Remote and hybrid work are routine for attorneys now. Depositions happen from hotel rooms, drafting happens at the kitchen table and a partner may review a brief on a phone at a child's soccer game. The ABA addressed this directly in Formal Opinion 498, on virtual practice, which discusses the lawyer's duties of competence and confidentiality when working remotely and notes issues such as securing devices, home networks and client communications.
The firm's security perimeter no longer stops at the office door. This checklist walks through what to put in place so working from elsewhere does not mean working unprotected. It is general information and not legal advice.
Devices
- Use firm-managed laptops whenever possible. Personal computers are harder to patch, encrypt and monitor.
- Full disk encryption on every laptop, so a lost device is not a breach.
- Automatic updates and patching managed centrally rather than left to individual choice.
- Endpoint detection and response installed and reporting.
- Screen lock after a short idle period, with a password or biometric.
- Remote wipe capability for laptops and phones.
- No shared family use. The laptop used for client work is not the one the kids use for games.
Phones and tablets
Require a passcode, enable device encryption and use mobile device management to separate firm data from personal data. Decide whether personal phones may access firm email and, if so, under what conditions.
Home network
Most home networks are configured once and forgotten. A few steps make a real difference.
- Change the default router administrator password.
- Use WPA2 or WPA3 wireless security with a strong passphrase.
- Keep router firmware updated, or replace routers that no longer receive updates.
- Separate work devices from smart TVs, cameras and other internet-connected gadgets where the router supports guest or separate networks.
- Turn off remote administration of the router unless needed.
Remote access
- Require multi-factor authentication for every remote login.
- Use a managed VPN or a secure cloud-based access method rather than exposing remote desktop directly to the internet. Exposed remote desktop services are a long-standing entry point for ransomware.
- Prefer applications accessed through a managed browser or virtual desktop so data stays in firm-controlled systems.
- Disable local saving of client files when a cloud workspace can be used instead.
Public and travel settings
- Avoid public Wi-Fi for client work, or use a managed VPN if unavoidable.
- Use a privacy screen on planes and in coffee shops.
- Never leave a laptop in a vehicle.
- Be careful of conversations: calls with clients should not be audible to strangers.
- Beware public charging ports; use your own charger or a data-blocking adapter.
- When traveling internationally, ask the firm administrator about device policies in advance.
Printing and paper at home
Decide whether printing client documents at home is allowed. If so, require shredding, not household trash. Locked storage for paper files is easy to forget and surprisingly important for anyone with roommates or visitors.
Video meetings and smart speakers
Use firm-approved meeting platforms with passcodes and waiting rooms. Check who is in the room. Smart speakers and voice assistants may be listening in a home office; consider muting or relocating them during privileged calls.
Collaboration and file sharing
Provide an approved way to share documents with clients and co-counsel. If it is slower than personal email, people will use personal email. Remind staff that personal cloud storage and consumer messaging apps are not for client documents unless approved.
Policy and acknowledgment
Create a short remote work policy covering the points above. Require attorneys and staff to acknowledge it annually. Include who to call if a device is lost or stolen, and stress reporting immediately rather than after a search of the house.
A quick self-check for attorneys
- Is my laptop encrypted and updated?
- Do I use MFA everywhere?
- Is my home Wi-Fi password strong and my router updated?
- Do I save files only to approved locations?
- Can I lock away paper files?
- Do I know how to report a lost device?
Administrators: verify, do not assume
Policies are only as good as their enforcement. Run a report of devices without encryption, devices missing updates and accounts without MFA. Fix exceptions promptly and revisit monthly.
How Counsel Cyber can help
Counsel Cyber secures and supports remote and hybrid law firm teams with managed devices, monitoring and clear policies. If you would like an assessment of your remote work setup, we are glad to help.