Many law firms still hand new employees a password policy written years ago: change it every 90 days, use eight characters with a number and a symbol. Security guidance has moved on. NIST's digital identity guidelines, for example, now recommend against forcing routine periodic password changes and against arbitrary composition rules, favoring length, screening against known-compromised passwords and multi-factor authentication.
Updating how your firm approaches credentials is one of the cheapest, highest-return security improvements available.
What Is Wrong With the Old Advice
Forced rotation encourages predictable patterns, such as "Summer2026!" becoming "Fall2026!". Complexity rules lead to passwords that are hard for people to remember but easy for computers to guess. Staff reuse passwords across sites because they cannot remember dozens of unique ones. When any one of those sites is breached, attackers try the same combination on your firm's email.
Pillar 1: Password Managers
A password manager stores unique, long, random passwords for every account and fills them in. Employees remember one strong passphrase and the manager does the rest.
Why firms should provide one
- It makes unique passwords for every system practical.
- It can warn about reused or compromised passwords.
- It lets administrators share credentials for legitimate shared systems without emailing them.
- It helps with offboarding, since access to shared items can be revoked.
Choosing and rolling out
Pick a business-grade product with administrative controls, and pay for it rather than relying on staff to choose personal tools. Provide a short training, import existing passwords where possible and require MFA on the manager itself. Explain that its master passphrase is the one thing to protect most carefully.
Pillar 2: Multi-Factor Authentication
MFA remains the strongest single defense against stolen passwords. Methods differ in strength.
- Hardware security keys and passkeys: Strongest, and resistant to phishing.
- Authenticator app with number matching or prompts: Strong and widely supported.
- Text message codes: Better than nothing but weaker, since phone numbers can be hijacked and codes can be phished.
Move toward the strongest method your systems support, especially for administrators, partners and finance staff. Be alert to "MFA fatigue" attacks, in which an attacker triggers repeated approval prompts hoping the user taps accept. Train staff to deny unexpected prompts and report them immediately.
Pillar 3: Passkeys
Passkeys replace passwords with cryptographic credentials stored on a device and unlocked by a fingerprint, face or device PIN. They resist phishing because they only work on the real website. Support has been growing across major platforms. Where your key systems support passkeys, consider enabling them. Keep a recovery plan for lost devices.
A Simple Policy Outline
- Use a firm-approved password manager for all work credentials.
- Passwords or passphrases should be long; length matters more than symbols. Many experts suggest at least 14 characters for important accounts.
- Never reuse a work password anywhere else.
- Change a password immediately if you suspect compromise, not on a calendar.
- Use MFA on every account that supports it.
- Never share personal credentials, and use named accounts so activity is attributable.
- Never approve an MFA prompt you did not initiate.
- Report lost phones or suspected phishing at once.
Admin and Shared Accounts
Administrators should have separate, privileged accounts used only when needed, with the strongest MFA available. Shared accounts, such as for a scanner or a social-media login, should be minimized, stored in the password manager and rotated when someone leaves.
Check for Exposed Credentials
Ask your IT provider whether the firm's email addresses show up in known breach data and whether systems screen new passwords against known-compromised lists. Many modern identity platforms offer this.
Address the Human Side
Staff resist change when it adds friction. Make the new approach easier than the old one: single sign-on where possible, a password manager that autofills and a brief explanation of why. Lawyers respond well to risk framed in terms of client duties. ABA Model Rule 1.6(c) asks for reasonable efforts to protect client information, and strong authentication is among the plainest examples of reasonable efforts.
Retire the Sticky Note
If passwords are written on paper at desks, treat it as a symptom. Roll out the manager, and ask people to hand in the notes.
Counsel Cyber helps law firms deploy password managers, MFA and single sign-on, and update policies to match current guidance. If your current password policy is a decade old, we can help refresh it.