Hi, seen your post. I had an exprience, a side job, very simular to yours. I learned the hard way about security and Law firms.
I was so worried about people getting in that I let a security hole on info getting out, like on e-mails and documents sent to clients. Watch e-mails sent to each other( The Partners). The stuff they say in clear text was amazing. Protect your self no matter how good of a friend this lawyer is.
Make a proposal of what your going to do, what email system you will use (ENCRYPT IT !! ), and explain the back-up sysytem to them, who will run it and back it up to a secure server behind another firewall. AND who is to maintain the security and system after the install. "Small Law firm" can cause you Large Headaches. When Firms get hit with a discovery, that means electronic too, they can come in and pick your whole e=mail system apart .
You can also get info on storing data from secure services that encrypts, stores, has secure clients and e-mail. They deal with people like law firms and R+D people. They generally arenot ISP's, but their services are on the net, browse around for them.
Ftp, tftp, telnet are dead, learn secure shell.. sorry Iam goin off on a tangent here, That s my 2 cents, one screwdriver turner to another,
....Protect yourself .
Later.......