ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Applying Zero Trust Ideas in a Ten-to-150-Attorney Law Firm

Zero trust is more than a buzzword. See how its core ideas translate into affordable, practical controls for firms with ten to a hundred and fifty attorneys.

3 min readBy Counsel Cyber Team

Vendors use the phrase zero trust so freely that it has started to sound like a product. It is better understood as an approach: do not automatically trust anyone or anything because they are inside the network. Verify who is asking, check the health of their device and give them only the access they need. NIST has published guidance on zero trust architecture, and CISA has a maturity model, both of which describe the idea in more depth.

For a small or mid-size law firm, zero trust does not require ripping out your infrastructure. It describes where to focus effort, much of which you can do with the tools you already own.

Why the old model is failing

The traditional model treated the office network as a safe zone. Once a user or device was inside, it could reach most resources. That assumption no longer holds. Attorneys work from home and court. Data lives in cloud services. Attackers who steal one password can behave like a legitimate user. If everything inside is trusted, a single compromised account gives access to everything.

Core principles in plain English

  1. Verify explicitly. Authenticate every user with strong methods like MFA, and consider context such as location and device.
  2. Use least privilege. Give people only the access their job needs, and for only as long as needed.
  3. Assume breach. Design as if an attacker may already be inside, so segmentation and monitoring limit damage.

Practical steps for a law firm

1. Strong identity everywhere

Identity is the new perimeter. Enforce MFA for all users and administrators. Where possible, use a single identity provider such as Microsoft Entra ID for sign-in to practice management, document management and other applications, so you can apply consistent rules and cut off access from one place. Prefer phishing-resistant methods, such as security keys or passkeys, for administrators and high-risk users.

2. Conditional access

Use policies that evaluate context. For example, require MFA at every sign-in from unfamiliar locations, block sign-ins from countries where nobody at the firm works and deny access from devices that are not managed or are missing security updates. These rules are available in common Microsoft 365 business plans and are among the most effective low-cost measures.

3. Device health

Require that devices accessing firm data be enrolled, encrypted and updated. An unmanaged personal computer can be limited to web-only access with no downloads, while a managed laptop gets full access.

4. Least privilege and role-based access

Review who can see which matters, folders and systems. Remove broad access granted for convenience. Separate administrator accounts from everyday ones, and require approval or time limits for elevated access where your tools support it.

5. Segment the network

Even in a small office, separate guest Wi-Fi from the main network, isolate printers and other devices that cannot be secured well and limit server access to the users who need it. If an attacker lands on one device, segmentation makes lateral movement harder.

6. Replace broad VPNs with application-level access

Traditional VPNs often put remote users on the internal network. Where it makes sense, move to application-based access that connects people only to specific resources. Many firms reduce reliance on VPNs simply by moving more systems to the cloud.

7. Monitor and respond

Assume something will go wrong. Collect logs from identity systems, email and endpoints, and have someone watching them. Alerts about impossible travel, new forwarding rules and mass downloads can catch an intruder who has already authenticated.

8. Protect data directly

Use sensitivity labels, encryption and sharing controls so that a file stays protected even if it leaves your environment. Limit external sharing and review it regularly.

Ethics connection

Rule 1.6(c) calls for reasonable efforts to protect client information, and ABA Formal Opinion 477R describes a fact-based approach that considers the threat landscape and available safeguards. Zero trust controls, many of them inexpensive, help demonstrate that effort.

A sensible order of operations

  1. MFA everywhere, with legacy sign-in blocked.
  2. Device enrollment and encryption.
  3. Conditional access policies.
  4. Admin account separation.
  5. Cleanup of access rights.
  6. Logging and monitoring.
  7. Segmentation and application-level access.

Avoid common traps

  • Buying a product labeled zero trust without changing practices.
  • Enforcing rules so tightly that attorneys bypass them. Test with real users.
  • Forgetting legacy systems that cannot support modern authentication. Isolate them.
  • Skipping documentation. Record your policies and the reasons behind them.

Where we fit

Counsel Cyber helps firms put these ideas to work using the Microsoft 365 licenses they already pay for. If you want a prioritized plan for your environment, ask us for a security review.