Remote and hybrid work is now routine in law practice. Attorneys draft at home, take calls from courthouse hallways, and review documents on airplanes. ABA Formal Opinion 498 addressed virtual practice and discussed lawyers' duties around technology competence, confidentiality, and supervision when working remotely. It touches on securing home networks, devices, and conversations. This post turns those themes into a practical setup guide. It is general information, not legal advice.
Devices
Firm-managed laptops
Provide a managed laptop to each attorney and staff member who works remotely. Standard configuration should include:
- Full-disk encryption
- Endpoint detection and response with monitoring
- Automatic operating system and application updates
- A screen lock after a short period of inactivity
- Remote lock and wipe capability for lost or stolen devices
Personal devices
If personal phones or computers must be used, limit the exposure. Use mobile application management so firm data lives inside a protected container, require a device PIN, and block downloading of files to unmanaged computers where possible. Browser-only access with no local storage is a reasonable approach for personal machines.
Access
- MFA on everything, with phishing-resistant methods for administrators and the most sensitive accounts
- Conditional access that checks device health and location before allowing sign-in
- VPN or zero-trust access for internal systems, with no remote desktop exposed directly to the internet
- Single sign-on to reduce password sprawl and make it easier to cut off access
Home networks
Most attorneys cannot become network engineers, but a few steps help.
- Change the default router password and keep the router firmware updated.
- Use WPA2 or WPA3 encryption with a strong Wi-Fi passphrase.
- Keep work devices off networks shared with smart-home gadgets where practical, for example by using a guest network for those gadgets.
- Avoid using public Wi-Fi for client work without a protected connection. Consider a personal hotspot as an alternative.
Everyday habits
Physical privacy
- Position screens away from windows and family members
- Take client calls where they cannot be overheard, and be mindful of voice assistants that may be listening
- Lock the device whenever stepping away, including at home
- Never leave a laptop in a parked car
Printing and paper
Printing at home creates paper copies that need secure storage and shredding. Set a rule: print only when necessary, and shred or return files to the office.
Communications
- Use firm-approved tools for messaging and video, and avoid personal chat apps for client matters
- Check meeting links and attendee lists before sharing sensitive material
- Use secure sharing rather than email attachments for sensitive files, and verify recipients
Policy and training
A short remote work policy should cover approved devices, home network expectations, handling of paper, use of public networks, lost-device reporting, and who to call with problems. Review it at onboarding and annually. Add scenario training: What if your laptop is stolen from a car? What if a link in your email asks you to re-enter your password?
Supervision
Under Model Rules 5.1 and 5.3, firms must make reasonable efforts to supervise lawyers and staff. For remote teams, that means clear policies, training, and monitoring that fits the size of the firm, such as alerts for unusual sign-ins or large downloads. Check in with remote staff regularly, not just when something breaks.
Travel
When attorneys travel, especially internationally, additional care is warranted.
- Carry only the data needed
- Use a clean loaner device for high-risk destinations if your IT provider supports it
- Avoid charging from public USB ports
- Report lost or stolen devices immediately so access can be revoked
Support matters
Remote attorneys who cannot get quick help will find workarounds. Make sure the help desk is easy to reach, remote tools allow technicians to assist, and device replacement is fast.
A checklist to adopt
- Managed, encrypted laptop with endpoint protection
- MFA and conditional access enforced
- No direct internet exposure of internal services
- Home router secured
- Written remote work policy acknowledged
- Lost-device reporting steps known
- Training completed in the past year
How we help
Counsel Cyber supports remote and hybrid law firm teams with device management, secure access, and policy templates. If your firm's remote work setup has grown informally, we can review it with you and recommend practical improvements.