Vendors have attached the phrase "zero trust" to everything from firewalls to laptops, which has made it hard to know what it actually means. Stripped of marketing, it is a simple idea: do not automatically trust a user or device just because it is inside your network or has signed in once. Verify, give the least access needed, and assume something may already be compromised.
NIST has published guidance on zero trust architecture, and CISA has a zero trust maturity model written for government agencies, but the ideas scale down well to a twelve-attorney firm. You do not need to buy a product called zero trust. You need to change a handful of defaults.
Why the old model fails
The traditional office was a castle. Everyone inside the firewall was trusted, and the firewall kept outsiders out. Today attorneys work from home, courthouses, and airports. Documents live in cloud services. The castle wall has little left to protect, and anyone who steals a password walks in as a trusted insider.
Five practical steps
1. Verify identity every time it matters
Require multifactor authentication for email, document management, practice management, and remote access. Use conditional access to raise the bar when something looks unusual, such as a sign-in from a new country or an unmanaged device.
2. Verify the device, not just the person
Allow access to firm data only from devices that meet a baseline: disk encryption on, operating system updated, endpoint protection running. Personal devices can be allowed with limits, for example browser-only access with no downloading of files.
3. Give the least access that works
Not every person needs every matter folder. Review permissions on file shares and document management systems.
- Restrict sensitive matters to the team working them.
- Separate administrator accounts from everyday accounts. Nobody should read email from an account that can also change firm settings.
- Remove access when people change roles or leave, on the day it happens.
4. Segment the network
Put guest Wi-Fi on a separate network from staff devices. Isolate printers, cameras, and other devices that cannot be patched well. If an attacker lands on one machine, segmentation limits how far they can travel.
5. Watch and log
Zero trust assumes failure will happen, so you need to see it. Keep logs of sign-ins and file access, and have someone, whether staff or a managed detection service, review alerts and respond.
What zero trust is not
- It is not a single product you buy once.
- It does not mean distrusting your employees. It means not letting one stolen password open every door.
- It does not require replacing everything you own.
- It does not eliminate the need for training, backups, or incident response planning.
Making it livable for attorneys
Security that frustrates lawyers gets bypassed. A few design choices help:
- Use single sign-on so people authenticate once per session and not for every app.
- Choose phone-based approvals or hardware keys that take seconds.
- Make the rule exceptions explicit and time-limited instead of letting informal workarounds accumulate.
- Explain the why. A short story about a stolen password usually works better than a policy memo.
A hypothetical walk-through
Consider a hypothetical six-attorney firm. An assistant's laptop is infected after she opens a malicious attachment. In an old-style setup, the malware finds the shared drive mapped to every folder and encrypts it all. In a firm following these steps, her account has access only to her team's matters, the device is flagged by endpoint protection within minutes, and network segmentation keeps the malware away from the server holding backups. The incident is still unpleasant, but it is contained.
Where to begin
You do not have to do all five at once. Start with MFA and admin account separation, which are the cheapest and most effective, then move to device checks and permission clean-up over a few quarters.
Counsel Cyber helps law firms turn the zero trust idea into a short, prioritized roadmap that fits their size and budget. If you would like us to assess where your firm stands today, we are happy to start with a conversation.