ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Multi-Factor Authentication for Law Firms: Beyond Text Messages

Not all MFA is equal. Compare authenticator apps, number matching, hardware keys and SMS codes, and learn how to roll out stronger MFA across your firm.

3 min readBy Counsel Cyber Team

Turning on multi-factor authentication is one of the most effective steps a law firm can take, and most firms have done it. But "we have MFA" covers a wide range of protection. A text message code is better than a password alone, and a hardware security key is much better than a text message. Attackers know the difference, and they target the weaker methods.

This post explains the options and how to choose.

Why Not All MFA Is Equal

Attackers have adapted to MFA in several ways:

  • Phishing pages that capture codes. A fake sign-in page collects your password and your one-time code, then uses both immediately.
  • MFA fatigue. The attacker triggers repeated approval prompts until a tired or confused user taps "approve."
  • SIM swapping. The attacker convinces a phone carrier to move your number to their device, receiving your text codes.
  • Session theft. Malware or a proxy steals the logged-in session after MFA has already succeeded.

CISA has encouraged organizations to adopt phishing-resistant MFA, particularly for high-risk accounts. That guidance is worth reading, and it points toward the stronger end of the options below.

The Options, From Weakest to Strongest

SMS or voice codes

Easy and familiar, but vulnerable to SIM swapping and interception, and codes can be phished. Better than nothing; not a good long-term choice for important accounts.

Authenticator app with one-time codes

Apps that generate a rotating code avoid the phone-carrier risks. They are still phishable, because a user can type a code into a fake page.

Push approval with number matching

The user approves a prompt on their phone, and the sign-in screen displays a number they must enter. This blunts MFA fatigue because a random approval is no longer enough. It is a meaningful improvement over simple push prompts.

Passkeys and hardware security keys

These use cryptographic credentials tied to the real website, so a fake page cannot capture something usable. They are considered phishing-resistant. Hardware keys and passkeys require more setup and user education, but they offer the strongest protection of the common options.

A Practical Strategy for a Firm

You do not need to deploy the strongest method for everyone at once. Prioritize.

  1. Start with everyone on an authenticator app with number matching, and phase out SMS.
  2. Give stronger methods to higher-risk accounts first: managing partners, administrators, finance and anyone who approves wire transfers or holds admin rights.
  3. Disable legacy protocols that bypass MFA, such as old email protocols that do not support modern authentication.
  4. Use conditional access where available, to require MFA from new devices or locations and to block sign-ins from countries where you have no business.
  5. Cover everything: email, practice management, document management, VPN, remote desktop, password manager, backup console and any admin portal.

Rollout Tips

  • Explain the why. Staff accept MFA more readily when they understand the threat.
  • Enroll in person or by video with help from IT, instead of by email.
  • Plan for lost phones. Define a verified recovery process so help-desk staff cannot be socially engineered into resetting MFA for an attacker.
  • Register backup methods, such as a second key kept somewhere safe.
  • Teach the rule: never approve a prompt you did not trigger, and report unexpected prompts immediately.
  • Don't exempt partners. Exemptions create the weak link.

Check for Gaps

Run a report of accounts without MFA, service accounts and shared mailboxes. Many incidents start with the one forgotten account.

What MFA Does Not Fix

MFA is one control, not a complete defense. It does not stop a user from handing over data willingly, from authorizing a fraudulent wire, or from installing malware. Pair it with email security, endpoint monitoring, training and a wire verification process.

Next Steps

Counsel Cyber helps firms review MFA coverage, move to phishing-resistant methods and set up recovery procedures that do not become a loophole. If you are not sure how your firm measures up, ask us for a quick review.