ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Securing Remote and Hybrid Work at a Law Firm: A Practical Guide

Remote work is permanent at many firms. Secure home networks, devices, video calls and client data with this practical checklist drawn from ABA Opinion 498.

3 min readBy Counsel Cyber Team

Remote and hybrid work arrangements are now an ordinary part of law practice. Attorneys draft at home, take client calls from kitchens, and review documents on trains. ABA Formal Opinion 498, issued in 2021, addresses virtual practice and discusses competence, confidentiality, communication and supervision in that setting. Its message, in brief, is that reasonable steps are needed to protect client information wherever the work happens.

This post turns that principle into a practical checklist for firms.

Start With Managed Devices

The single biggest improvement is to ensure firm work happens on firm-managed devices.

  • Full-disk encryption on every laptop, so a lost device does not expose data
  • Endpoint protection with monitoring
  • Automatic updates for the operating system and applications
  • Screen lock after a short idle time
  • Remote wipe capability for lost or stolen devices
  • Limited admin rights, so malware cannot easily install

If personal devices must be used, enroll them in mobile device or application management so firm data is protected and can be removed, and require the same baseline security.

Control How People Connect

Prefer cloud tools with strong sign-in

Cloud applications protected by MFA and conditional access often reduce reliance on traditional VPNs. Where VPN or remote desktop is used, require MFA and never expose remote desktop directly to the internet.

Use conditional access

Policies can require compliant devices, block sign-ins from unexpected countries and demand extra verification for risky sign-ins.

Avoid public Wi-Fi without protection

Coffee shops and airports are riskier networks. Encourage a firm VPN or a phone hotspot, and rely on encrypted connections.

Secure the Home

Firms cannot manage every home, but they can set expectations:

  1. Change the default router password and use a strong Wi-Fi passphrase
  2. Keep router firmware updated
  3. Separate work devices from smart home gadgets where possible
  4. Use a private workspace, if possible, for confidential calls
  5. Keep family members off work devices
  6. Lock the screen when stepping away

Protect Conversations and Documents

  • Video calls: use waiting rooms or passcodes, check who is on the call, and be aware of what is visible in the background
  • Voice assistants and smart speakers: consider moving them out of earshot of client calls
  • Printing: avoid printing confidential documents at home, or shred what is printed
  • Paper files: store securely and return them to the office when finished
  • Messaging apps: use firm-approved tools, not personal texting, for client matters
  • File storage: save work in the document management system, not on local desktops or personal cloud accounts

Supervision From a Distance

Rules 5.1 and 5.3 still apply when the team is spread out. Consider:

  • Regular check-ins and clear escalation paths
  • Training on security expectations for remote work
  • A short written remote work policy that people acknowledge
  • Spot checks of device compliance reports

Travel

  • Use a privacy screen on planes and trains
  • Never leave a laptop or phone unattended or in a parked car
  • Carry only the data you need
  • Use a loaner device for high-risk destinations if your firm has them
  • Report a lost device immediately so it can be locked

Policy Basics

A one-page remote work policy should cover approved devices, approved applications, network use, physical safeguards, incident reporting and handling of paper. Pair it with training so it is understood.

Test Your Setup

Ask your IT provider for a report showing which devices are encrypted, patched and protected, and for any that are not. Review it monthly. Missing devices are usually the unmanaged ones.

Quick Wins This Month

If the full list feels large, start with three steps: confirm every laptop is encrypted, turn on conditional access for firm accounts, and send staff a one-page remote work reminder. Those three cover a large share of everyday remote-work risk and can be done in a few weeks.

Support

Counsel Cyber helps firms secure remote and hybrid work with device management, conditional access and training tailored to attorneys. If you would like to know where your remote setup stands, we can review it with you.