Every law firm hires and loses people, and each change is a security event. A new hire needs access quickly, but only to what the role requires. A departing employee, whether leaving on good terms or not, should lose access immediately and completely. When these steps rely on memory, accounts linger for months, former employees keep access to client files, and nobody can say who has permission to what.
A written checklist, shared between HR, the office manager and IT, fixes this. Below is a version you can adapt.
Why it matters
Model Rule 5.3 asks lawyers to make reasonable efforts to ensure nonlawyer staff conduct is compatible with the lawyer's professional obligations, and Rule 1.6(c) calls for reasonable efforts to prevent unauthorized access to client information. Confirm details with your state bar, but access management is clearly part of showing those efforts. It also appears regularly on cyber-insurance applications and client security questionnaires.
Onboarding checklist
Before the first day
- Get a written request from the hiring manager that names the role, start date, supervisor and required systems.
- Create accounts with the standard role template: email, directory login, practice-management, document management and billing as needed.
- Assign least-privilege access. Start with the minimum for the job. Add more when requested and approved.
- Prepare the device. Provide a managed laptop with disk encryption, endpoint protection and the standard configuration. Avoid personal devices for client work unless they are enrolled in a management program.
- Order any hardware tokens or phone licenses that will be required.
On the first day
- Set up multi-factor authentication with the new user present, and register an authenticator app or security key.
- Provide a password manager account and show how to use it.
- Walk through security policies. Cover acceptable use, handling client data, AI tool rules and how to report suspicious messages.
- Complete security awareness training within the first week, and add the user to ongoing phishing simulations.
- Record what was issued: device serial numbers, licenses, access granted.
In the first month
- Confirm the user has what they need and nothing extra.
- Check that signed confidentiality and acceptable-use acknowledgments are on file.
Role changes
People move between practice groups, take on new responsibilities or become supervisors. Treat a role change as both an onboarding and offboarding event. Add the new access, and remove the old access that is no longer needed. Permissions tend to accumulate when this step is skipped.
Offboarding checklist
Plan for two scenarios: a routine departure with notice, and an immediate or contentious one. The immediate scenario needs a faster path, so decide in advance who may authorize an emergency termination of access.
On or before the last day
- Notify IT as soon as the date is known, using a standard form.
- Transfer ownership of matters, files and shared mailboxes to named colleagues.
- Set an email forward or automatic reply according to firm policy, and give a supervising attorney access to review the mailbox for client messages.
- Collect firm property: laptop, phone, tokens, keys, access cards and any stored credentials.
At the moment of departure
- Disable the account in the directory and in every connected cloud system. If you use single sign-on, this covers a lot, but check systems that sit outside it.
- Revoke active sessions and tokens, including mobile email, app passwords and connected applications.
- Remove MFA devices from the account.
- Reset shared passwords the person knew, such as shared logins, Wi-Fi keys for special networks, or vendor portals.
- Remove access from practice-management, document management, accounting and trust-accounting systems.
- Remove from groups, distribution lists and Teams channels.
- Disconnect remote access such as VPN profiles.
- Wipe or reimage devices after preserving data as required, and if the person used a personal phone with firm email, remotely remove the work data.
After departure
- Preserve the mailbox and files according to your retention and legal-hold policy before deleting anything.
- Convert the license to a shared mailbox or archive rather than letting data vanish.
- Review audit logs for large downloads or forwarding rules in the days before departure.
- Record completion of each step and who signed off.
Quarterly access reviews
Every quarter, have IT produce a list of active accounts and have supervising attorneys confirm each one. Look for dormant accounts, shared accounts, guest users, and anyone with administrator privileges they no longer need.
Making it work
Assign an owner for the process, keep the forms short, and measure how many hours pass between a departure and full account closure. The goal is the same day.
Counsel Cyber manages onboarding and offboarding as part of our managed IT service for law firms, and can also help you build the checklist and audit existing accounts. If you suspect former employees still have access, we can start with a quick review.