ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

New Attorney Onboarding: A Day-One IT Checklist for Law Firms

A practical checklist for onboarding a new attorney or paralegal, so accounts, devices, security and training are ready before the first billable hour.

3 min readBy Counsel Cyber Team

A new hire's first morning sets a tone. When the laptop is ready, the accounts work and the attorney can open a matter before lunch, the firm looks organized. When logins fail and the printer is a mystery, productive time leaks away and security shortcuts begin, such as borrowing a colleague's password.

Onboarding is also a security event. Every new account is new access to client information. This checklist helps firm administrators get the sequence right.

Two Weeks Before Start

Confirm the role and access profile

Decide in advance what the person needs: which practice groups, which matter folders, which billing permissions. Define access by role rather than copying another user. Copying a colleague's permissions is how people end up with access to files they never should see.

Order and prepare equipment

  • Laptop or desktop, monitors, docking station and headset.
  • Disk encryption turned on and verified.
  • Standard security software installed and reporting.
  • Operating system and applications fully updated before the device is handed over.
  • Mobile device enrolled in management if the person will access firm email on a phone.

Create accounts in advance

Set up the email account, directory account, document management and practice-management access, phone extension and any research or e-filing tools. Enforce multi-factor authentication from the start, and have the person enroll during onboarding rather than later.

Day One

  1. Hand over the device in person or by tracked shipment with written instructions for the first login.
  2. Walk through multi-factor enrollment and show how to approve prompts safely, including why an unexpected prompt should be reported, not approved.
  3. Set up a password manager and explain why reusing passwords across systems is prohibited.
  4. Review the acceptable use and confidentiality policies and collect a signed acknowledgment.
  5. Introduce how to get help, including the help desk number, how to report a suspicious email and what to do if a device is lost.
  6. Complete short security awareness training, focused on phishing and wire-fraud attempts that target legal staff.

First Week

Verify the practicalities

Confirm printing, scanning, remote access, conferencing, e-signature and the phone system all work. Check in after a few days, since people often hesitate to report small annoyances.

Apply the "least privilege" principle

After a few days, confirm that access matches actual work. It is easier to add permissions that are needed than to clean up excess later. Ethical walls and conflicts screens should be reflected in system permissions, not just in policy.

Document the setup

Record the device serial number, assigned software licenses and the accounts created. This documentation matters for audits, insurance questions and eventual offboarding.

Why This Process Connects to Professional Duties

ABA Model Rules 5.1 and 5.3 address supervisory responsibilities for lawyers and for nonlawyer assistance. Training new staff on confidentiality and security expectations from day one is a straightforward way to show that supervision happens in practice. Confirm specifics with your state bar, but a documented onboarding routine is easy to defend.

Do Not Forget Offboarding

The mirror image of this checklist matters just as much. When someone leaves, disable accounts the same day, recover devices, transfer mailbox and file ownership, remove access from cloud tools and revoke phone enrollment. Departing employees with lingering access are a common and preventable risk.

Common Mistakes

  • Waiting until the first morning to create accounts.
  • Granting broad access because it is faster.
  • Skipping multi-factor enrollment "until things calm down."
  • Letting new hires bring personal devices into the environment without management.
  • Having no record of what was issued.

Make It Repeatable

Turn this checklist into a ticket template that your IT provider and your administrator both follow, with a named owner for each step. Review it twice a year and after any incident.

How Counsel Cyber Helps

Counsel Cyber handles onboarding and offboarding for law firm clients as part of managed IT, including role-based access and security setup. If your current process depends on one person's memory, we can help turn it into a repeatable workflow.