ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Security Keys, Number Matching and SMS: Ranking MFA for Law Firms

Not all MFA is equal. Compare text codes, authenticator apps, number matching and security keys, and learn how to roll out stronger MFA across your law firm.

3 min readBy Counsel Cyber Team

Multi-factor authentication is among the most effective single steps a firm can take against account takeover, and nearly every cyber-insurance application asks about it. But the word covers a range of methods with very different strengths. Attackers have adapted, and some common forms of MFA can now be bypassed. Knowing the differences helps a firm choose well, and avoid a false sense of security.

The basic idea

MFA requires more than a password: something you know plus something you have, or something you are. If a password is stolen in a phishing email or a data breach elsewhere, the attacker still needs the second factor.

The methods, from weaker to stronger

SMS text codes

A six-digit code sent by text message is better than nothing, but it is the weakest common option. Criminals can sometimes hijack a phone number by tricking a carrier into transferring it, a tactic known as SIM swapping, and codes can be intercepted or phished. CISA has encouraged organizations to move away from SMS and voice-based MFA where stronger options exist.

Email codes

Sending a code to an email address is only as secure as that mailbox. It makes little sense if the account being protected is the email itself.

Authenticator app codes

Apps that generate a rotating code on a phone are stronger than SMS because they do not travel over the phone network. They remain vulnerable to phishing, where a user enters both the password and the code on a fake site that relays them to the real one in real time.

Push notifications

An approval prompt is convenient. Its weakness is fatigue: attackers with a stolen password can send repeated prompts until a tired user taps approve. Settings such as number matching, where the user must enter a number shown on the login screen, and showing the application and location in the prompt, reduce this risk significantly.

Phishing-resistant methods

The strongest options bind the login to the real website so that a fake page cannot capture a usable response. These include:

  • FIDO2 security keys, small hardware devices that you insert or tap
  • Passkeys, built on the same standards and stored on a device or in a password manager
  • Certificate-based authentication in some enterprise settings

CISA describes FIDO-based authentication as phishing-resistant and recommends it for high-value accounts such as administrators.

Where to apply the strongest protection

Not every account needs a hardware key, but some do.

  1. Administrator accounts for Microsoft 365, backup, firewall and remote management tools
  2. Partners and finance staff who authorize payments
  3. Email accounts generally, since email is the key to password resets everywhere
  4. Remote access and VPN
  5. Practice-management, document management and billing platforms
  6. Banking and trust-account portals

Rollout plan

  1. Inventory systems that support MFA and note those that do not.
  2. Pick a standard method for everyone, such as an authenticator app with number matching, and a stronger method for privileged users.
  3. Disable legacy authentication protocols that bypass MFA, which is commonly a gap in email systems.
  4. Plan recovery. Decide how a user who loses a phone proves their identity. Weak recovery processes become the attacker's route, so do not let a help desk reset MFA on the strength of a phone call alone.
  5. Register backup methods, such as a second key kept securely.
  6. Train staff to deny unexpected prompts and report them immediately.
  7. Use conditional access to require stronger checks for unfamiliar locations or devices.
  8. Review exceptions and close them over time.

Common mistakes

  • Enforcing MFA for some users but not all
  • Exempting partners because it is inconvenient
  • Leaving service accounts and shared mailboxes without protection
  • Allowing unlimited approval prompts
  • Skipping MFA on the backup console
  • Treating MFA as a replacement for other controls

The ethics link

Model Rule 1.6(c) calls for reasonable efforts to prevent unauthorized access to client information, and ABA Formal Opinion 477R discusses risk-based security measures, including multi-factor authentication as one option lawyers may consider. Confirm with your state bar how this applies in your jurisdiction.

Convenience matters

People bypass what annoys them. Single sign-on, trusted-device policies and passkeys can make secure logins faster than typing passwords all day. Choose the approach your people will actually use.

Counsel Cyber helps law firms deploy and enforce MFA across Microsoft 365 and practice-management tools, including hardware keys for administrators and partners. If you would like to know where your gaps are, we can start with a quick coverage report.