ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Law Firm Password Practices: What to Keep and What to Retire

Old password rules often make things worse. See which practices to keep, which to drop, and how password managers and MFA fit a law firm's daily work.

3 min readBy Counsel Cyber Team

For years, firms taught staff to create complicated passwords and change them every ninety days. The result was predictable: Summer2024! became Fall2024! and then Winter2024!, with a sticky note under the keyboard as insurance. Modern guidance, including NIST's digital identity guidelines, has moved away from forced periodic changes and complexity gimmicks toward longer passphrases, screening against known-compromised passwords, and multifactor authentication.

It is worth updating your firm's habits to match what is now known to work.

Practices worth retiring

  • Forced rotation on a calendar. Frequent mandatory changes push people toward predictable patterns. Change passwords when there is evidence of compromise, not just because the calendar says so.
  • Arbitrary complexity rules. Requiring a symbol and a capital letter tends to produce the same predictable substitutions.
  • Security questions. The name of your first pet or high school is often discoverable or guessable. Treat these answers like additional passwords, or avoid the feature if possible.
  • Shared accounts. A shared login means no one is accountable and no one can be removed cleanly.
  • Passwords in spreadsheets, emails, or sticky notes. Convenient to everyone, including attackers.

Practices worth keeping or adopting

Length over complexity

A long passphrase of several unrelated words is easier to remember and harder to guess than a short string of symbols. Encourage twelve or more characters at a minimum, with longer for important accounts.

Uniqueness for every account

The most common way passwords are abused is reuse. When a retail site or a social network is breached, attackers try the same email and password on Microsoft 365, banking, and legal software. One reused password can open many doors.

Screening against known-bad passwords

Where your identity platform offers it, block passwords that appear in breach lists or are obviously weak, such as the firm's name plus a number.

Password managers

A password manager lets people use long, unique passwords without memorizing them. For firms:

  1. Choose a business-grade manager with administrative controls.
  2. Require MFA on the manager itself and a strong master passphrase.
  3. Set up shared vaults for credentials that truly must be shared, such as vendor portals, with access limited by role.
  4. Make sure departing employees' access is removed and shared credentials rotated.
  5. Train users on the browser autofill and on spotting fake login pages.

Multifactor authentication everywhere it matters

Passwords alone are not enough. Add MFA on email, remote access, practice-management and document systems, and administrator accounts. Prefer authenticator apps or hardware keys over text messages when possible. CISA has published guidance encouraging stronger, phishing-resistant forms of MFA for high-risk accounts.

Special handling for privileged accounts

Administrator accounts deserve extra care.

  • Use separate admin accounts that are never used for email or browsing
  • Require phishing-resistant MFA where available
  • Store emergency "break glass" credentials securely and test them
  • Review who holds admin rights quarterly

Responding to a breach notice

When a service you use reports a breach, or a monitoring tool flags exposed credentials:

  1. Change the password on that service immediately.
  2. Change it anywhere else it was reused.
  3. Check for suspicious sign-ins or new forwarding rules.
  4. Confirm MFA is enabled.

Keep the rules short

A one-page standard works better than a long policy:

  • Use a password manager.
  • Make passwords long and unique.
  • Never share your password.
  • Approve only MFA prompts you started.
  • Report anything odd right away.

Handling resistance

Attorneys may complain that security slows them down. Make the secure path easy: single sign-on, a good password manager integrated with browsers, and MFA methods that take a few seconds. Explain with a concrete example, such as a reused password turning one retailer's breach into a client-data incident.

Verify, do not assume

Ask your IT provider for a report on accounts without MFA, accounts with old passwords exposed in breach data, and shared accounts still in use. Fixing these three lists makes a measurable difference.

Our offer

Counsel Cyber helps firms roll out password managers, MFA, and policy updates with minimal friction for attorneys. If you would like a quick account-hygiene review, we can help you see where your biggest exposures are.