ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Law Firm IT Onboarding and Offboarding Checklist for Staff

Starting and departing staff are major sources of security gaps. Use this onboarding and offboarding checklist to cover accounts, devices, access and data.

3 min readBy Counsel Cyber Team

People joining and leaving a firm are among the most common times for security gaps to open. A new hire waits days for a computer, so someone shares a login in the meantime. A departing associate keeps working access to email and the document system for months because nobody told IT. These problems are preventable with a written checklist and a clear owner.

This guide gives firm administrators a practical outline that can be adapted for attorneys, paralegals, assistants, interns and contractors.

Who Owns the Process

Assign shared responsibility between HR or the office manager, who knows when changes happen, and IT, who carries them out. A simple request form or ticket template ensures both sides have the details: name, role, start or end date, supervisor, and access needs. Notice should reach IT well before the date, ideally a week or more for new hires.

Onboarding Checklist

Before day one

  • Create user accounts with the minimum access needed for the role
  • Assign licenses for email, practice management and document management
  • Prepare a laptop or workstation with encryption, endpoint protection and updates in place
  • Enroll the person in MFA and set up the authenticator method
  • Add to correct groups, distribution lists and matter teams
  • Provision phone, voicemail and printing access
  • Order any required hardware, such as headsets or badges

Day one

  • Hand over equipment and verify the person can sign in
  • Walk through MFA and password manager use
  • Review acceptable use, confidentiality and AI use policies, and collect signed acknowledgment
  • Give a short security orientation: how to spot phishing, how to report it, wire verification and handling of client data
  • Explain remote work rules and personal device policy
  • Share contact information for help desk support

First 30 days

  • Complete formal security awareness training
  • Check that access matches the role, removing anything unnecessary
  • Confirm backups cover any local data
  • Follow up on questions with a quick check-in

Offboarding Checklist

Before the last day

  • Confirm the departure date and whether it is voluntary or involuntary, since timing of access removal differs
  • Identify what the person has access to: email, shared mailboxes, matters, cloud storage, third-party portals, trust accounts and bank approvals
  • Arrange for transfer of files, matters and responsibilities
  • Plan return of equipment, badges and keys

On the last day, or immediately for sensitive departures

  • Disable the account and revoke active sessions, rather than waiting for passwords to expire
  • Reset passwords for any shared accounts the person knew
  • Remove MFA devices and registered phones
  • Revoke access to practice management, document management, VPN and remote tools
  • Remove access to bank and trust account systems and update signers with the bank
  • Remove from distribution lists and matter teams
  • Disconnect cloud storage syncing and wipe firm data from personal devices through device management
  • Forward or delegate mail as policy allows, and set an automatic reply

After departure

  • Retrieve and inspect returned equipment, then wipe and reissue it according to policy
  • Preserve mailbox and files according to retention rules or legal hold before deletion
  • Convert or delete the license when appropriate
  • Review logs for unusual activity before and after departure
  • Update documentation and any vendor portals where the person was a contact

Special Situations

  • Contractors and interns: Set expiration dates on accounts at creation.
  • Role changes: Treat a move between practice groups as a mini offboarding and onboarding, removing access no longer needed.
  • Involuntary terminations: Coordinate with leadership so access is removed at the same moment the conversation happens.
  • Lawyers moving firms: Handle client file transfers according to ethics rules and client direction. Check your state bar's guidance.

Why It Matters

ABA Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information, and Rules 5.1 and 5.3 address supervision. Prompt access removal is a reasonable, demonstrable control. It also helps with insurance applications and client questionnaires, which often ask about offboarding.

Make It Routine

Run a quarterly reconciliation comparing your active staff list against user accounts in every major system. Anything that does not match is investigated.

How Counsel Cyber Helps

Counsel Cyber builds onboarding and offboarding workflows into our managed service, with request forms, same-day account removal and quarterly access reviews. If you are unsure whether former employees still have access, we can check.