Start the law-firm IT risk check
Move through the risk questions first, then practice context, then delivery details. The online scorecard appears immediately, and the full checklist is emailed after submission.
Before you start
The check is about systems, controls, and ownership. Do not enter client names, matter details, privileged communications, passwords, trust-account information, or confidential documents.
The questions cover
Before the questions
Check what your practice can prove, not what everyone assumes is handled.
The risk check uses practical scenarios across trust money, matter access, personal devices, backups, admin access, security alerts, and AI use. It takes about five minutes.
Your online scorecard appears immediately. High-risk or suitable submissions can be reviewed by Crypton next business day.
Step 1
Answer 10 scenarios
Each question is designed to uncover assumptions and missing information.
Step 2
Add practice context
Staff count, role, support model, and urgency shape the result route.
Step 3
See the online scorecard
You’ll see what to check first immediately, then receive the full checklist by email.
What a review produces
A plain-English action plan that names the concern, what to confirm, the owner and the next decision for partners.
Sample action-plan excerpt
Confirm the last recovery test, who receives risky mailbox alerts and who takes over for practice-blocking IT issues.
Sample result preview
The result is based on your answers. It is not a legal, regulatory, or cybersecurity compliance certification.
Priority risks
Mailbox and payment-redirection checks, departed-user access, recovery tests and urgent support ownership are ranked from the answers you choose.
What needs attention first
Items move up the list when the answer depends on assumptions, an informal process or records the practice has not seen recently.
What can wait
Areas with a clear process, recent records and named ownership are shown separately so the checklist does not treat every answer as urgent.
Suggested next step
The result points to questions for the provider, scheduled record checks or a focused law-firm IT review when the answers show higher risk.
Keep answers at the systems and process level. Do not enter client names, matter details, privileged communications, passwords, trust-account information, or confidential documents.
You can go back between questions before submitting.