Passwords remain the front door to your email, document management system and billing platform. Guidance has shifted in recent years. Current thinking from NIST favors length over complexity tricks and discourages forced periodic changes unless there is evidence of compromise. Yet many firm policies still demand a symbol, a number and a new password every 90 days, which tends to produce predictable patterns like a season followed by a year.
Below is an outline you can adapt into your own policy. It is written for small and mid-size law firms and is meant to be short enough that people will actually read it.
Purpose and scope
State in two sentences why the policy exists: to protect client confidences and firm systems. Say it applies to attorneys, staff, contractors and anyone with access to firm accounts. Including partners explicitly matters, because exceptions for senior people are a common weakness.
Password rules
Make length the standard
Require long passphrases, for example four or more unrelated words, of at least 14 characters for accounts that are not protected by a password manager's generated password. Allow spaces and any characters. Block passwords that appear in known breach lists and obvious choices like the firm name.
Do not reuse passwords
Each account gets its own password. Reuse is how a breach at an unrelated website becomes a breach of your firm email. Explain this reason in the policy, since people comply more readily when they understand it.
Change on cause, not on a calendar
Require a change when there is suspicion or evidence of compromise, when an employee leaves, or when a shared credential changes hands. This is consistent with NIST guidance, though you should consider your carrier's and clients' expectations before dropping periodic changes entirely.
Require a password manager
A firm-approved password manager lets people use long unique passwords without memorizing them. In the policy:
- Name the approved tool and require its use for all work accounts.
- Require a strong master passphrase and MFA on the manager itself.
- Prohibit storing passwords in spreadsheets, sticky notes, browser autofill on shared computers or email drafts.
- Describe how shared credentials are stored and who can see them.
Multi-factor authentication
Passwords alone are not enough. Require MFA on email, remote access, document management, practice management, billing and administrative accounts. Prefer authenticator apps or hardware security keys over text messages where possible, and train people to reject unexpected approval prompts, since attackers sometimes send repeated prompts hoping someone taps approve to make them stop.
Shared and service accounts
Shared logins make it impossible to know who did what. Where a shared account is unavoidable, such as a vendor portal, record who may use it, store the password in the manager and rotate it when staff change. Service accounts used by software should have long random passwords and an assigned owner.
Onboarding and offboarding
Tie the policy to the employee lifecycle.
- At hire, create accounts, enroll MFA and set up the password manager in the first week.
- At role change, review and adjust access.
- At departure, disable accounts the same day, revoke sessions, retrieve devices and rotate any shared passwords the person knew.
Reporting and response
Tell people exactly what to do if they enter a password on a suspicious page or notice an unfamiliar login: change the password, tell IT immediately and do not feel embarrassed. Fast reports limit damage. Make clear that reporting a mistake promptly will never be treated as misconduct.
Enforcement and exceptions
Say who approves exceptions, how they are documented and how long they last. Technical enforcement works better than reminders, so configure systems to block weak and breached passwords and to require MFA rather than relying on trust.
Review schedule
Review the policy once a year and after any security incident. Keep a version history so you can show what the policy said at a particular time.
Ethics context
The ABA has said in Formal Opinion 477R that lawyers should make reasonable efforts to protect confidential communications and that reasonable depends on circumstances. Strong authentication is among the inexpensive safeguards commonly discussed. Check your state bar guidance for specifics.
Next step
Counsel Cyber can help your firm roll out a password manager, enforce MFA and tailor this outline to your practice. If you would like a second set of eyes on your current policy, ask us for a security review.