ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Clio Security Settings Every Firm Administrator Should Review

A practical review of the security and access settings in Clio and similar practice-management platforms that firm administrators should check regularly.

3 min readBy Counsel Cyber Team

Practice-management platforms such as Clio hold the core of your firm: client contacts, matter notes, billing records, calendar entries, documents and often trust accounting information. Security settings in these platforms are not always the first thing people configure during setup, and they tend to drift as staff change. A thorough review takes an afternoon and pays off for years.

This guide uses Clio as the example, but the same categories of settings apply to other cloud practice-management tools. Menu names and options change over time, so use this as a checklist of topics and confirm exact steps with your vendor's current documentation.

Authentication

Turn on multi-factor authentication for every user

Check whether your plan lets you enforce it, and if so, enforce it for all users rather than leaving it optional. Prefer authenticator apps or security keys over text messages where available.

Consider single sign-on

If your firm uses Microsoft 365, ask whether the platform supports single sign-on through your identity provider. That lets you manage access and MFA in one place and disable a departing employee in a single step.

Set password expectations

If SSO is not available, require long, unique passwords stored in a firm-approved password manager.

User accounts and roles

Match accounts to people

Export the user list and compare it to your current roster. Remove or deactivate departed staff, and eliminate shared logins such as "reception" that cannot be tied to a person.

Apply least privilege

Review each role. Does every user need access to billing, trust accounting, firm-wide reports or settings? Limit those to the people who need them.

Limit administrators

List who holds administrator rights. Most firms need only two or three, and administrators should use MFA and ideally separate accounts.

Matter and document permissions

  • Review how matters are shared. Restrict sensitive matters, such as internal HR or high-profile clients, to named users.
  • Confirm that ethical walls are still accurate after staff changes.
  • Check client portal settings, including who can invite clients and whether portal links expire.
  • Review how documents are shared externally, and whether sharing links are time-limited.

Connected apps and integrations

Practice-management platforms integrate with email, calendars, accounting, e-signature, payment processors and increasingly AI tools. Each connection is a path to your data.

  1. List every connected application.
  2. Remove any nobody uses.
  3. Confirm who authorized each one and what permissions it holds.
  4. Review any third-party app that can read or export all matters.

Ask your vendor whether it provides logs of API connections, and review them periodically.

Audit logs and alerts

Find out what activity logs exist and how long they are kept. Look for login history, record exports and permission changes. Sample them periodically for odd hours, unfamiliar locations or large downloads. If the platform supports notifications for suspicious activity or administrator changes, enable them.

Data export and backup

Understand how you would get your data out. Test an export of contacts, matters and billing records so you know the format and how long it takes. The platform vendor protects its infrastructure, but your retention and recovery options may be limited, so consider an independent export or backup process and ask the vendor in writing what it offers after accidental deletion.

Trust accounting controls

If you use the platform for trust accounting, confirm that only authorized users can post or edit trust transactions, that reconciliation reports are reviewed by someone other than the person posting, and that changes leave an audit trail. Trust rules vary by state, so confirm requirements with your bar.

Offboarding and onboarding

Add the platform to your offboarding checklist, so access is removed the same day an employee departs. For new hires, use role templates instead of copying a colleague's permissions.

Why bother

ABA Model Rule 1.6(c) addresses reasonable efforts to prevent unauthorized disclosure of client information, and Model Rule 1.1 Comment 8 addresses understanding technology risks. Reviewing the settings of the system holding most of your client data is a straightforward way to act on both.

How we help

Counsel Cyber supports law firms using Clio, NetDocuments, iManage and Microsoft 365. We can walk through these settings with your administrator, document the configuration and set a recurring review schedule.