Few security topics generate more eye-rolling than passwords. Staff juggle dozens of accounts for email, practice management, court portals, research services, banking and vendors. Under pressure, they reuse passwords, write them on sticky notes or save them in a shared spreadsheet. Then something leaks, and one reused password opens several doors.
A sensible policy makes the secure choice the easy choice. Current guidance from bodies such as NIST has moved away from some older habits, like frequent forced changes and complex character rules, toward length, uniqueness, screening against known breached passwords and multi-factor authentication. Confirm current recommendations as they evolve.
What a good policy emphasizes
Unique passwords for every account
Reuse is the biggest practical risk. When a third-party site is breached, attackers try the leaked email and password combinations on other services. A unique password per account limits the blast radius.
Length over complexity
A long passphrase made of several unrelated words is generally stronger and easier to remember than a short string stuffed with symbols. Many guidelines now favor minimum lengths of around twelve to fifteen characters or more for human-chosen passwords. A password manager can generate far longer ones.
A firm-approved password manager
Asking people to remember dozens of unique passwords is unrealistic. A business password manager stores credentials in an encrypted vault, fills them in automatically and generates strong passwords. Choose a business-grade product that offers:
- Centralized administration and user provisioning.
- Strong encryption and a clear security record.
- MFA for vault access.
- Shared folders with access controls, so teams can share credentials like a court e-filing login without emailing them.
- Reporting on weak, reused or exposed passwords.
- Emergency access and a documented recovery process.
MFA everywhere it is available
Passwords alone are not enough. Pair them with MFA for email, remote access, practice management, banking portals and administrator accounts.
Changing passwords when it matters
Instead of forcing changes every 90 days, which tends to produce predictable patterns like adding a number, require a change when there is evidence of compromise, when someone leaves the firm or when a breach affects a service.
Policy elements to write down
- Scope: who and what it applies to, including contractors.
- Required tools: staff must use the firm's password manager for work accounts.
- Prohibitions: no password sharing over email or chat, no storing passwords in documents or on sticky notes, no reusing work passwords on personal sites.
- Master password: a long, unique passphrase known only to the user, protected with MFA.
- Shared accounts: where unavoidable, store in a shared vault with logged access, and rotate when staff leave.
- Reporting: how to report a suspected compromise, with a no-blame tone.
- Exceptions: a process for legacy systems that cannot support the rules.
Dealing with shared logins
Law firms often share logins for court systems, research tools or vendor portals. Treat them as managed risks.
- Prefer individual accounts when the vendor supports them.
- If sharing is necessary, store credentials in the password manager rather than in email or a spreadsheet.
- Rotate the password when someone leaves the firm.
- Where possible, enable MFA using a method the team can share safely, or assign a responsible owner.
Rolling it out
Policy documents alone do not change behavior. Plan a rollout.
- Choose a manager and pilot with a small group.
- Provide a short, hands-on training session, including how to use the browser extension and mobile app.
- Help people migrate existing passwords and clean up duplicates.
- Set a deadline and offer a help desk drop-in.
- Have partners go first. People notice when leadership exempts itself.
- Review the manager's reports quarterly and follow up on weak or reused items.
Handling resistance
- "It is one more thing to learn." Show how it saves time with autofill.
- "What if the vault is hacked?" Explain that reputable managers encrypt data so the vendor cannot read it, and that the alternative, reuse, is a bigger risk.
- "I forgot my master password." Plan recovery and emergency access in advance.
Beyond passwords
Consider passkeys and single sign-on where supported. They reduce the number of passwords people handle and are more resistant to phishing. Over time, the aim is fewer passwords, not better ones alone.
Connect to ethics and insurance
Rule 1.6(c) and technology competence under Rule 1.1, Comment 8, are often cited when discussing access controls. Insurers and clients may ask whether you require MFA and a password manager. A written policy and deployment report answer both.
Next step
Counsel Cyber helps law firms select and roll out password managers and write policies that staff actually follow. If your current approach relies on memory and spreadsheets, we can help you move to something safer.