a short incident plan that staff know about?
  • When was a backup last restored to prove it works?

If any answer is “not sure”, that is the place to start.

How Digitek helps law firms

Digitek IT works with principals and practice managers to put these controls in place and keep them running. We set up Microsoft 365 accounts, multi-factor authentication and password management, keep computers updated, run phishing training, back up email and files separately and test restores.

We also help you write a call-back procedure and an incident plan that suit your office. Jim has supported lawyers throughout his career, so we work through your firm’s procedures with you rather than handing over a list.

Find out more about our IT support for law firms, or call us on 02 4504 8643 to talk about your trust account setup.

Scroll to Top