ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Phishing-Resistant MFA: A Practical Guide for Small Law Firms

Not all multi-factor authentication is equal. Learn which MFA methods hold up against phishing and how a law firm can roll out stronger options step by step.

3 min readBy Counsel Cyber Team

Turning on multi-factor authentication is one of the most effective steps a law firm can take, and most firms have done it. But attackers have adapted. Phishing kits can now sit between your attorney and the real sign-in page, capturing the password and the one-time code at the same moment. If your MFA relies on text-message codes alone, that is worth a closer look.

CISA has published guidance describing "phishing-resistant" MFA and encouraging organizations to move toward it, especially for administrators and other high-value accounts. Here is what that means in practical terms for a firm without a large IT department.

The MFA methods, from weakest to strongest

SMS and voice codes

Better than a password alone, but codes can be intercepted by SIM-swapping or relayed by a phishing page. Use only if nothing better is available.

Authenticator app codes

A six-digit code from an app is stronger than SMS, but it can still be typed into a fake page and relayed by an attacker in real time.

Push approval with number matching

Push notifications that require typing a number shown on the sign-in screen reduce "approval fatigue" attacks, where a user taps Approve on a request they did not initiate. This is a meaningful improvement over simple tap-to-approve.

Passkeys and security keys

FIDO2 security keys and passkeys are bound to the real website's address, so they will not work on a lookalike page. This is the category CISA calls phishing-resistant. Options include hardware keys, built-in laptop biometrics such as Windows Hello, and passkeys stored on phones.

Who should move first

You do not need to switch everyone on day one. Prioritize:

  1. IT administrator and global admin accounts
  2. Managing partners and anyone who approves payments or wires
  3. Accounting and finance staff
  4. Anyone with access to trust account systems
  5. Everyone else, in phases

A rollout plan that does not disrupt the practice

  1. Audit today's state. List each account type and which MFA method it uses. Confirm that MFA is truly enforced, not merely available.
  2. Close the gaps first. Eliminate legacy email protocols that bypass MFA, and remove exceptions granted "temporarily" long ago.
  3. Disable the weakest options for admins. Require a security key or passkey for privileged accounts.
  4. Pilot with a small group. Choose two or three tolerant users, usually a partner and an assistant, and collect feedback for a couple of weeks.
  5. Issue backup methods. Every user needs a second registered method so that a lost phone does not stop an associate from working before a hearing.
  6. Train briefly. A 15-minute session showing what a legitimate prompt looks like, and what to do about an unexpected one, prevents most frustration.
  7. Document recovery. Define how the help desk verifies identity before resetting a user's MFA, since attackers target that step.

Common objections

  • "It slows attorneys down." Passkeys with a fingerprint or face unlock are typically faster than typing a code.
  • "Our staff use personal phones." Passkeys can be stored on a phone, but a hardware key is an option for those who prefer separation of personal and firm devices.
  • "We have older software that doesn't support it." Put it behind a modern single sign-on or remote access gateway, or plan its replacement.

Do not forget the help desk

Many real-world account takeovers happen when someone calls support claiming to be a locked-out user. Write down a verification procedure, such as a call-back to a known number, and make sure the help desk follows it every time.

Practical advice on cost

Hardware keys are a modest per-user expense, and many Microsoft 365 plans already include the controls needed for passkeys and number matching. Confirm what your licensing allows before buying anything.

Getting started with Counsel Cyber

We help law firms audit their current MFA, enforce it consistently and move high-risk accounts to phishing-resistant methods. If you would like a quick assessment, we can review your configuration and give you a prioritized plan.