Attorneys work in courthouses, airports, client offices, kitchens and cars. The phone in a lawyer's pocket usually holds email, calendar, documents and contact details for clients, along with access to the practice-management system. It is a small computer with a very large amount of firm information, and it travels everywhere.
ABA Formal Opinion 498, on virtual practice, and Formal Opinion 477R, on securing communications, both address the risks of working outside the office, and both emphasize reasonable, risk-based safeguards. This article translates those themes into specific steps. It is general information, not legal advice.
Set a Baseline for Every Device
Require screen locks and encryption
Every phone, tablet and laptop that touches firm data should have a passcode or biometric lock and full-device encryption, which is typically on by default on current phones but should still be verified. A strong passcode, rather than a four-digit PIN, is a meaningful improvement.
Keep software updated
Updates often fix security flaws that attackers actively exploit. Turn on automatic updates, and have IT report on devices that fall behind.
Use device management
Mobile device management lets the firm enforce settings, separate work data from personal apps, remotely wipe lost devices and block access from devices that fail checks. It is far easier to require it at onboarding than to retrofit it later.
Control app and account access
Require MFA on email and firm apps. Review which apps can access work data, and restrict installation of unvetted apps on managed devices.
Personal Phones and Bring-Your-Own-Device
Many firms allow personal phones for email. If so, define the rules.
- Require the management profile or a secure app container.
- Separate work and personal data, so a wipe affects only firm information.
- Agree in writing what the firm may do, including remote wipe of work data.
- Prohibit saving client documents to personal cloud storage or messaging apps.
- Set a rule for what happens when the person leaves.
Public Wi-Fi and Travel
Public networks
Airport, hotel and coffee-shop Wi-Fi can be monitored or spoofed. Modern encrypted connections reduce the risk, but prudent habits still help.
- Prefer a personal hotspot for sensitive work.
- Use the firm's VPN or secure access service when connecting to internal resources.
- Do not ignore browser certificate warnings.
- Turn off automatic connection to open networks.
Physical surroundings
- Use a privacy screen on laptops in public.
- Do not discuss client matters where others can overhear, and keep video calls private.
- Never leave devices unattended in cars, hotel rooms or conference tables.
Charging and accessories
Avoid public USB charging stations when possible; use your own charger and outlet or a data-blocking adapter.
Border crossings
Travel to other countries can raise questions about device searches. Firms that handle sensitive matters may consider loaner devices with minimal data for international trips. Policies on this vary and the legal landscape is complex, so consult counsel about advice for your attorneys.
Messaging and Texting
Text messages and consumer messaging apps may be convenient, but they can place client information in uncontrolled places. Set rules about what may be shared, which apps are approved and how messages that form part of the record are preserved. Ask clients to avoid sending sensitive information by unsecured channels.
Lost or Stolen Devices
Speed matters, so build the steps into a short procedure.
- Report the loss to IT immediately, day or night.
- IT locks the device and, if needed, wipes it remotely.
- Reset passwords and revoke sessions for the affected user.
- Determine whether the device was encrypted and what data it contained.
- Document the event, since breach analysis may depend on it.
An encrypted, managed device that is wiped quickly is often a manageable incident. An unencrypted one with saved passwords is much worse.
Phishing on Phones
Small screens hide details like full sender addresses and link destinations. Texts that pretend to come from a bank, delivery service or the firm itself are common. Teach staff to avoid tapping links in unexpected texts and to report them.
Train and Remind
Include mobile habits in regular awareness training. A brief checklist on the back of a badge holder or phone case card can work better than a long policy.
Counsel Cyber manages mobile and remote-work security for law firms, including device management, secure access and lost-device procedures. If your attorneys carry firm data on personal phones, we can help you set sensible rules.