Lawyers generally take physical security seriously but rarely give digital security much thought. They're often working on their own (somewhere between 1/4 to 1/2 of lawyers are independent/very small firm in Canada/US). This means they don't have the time, expertise or money to invest in knowing what to do or how to do it. But I've found they usually do want to know and that was the reason for this presentation.
This isn't a list of the best things to do, it's a list of some practical steps that can make things better. But ultimately the right level of security depends on the importance of the client communications. Some things are fine to do as Google Docs and other things you'll want to do with in-person meetings where no phones are allowed.