Multi-factor authentication, or MFA, asks for something beyond a password, such as a code or an approval on a phone. CISA and other government agencies consistently recommend it as a foundational control, and cyber insurers commonly ask about it. Even so, it is often deployed unevenly at law firms, with exceptions for senior lawyers or "just this one system."
Many of those gaps come from myths. Here are the most common ones, and what is closer to the truth.
Myth 1: "We are too small to be a target"
Attackers do not usually pick victims by name. They run automated campaigns across thousands of accounts, looking for passwords that were reused or leaked. A small firm with weak sign-in controls is easy to find. Law firms also hold valuable material, such as settlement funds and confidential client files, which makes them attractive no matter the size.
Myth 2: "Our passwords are strong"
A strong password still can be stolen. Phishing pages harvest passwords. Credentials leaked in unrelated breaches get tried against other sites. Passwords used in more than one place are only as safe as the weakest site. MFA reduces the damage when a password is exposed.
Myth 3: "MFA is too inconvenient for attorneys"
A modern setup adds a few seconds, and many sign-ins can be remembered on trusted devices for a period. The inconvenience of a compromised mailbox, with a week of cleanup and client notifications, is much larger. If convenience is a real concern, choose a smoother method such as an authenticator app or a hardware security key instead of dropping MFA.
Myth 4: "Text message codes are as good as anything"
Text codes are far better than nothing, and any MFA beats none. But text messages can be intercepted or diverted through SIM swapping, and codes can be typed into fake sign-in pages. Stronger options include authenticator apps with number matching, passkeys and hardware security keys, which are more resistant to phishing. For administrators and partners with broad access, aim for the strongest method your systems support.
Myth 5: "If MFA is on, we are safe"
MFA is a major improvement, not an invincible shield. Attackers have developed techniques that try to get around it.
- Approval fatigue. The attacker repeatedly triggers prompts hoping the user taps "approve" to make them stop.
- Real-time phishing. A fake page relays the user's code to the real site and steals the session.
- Token theft. Malware on a device copies an already authenticated session.
The answer is layers: number-matching prompts, phishing-resistant methods where possible, conditional access rules, endpoint protection and monitoring for odd sign-ins. Train staff to report unexpected prompts rather than approve them.
Myth 6: "We turned it on, so it covers everything"
Check the coverage. Gaps frequently include:
- Older protocols and legacy email apps that do not support MFA.
- Shared mailboxes and service accounts.
- VPN, remote access and remote desktop.
- Practice management, document management and billing systems.
- Administrator accounts, which should always be protected.
- The "temporary" exception granted two years ago to a senior partner.
Ask your IT provider for a report listing every account and its MFA status, and review exceptions with the managing partner.
Myth 7: "MFA is an IT issue, not a partner issue"
Rule 1.1, Comment 8 of the ABA Model Rules refers to keeping abreast of the benefits and risks of relevant technology, and Rule 1.6(c) addresses reasonable efforts to prevent unauthorized access to client information. Leadership sets the tone. If partners ask for exceptions, staff will notice. Many firms find that adoption improves quickly once a partner announces that MFA applies to everyone, starting with them.
A short rollout plan
- Turn on MFA for email and administrator accounts first.
- Extend to remote access, practice management and document management.
- Retire legacy authentication methods.
- Move high-risk users to stronger methods.
- Review exceptions monthly until there are none.
- Give staff a clear path to report unexpected prompts.
Next step
Counsel Cyber helps law firms deploy MFA smoothly and audit where it is still missing. If you want a list of your current gaps, we can produce one in a short review and help you close them without disrupting your lawyers.