ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Securing Laptops and Phones Your Attorneys Take Home

Attorneys work from courtrooms, kitchens and airports. These encryption, device management and policy steps keep client data safe when devices leave the office.

3 min readBy Counsel Cyber Team

A firm's data no longer lives in the office. It travels on laptops to depositions, on phones to hearings and on tablets to kitchen tables. Every one of those devices can be lost, stolen, shared with a family member or infected by a careless download. Protecting the firm now largely means protecting its endpoints.

ABA Formal Opinion 498, on virtual practice, discusses reasonable efforts when lawyers work remotely, including attention to devices, networks and access to client files. Your state bar may add its own expectations. The steps below are practical baselines for a small or mid-size firm.

Start with an inventory

You cannot protect devices you do not know about. List every laptop, desktop, phone and tablet that touches firm data, who uses it and whether the firm or the individual owns it. Include home computers used occasionally, since they are often the weakest link.

Turn on full-disk encryption

Encryption makes a lost laptop an inconvenience instead of a breach. Windows and macOS both include built-in tools, BitLocker and FileVault. Enable them on every device, verify that it is actually on, and store recovery keys somewhere the firm controls, not on a sticky note taped to the machine. Phones are generally encrypted when a passcode is set, so require one.

Keep systems updated

Most attacks exploit known flaws for which a patch exists. Configure automatic operating system and application updates, and use management tools so IT can see which devices are behind. Retire hardware that no longer receives security updates.

Use real endpoint protection

Consumer antivirus is not enough for a law firm. Look for endpoint detection and response with someone watching the alerts, so suspicious behavior is investigated and a compromised device can be isolated quickly, even if it is in an attorney's home.

Manage mobile devices

Mobile device management, or MDM, lets the firm enforce settings without taking over a person's phone.

  • Require a passcode or biometric lock and an automatic lock time.
  • Separate work and personal data where the platform allows it.
  • Enable remote lock and remote wipe for lost devices, and use selective wipe for personal phones.
  • Limit which apps can open or copy work email and documents.

Decide the rules for personal devices

Bring-your-own-device is common. Whatever you choose, set conditions. A reasonable policy might say personal devices must be enrolled in management, encrypted, updated, passcode protected and free of work data stored locally, with access through approved apps. If someone will not agree to those conditions, they use a firm device.

Secure connections

  • Use a firm-managed VPN or a modern zero-trust access tool when reaching internal resources.
  • Avoid conducting confidential work on public Wi-Fi without protection, and teach staff why.
  • Encourage hotspots over unknown networks when traveling.
  • Configure home routers with updated firmware and a strong password, and advise staff to do the same.

Travel and courthouse habits

Teach practical habits that cost nothing.

  1. Never leave a laptop in a parked car or unattended in a conference room.
  2. Use a privacy screen on planes and in cafes.
  3. Lock the screen whenever stepping away.
  4. Do not plug into unknown charging stations or USB ports.
  5. Report a lost device immediately, even if you hope to find it.

Protect shared family environments

Policy should address family members using the same computer. Ideally, work happens on a firm device used only by the employee, with a separate account for any other user. At minimum, never leave the work session unlocked and do not allow others to use it.

Prepare for loss and theft

Create a short incident procedure.

  1. The user reports the loss to IT right away.
  2. IT locks or wipes the device and revokes sessions and tokens.
  3. IT checks whether the device was encrypted and whether data was stored locally.
  4. The firm determines if client information was exposed and, with counsel, whether notification is required.

Encryption is often the deciding factor in that last step, which is another reason to verify it everywhere.

Offboarding

When someone leaves, collect devices, wipe firm data from personal ones and disable access the same day. Keep an equipment checklist so nothing is forgotten.

Make it easy

Security that is painful gets bypassed. Provide good hardware, a reliable VPN and a simple way to get help, and attorneys will use them.

Support from Counsel Cyber

Counsel Cyber enrolls and manages devices for law firms, including encryption, endpoint protection and remote wipe. If you are not sure how many unmanaged devices touch your data, we can help you find out.