ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Multi-Factor Authentication for Law Firms: Where to Turn It On First

Not every login needs MFA on day one. Here is a prioritized rollout order for law firms, with tips for avoiding attorney pushback and weak methods.

3 min readBy Counsel Cyber Team

Multi-factor authentication, or MFA, adds a second proof of identity beyond a password. It is among the most effective steps a firm can take against stolen credentials, which remain a common way attackers get into email and document systems. CISA has long encouraged organizations to turn it on, and cyber insurers frequently ask about it.

Yet many firms have MFA in some places and not others. If you cannot do everything at once, this order gives you the most protection first.

Priority one: email

Email is the master key. Password resets for other systems flow through it, and attackers use compromised mailboxes to launch wire fraud. Enforce MFA on every Microsoft 365 or Google Workspace account, including shared and administrative accounts. Block legacy protocols that cannot use MFA, since attackers will use any door left open.

Priority two: administrator accounts

Anyone with administrative rights over your tenant, servers, firewall, backup system or practice-management platform should use MFA, and ideally a separate admin account that is not used for daily email. A compromised admin account can disable security tools and delete backups.

Priority three: remote access

VPN, remote desktop and any portal exposing internal systems to the internet need MFA. Attackers constantly scan for remote access without it.

Priority four: practice management and document systems

Clio, NetDocuments, iManage and similar platforms hold the most sensitive material in the firm. Most offer MFA, and enabling it for every user is worth the small friction.

Priority five: everything else

Billing, payroll, banking portals, e-filing accounts, court systems that support it, and other cloud apps. Banking is arguably higher on the list for firms with trust accounts, so ask your bank what it offers.

Choosing the method

Not all second factors are equal.

  • Strongest: hardware security keys or passkeys, which resist phishing.
  • Good: authenticator app with number matching.
  • Weaker: SMS text codes, which can be intercepted or SIM-swapped, though still better than nothing.
  • Avoid approving prompts blindly: attackers use "MFA fatigue," sending repeated prompts until someone taps approve. Number matching and staff training reduce this risk.

Rolling it out without a revolt

  1. Explain why. A five-minute partner briefing about how credential theft works helps more than a policy memo.
  2. Start with the partners. When leadership uses it, everyone else follows.
  3. Offer a pilot group for a week to find problems before the whole firm switches.
  4. Provide hands-on enrollment help. Sit with people who are not comfortable with phones.
  5. Plan for lost phones. Have a verified process for resetting a user's MFA, since attackers will call the help desk pretending to be locked-out employees.
  6. Make exceptions rare and documented. Every exception is a weak spot.

Common mistakes

  • Enabling MFA for users but leaving old apps that bypass it.
  • Letting one shared login stay without MFA because "everyone needs it."
  • Not covering vendors and contractors who access your systems.
  • Forgetting to remove old devices from a departed employee's account.

Why this matters for firms

ABA Model Rule 1.6(c) calls for reasonable efforts to prevent unauthorized access to client information, and ABA Formal Opinion 477R discusses how the facts and available safeguards bear on what is reasonable. The ABA has not mandated MFA by name, but it is widely treated as a baseline control. Check with your state bar for any local guidance.

Measuring progress

Track three simple numbers each month: the percentage of accounts with MFA enforced, the number of accounts with exceptions, and the number of sign-ins blocked or challenged. Share them with partners in a short report. Seeing coverage move from partial to complete is motivating, and a persistent exception list shows exactly where to focus next. Review the list at every quarterly meeting with your IT provider, and ask why each exception still exists.

What to tell clients

Clients increasingly ask about authentication in security questionnaires. Being able to answer that MFA is enforced on email, remote access and your document systems, with documented exceptions and a plan, is a far stronger response than a hesitant maybe.

Next step

Make a list of every system holding client data and mark whether MFA is enforced, optional or unavailable. Counsel Cyber can run that inventory for you and sequence a rollout that respects your attorneys' schedules.