ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Remote Access to Practice Management Systems: A Secure Setup Guide

How hybrid and remote law firms can secure access to practice management and document systems with MFA, device rules, conditional access and sensible policies.

4 min readBy Counsel Cyber Team

A decade ago, most attorneys worked in the office, on firm-owned computers, behind a firm-owned network. Today, an attorney might open the practice management system from a courthouse hallway, a home office or a hotel. The ABA's Formal Opinion 498, on virtual practice, recognized this reality and discussed how existing duties of competence, confidentiality and supervision apply when lawyers work remotely.

Security has to follow the person and the device, not the building. Here is a practical setup guide for firm administrators.

Principle: assume the network is not trusted

Home Wi-Fi and public networks are outside your control. The safer assumption is that every sign-in attempt could come from anywhere, and the system should decide whether to allow it based on who is signing in, from what device and under what conditions.

Step 1: Strong identity

  1. Single sign-on. Where possible, use a central identity provider such as Microsoft Entra ID so users sign in once and the firm controls policies in one place.
  2. MFA for everyone. Prefer phishing-resistant methods for administrators and partners, and authenticator apps with number matching for others.
  3. Unique accounts. Avoid shared logins to practice management, document management or billing.
  4. Block legacy sign-in methods that cannot support MFA.

Step 2: Device requirements

Not every device deserves the same trust.

  • Firm-managed laptops should be encrypted, patched, protected by endpoint detection and enrolled in management software.
  • Personal devices should access firm data only through controlled means, such as a web session with restrictions, or a managed app that separates firm data. Require a passcode and allow remote removal of firm data.
  • Shared or public computers should not be used for client work.

Conditional access policies can enforce these rules automatically, for example by allowing full access only from compliant devices and limited browser-only access from others.

Step 3: Conditional access rules

Conditional access lets you set conditions beyond a password. Consider policies such as:

  1. Require MFA for all cloud applications.
  2. Require a compliant, managed device for access to sensitive systems.
  3. Block sign-ins from countries where the firm has no business or staff. Provide a travel exception process for attorneys who travel abroad.
  4. Require reauthentication after a defined period or when risk is detected.
  5. Block sign-ins that appear risky, such as impossible travel or known malicious addresses.

Test policies in report-only mode first so you do not lock out the managing partner on a Monday morning.

Step 4: Secure the connection

If staff need access to on-premises resources such as a file server or legacy application, choose a modern secure remote access method. Avoid exposing remote desktop services directly to the internet, which is a frequent ransomware entry point. Use a properly configured VPN or a zero-trust access service with MFA. For cloud-based practice management, ensure that staff reach it through the vendor's secure web or app interface rather than through improvised shortcuts.

Step 5: Protect data at the edge

  • Limit downloads. Where possible, let users work in the browser or app rather than saving local copies.
  • Disable personal cloud storage syncing for client folders.
  • Encrypt laptops and phones so loss or theft does not equal exposure.
  • Control printing and screen sharing policies for home environments.
  • Set automatic session timeouts on mobile applications.

Step 6: Home office hygiene

Short, plain guidance helps. Provide a one-page checklist covering:

  1. Update the router firmware and replace default passwords.
  2. Use a separate network for guests and smart devices where possible.
  3. Lock screens when away, including from family members.
  4. Do not discuss confidential matters where voice assistants or others could hear.
  5. Shred or securely dispose of printed documents.
  6. Use only firm-approved video conferencing tools.

Step 7: Monitoring and response

Make sure someone reviews sign-in logs for patterns such as repeated failures, sign-ins at odd hours or from unusual places. Enable alerts for new device registrations and administrator changes. Have a process for rapidly disabling an account and wiping a lost device.

Step 8: Write the policy

A short remote work policy, acknowledged by each attorney and staff member, should cover approved devices, networks, tools, data handling, reporting of lost devices and supervision of staff working remotely. Ask your state bar whether it has specific guidance on virtual practice.

Common mistakes

  • Giving personal phones full access without any controls.
  • Allowing old email protocols that bypass MFA.
  • Exempting senior attorneys from device rules.
  • Forgetting to test policies before enforcement.
  • Leaving vendor and contractor accounts outside policy.

Where we can help

Counsel Cyber designs and manages secure remote access for hybrid law firms, including conditional access policies tuned to how attorneys really work. If you would like to review your current remote setup, we can start with a short assessment of how your people sign in today.