Back to furthermore
Furthermore Law
Information Security
Practice Area

Information Security Law

A promise you make once — and keep every day.

Security is a Promise

Trust requires safety. Safety is a promise: that you will protect people and their personal information.

It is a promise you make once but work towards every day. We read the signals, regulations, and emerging threats so that the security controls you build today reflect applicable laws and industry standards. We work with clients committed to keeping their promises.

A promise made once, kept every day.

Reading the Signals

Real security is never just code. It combines physical, technical, and administrative controls: locked facilities, encryption and access management, and the policies and oversight that hold them together. The rules governing all three grow more prescriptive every year, driven by an escalating threat environment.

Meeting them requires understanding the full scope of the frameworks that apply to you — because that scope is what lets you interpret your obligations of due diligence and due care rather than guess at them. We read those signals and translate them into controls that fit where you are headed.

Security as a Culture

Security is a culture, not a setting. The work is never done. The strongest controls fail when the people using them do not understand why they matter, and most vulnerabilities originate with personnel, not just code.

Treated as a checklist, security invites the single mistake that becomes a breach, a regulatory order, and a lawsuit at once. Treated as a shared practice — reinforced by ongoing training — it becomes part of how your teams work and how your products are designed.

How We Get You There

Interpreting security obligations takes more than legal training; it is rare for a lawyer to hold security certifications combined with fluency in law. That is what lets us speak with regulators, auditors, and security professionals on equal terms. Whether you are meeting your first security obligations or preparing your people for the controls they must follow, we meet you where you are. Our information security law services include:

  1. 01Compliance with Canadian and global information security laws and standards
  2. 02On-site security training for boards, executives, and personnel
  3. 03
    Negotiating security terms in commercial agreements, including:
    • Software Services Agreements
    • Data Processing Addendums
    • Vendor and supplier security schedules
  4. 04Incident response and breach notification readiness
  5. 05Information security policies and procedures

Security work never stands alone, and neither do we. Our information security practice is reinforced by adjacent work in Privacy Law, Regulatory Law, and AI Governance — so the layers you build hold across the data, the rules, and the systems that use them.

Let's secure what you hold.

Start a conversation