For years, firms taught staff to create complicated passwords and change them every ninety days. The result was predictable: Summer2024! became Fall2024! and then Winter2024!, with a sticky note under the keyboard as insurance. Modern guidance, including NIST's digital identity guidelines, has moved away from forced periodic changes and complexity gimmicks toward longer passphrases, screening against known-compromised passwords, and multifactor authentication.
It is worth updating your firm's habits to match what is now known to work.
Practices worth retiring
- Forced rotation on a calendar. Frequent mandatory changes push people toward predictable patterns. Change passwords when there is evidence of compromise, not just because the calendar says so.
- Arbitrary complexity rules. Requiring a symbol and a capital letter tends to produce the same predictable substitutions.
- Security questions. The name of your first pet or high school is often discoverable or guessable. Treat these answers like additional passwords, or avoid the feature if possible.
- Shared accounts. A shared login means no one is accountable and no one can be removed cleanly.
- Passwords in spreadsheets, emails, or sticky notes. Convenient to everyone, including attackers.
Practices worth keeping or adopting
Length over complexity
A long passphrase of several unrelated words is easier to remember and harder to guess than a short string of symbols. Encourage twelve or more characters at a minimum, with longer for important accounts.
Uniqueness for every account
The most common way passwords are abused is reuse. When a retail site or a social network is breached, attackers try the same email and password on Microsoft 365, banking, and legal software. One reused password can open many doors.
Screening against known-bad passwords
Where your identity platform offers it, block passwords that appear in breach lists or are obviously weak, such as the firm's name plus a number.
Password managers
A password manager lets people use long, unique passwords without memorizing them. For firms:
- Choose a business-grade manager with administrative controls.
- Require MFA on the manager itself and a strong master passphrase.
- Set up shared vaults for credentials that truly must be shared, such as vendor portals, with access limited by role.
- Make sure departing employees' access is removed and shared credentials rotated.
- Train users on the browser autofill and on spotting fake login pages.
Multifactor authentication everywhere it matters
Passwords alone are not enough. Add MFA on email, remote access, practice-management and document systems, and administrator accounts. Prefer authenticator apps or hardware keys over text messages when possible. CISA has published guidance encouraging stronger, phishing-resistant forms of MFA for high-risk accounts.
Special handling for privileged accounts
Administrator accounts deserve extra care.
- Use separate admin accounts that are never used for email or browsing
- Require phishing-resistant MFA where available
- Store emergency "break glass" credentials securely and test them
- Review who holds admin rights quarterly
Responding to a breach notice
When a service you use reports a breach, or a monitoring tool flags exposed credentials:
- Change the password on that service immediately.
- Change it anywhere else it was reused.
- Check for suspicious sign-ins or new forwarding rules.
- Confirm MFA is enabled.
Keep the rules short
A one-page standard works better than a long policy:
- Use a password manager.
- Make passwords long and unique.
- Never share your password.
- Approve only MFA prompts you started.
- Report anything odd right away.
Handling resistance
Attorneys may complain that security slows them down. Make the secure path easy: single sign-on, a good password manager integrated with browsers, and MFA methods that take a few seconds. Explain with a concrete example, such as a reused password turning one retailer's breach into a client-data incident.
Verify, do not assume
Ask your IT provider for a report on accounts without MFA, accounts with old passwords exposed in breach data, and shared accounts still in use. Fixing these three lists makes a measurable difference.
Our offer
Counsel Cyber helps firms roll out password managers, MFA, and policy updates with minimal friction for attorneys. If you would like a quick account-hygiene review, we can help you see where your biggest exposures are.