Most security incidents at law firms begin with an ordinary person doing something ordinary: clicking a link, reusing a password, or approving a prompt on a phone. Technology controls matter, but daily habits decide whether those controls hold. Here are ten habits worth building into your firm's culture, along with a short explanation of why each one matters.
1. Use a password manager
Reusing passwords is one of the most common ways accounts get taken over. When one website is breached, attackers try the same email and password everywhere else. A password manager lets every person have a long, unique password for each system without memorizing them.
2. Turn on multi-factor authentication everywhere it is offered
MFA adds a second proof of identity beyond a password. Prioritize email, practice-management software, document management, remote access and banking. Where possible, prefer an authenticator app or hardware key over text messages.
3. Never approve a prompt you did not trigger
Attackers sometimes steal a password and then spam the user with approval requests until one is accepted out of annoyance. If you receive an unexpected MFA prompt, deny it and report it right away, because it likely means your password is compromised.
4. Pause before clicking or opening
Phishing messages create urgency: a signature request, an invoice, a message from a judge's office, a shared document. Slow down. Check the sender's actual address, hover over links, and be cautious about unexpected attachments. If in doubt, contact the sender through a separate channel.
5. Verify payment instructions by phone
The FBI's Internet Crime Complaint Center has repeatedly warned about business email compromise, in which criminals impersonate a trusted party and redirect funds. Any request to change wire instructions, or any unusual payment request, should be confirmed by calling a number you already have on file, never one in the email.
6. Report mistakes immediately
Everyone clicks the wrong thing eventually. What changes the outcome is how quickly the person says so. A firm that treats reports as helpful, not shameful, gets earlier warnings. Make sure everyone knows exactly whom to call or email.
7. Keep client data in approved places
Avoid saving matter files on personal drives, sending them to personal email, or using unapproved file-sharing sites. Approved systems are backed up, monitored and access-controlled. Shadow systems are not.
8. Lock your screen and secure your devices
Lock the computer when you step away, use screen locks on phones and tablets, and keep devices updated. Lost or stolen laptops should be reported at once so they can be wiped remotely. Full-disk encryption helps protect data on a lost device.
9. Be careful in public and at home
ABA Formal Opinion 498 on virtual practice points to considerations such as securing home networks and keeping conversations confidential. Avoid working on client matters over public Wi-Fi without a VPN, change the default password on your home router, and keep family members off work devices.
10. Think before using AI tools
Generative AI can be useful, but pasting client information into a consumer tool may expose it. Use only the tools your firm has approved, and follow the firm's rules about what can be entered. ABA Formal Opinion 512 discusses the confidentiality and supervision issues involved.
Making the habits stick
Habits fade without reinforcement. A few practices help.
- Hold short, regular training sessions of fifteen minutes or so rather than one annual meeting.
- Run phishing simulations and use the results to teach, not punish.
- Have partners model the behavior. If leadership skips MFA, staff will too.
- Include security in onboarding and offboarding so new hires start with good habits and departing employees lose access immediately.
- Make the secure way the easy way, with single sign-on and a managed password vault.
Why this matters for the firm
Model Rule 1.6(c) calls for reasonable efforts to prevent unauthorized access to client information, and Rule 5.3 addresses supervising nonlawyer staff. Daily habits are some of the most visible evidence that a firm takes those duties seriously, though you should confirm specific obligations with your state bar.
Counsel Cyber provides security awareness training built for law firm staff, including short sessions and phishing simulations. If you would like help turning these ten habits into a routine, we are glad to talk.