ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Password Management for Law Firms: Policies Staff Will Follow

Password rules that frustrate people get worked around. Build a policy around a firm password manager, length and MFA instead of constant forced changes.

3 min readBy Counsel Cyber Team

Few security topics generate more eye-rolling than passwords. Staff juggle dozens of accounts for email, practice management, court portals, research services, banking and vendors. Under pressure, they reuse passwords, write them on sticky notes or save them in a shared spreadsheet. Then something leaks, and one reused password opens several doors.

A sensible policy makes the secure choice the easy choice. Current guidance from bodies such as NIST has moved away from some older habits, like frequent forced changes and complex character rules, toward length, uniqueness, screening against known breached passwords and multi-factor authentication. Confirm current recommendations as they evolve.

What a good policy emphasizes

Unique passwords for every account

Reuse is the biggest practical risk. When a third-party site is breached, attackers try the leaked email and password combinations on other services. A unique password per account limits the blast radius.

Length over complexity

A long passphrase made of several unrelated words is generally stronger and easier to remember than a short string stuffed with symbols. Many guidelines now favor minimum lengths of around twelve to fifteen characters or more for human-chosen passwords. A password manager can generate far longer ones.

A firm-approved password manager

Asking people to remember dozens of unique passwords is unrealistic. A business password manager stores credentials in an encrypted vault, fills them in automatically and generates strong passwords. Choose a business-grade product that offers:

  • Centralized administration and user provisioning.
  • Strong encryption and a clear security record.
  • MFA for vault access.
  • Shared folders with access controls, so teams can share credentials like a court e-filing login without emailing them.
  • Reporting on weak, reused or exposed passwords.
  • Emergency access and a documented recovery process.

MFA everywhere it is available

Passwords alone are not enough. Pair them with MFA for email, remote access, practice management, banking portals and administrator accounts.

Changing passwords when it matters

Instead of forcing changes every 90 days, which tends to produce predictable patterns like adding a number, require a change when there is evidence of compromise, when someone leaves the firm or when a breach affects a service.

Policy elements to write down

  1. Scope: who and what it applies to, including contractors.
  2. Required tools: staff must use the firm's password manager for work accounts.
  3. Prohibitions: no password sharing over email or chat, no storing passwords in documents or on sticky notes, no reusing work passwords on personal sites.
  4. Master password: a long, unique passphrase known only to the user, protected with MFA.
  5. Shared accounts: where unavoidable, store in a shared vault with logged access, and rotate when staff leave.
  6. Reporting: how to report a suspected compromise, with a no-blame tone.
  7. Exceptions: a process for legacy systems that cannot support the rules.

Dealing with shared logins

Law firms often share logins for court systems, research tools or vendor portals. Treat them as managed risks.

  • Prefer individual accounts when the vendor supports them.
  • If sharing is necessary, store credentials in the password manager rather than in email or a spreadsheet.
  • Rotate the password when someone leaves the firm.
  • Where possible, enable MFA using a method the team can share safely, or assign a responsible owner.

Rolling it out

Policy documents alone do not change behavior. Plan a rollout.

  1. Choose a manager and pilot with a small group.
  2. Provide a short, hands-on training session, including how to use the browser extension and mobile app.
  3. Help people migrate existing passwords and clean up duplicates.
  4. Set a deadline and offer a help desk drop-in.
  5. Have partners go first. People notice when leadership exempts itself.
  6. Review the manager's reports quarterly and follow up on weak or reused items.

Handling resistance

  • "It is one more thing to learn." Show how it saves time with autofill.
  • "What if the vault is hacked?" Explain that reputable managers encrypt data so the vendor cannot read it, and that the alternative, reuse, is a bigger risk.
  • "I forgot my master password." Plan recovery and emergency access in advance.

Beyond passwords

Consider passkeys and single sign-on where supported. They reduce the number of passwords people handle and are more resistant to phishing. Over time, the aim is fewer passwords, not better ones alone.

Connect to ethics and insurance

Rule 1.6(c) and technology competence under Rule 1.1, Comment 8, are often cited when discussing access controls. Insurers and clients may ask whether you require MFA and a password manager. A written policy and deployment report answer both.

Next step

Counsel Cyber helps law firms select and roll out password managers and write policies that staff actually follow. If your current approach relies on memory and spreadsheets, we can help you move to something safer.