Jump to section
A single reused password is often all that stands between a stranger and your entire client file. That is not a scare tactic, it is arithmetic. If your practice manager uses the same password for the firm's document system and a shopping site that got breached, the breach is now yours too. Multi-factor authentication (MFA) closes that gap, and rolling it out across a whole team is far less painful than most firms expect. Here is how to do it in a week without your inbox filling up with locked out staff.
Why a Strong Password Is No Longer Enough
Passwords fail in predictable ways. People reuse them, write them on sticky notes, and hand them over in convincing phishing emails without realizing it. Attackers do not sit at a keyboard guessing; they run stolen credentials against thousands of login pages automatically. A password that is only a password is a single point of failure.
MFA adds a second thing you must have, usually a code from your phone, on top of the thing you know. Even if a criminal has your password, they cannot get in without that second factor. For a law firm holding privileged material, that second layer is not a nice to have. It is a basic part of the duty to safeguard client information, and it pairs naturally with the other habits we cover in our legal tech and AI writing.
Note. MFA and two factor authentication mean the same thing in everyday use. Your staff will see both terms, along with 2FA, and they all point to the same second step.
Choosing App Codes Over Text Messages
When you switch on MFA, most services offer to text you a code. It works, and it is better than nothing, but it is the weakest option. Text messages can be intercepted, and a determined attacker can sometimes convince a phone carrier to move your number to their own SIM. That is a real risk for anyone whose name is on a firm letterhead.
Use an authenticator app instead. Apps like the ones from Microsoft, Google, or a standalone option generate a fresh six digit code every thirty seconds, right on the device, with no network needed. Pick one app and standardize on it firm wide so support stays simple.
| Method | Security | Best for |
|---|---|---|
| Authenticator app | Strong | Everyone, as the default |
| Hardware key | Strongest | Partners, admins, trust access |
| Text message | Weak | Last resort only |
For the handful of accounts that guard the most, your trust ledger, your domain administrator, your email provider, consider a physical security key. Those accounts justify the extra care, the same way your billing and trust processes get extra oversight.
Rolling It Out Account by Account
Do not try to switch on MFA everywhere at once. You will drown in confused calls. Work through your accounts in order of risk, and run each one as a small, contained wave.
- List every system the firm logs into: email, practice management, document storage, banking, court filing portals.
- Rank them by what an attacker could do with access. Email and your practice system sit near the top, because password resets flow through email.
- Enable MFA on your own account first and live with it for a day. You cannot support a process you have not felt.
- Roll out to one small team, gather the friction points, then widen.
Give people fifteen minutes and a printed one page guide with screenshots. Enrolment itself takes about two minutes per account, but the reassurance matters more than the clicks. A tool like A1 CMS can sit at the centre of this list, which makes it a sensible early candidate once your email is protected. If you are also tightening remote access, our going remote security checklist pairs well with this rollout.
Tip. Schedule enrolment during a quiet block, not a filing deadline. Ten calm minutes on a Tuesday morning beats a scramble the day a motion is due.
Handling Shared Logins and Departures
Shared logins are where MFA plans usually stall. If three people use one reception account, whose phone holds the code? The honest answer is that shared logins are a liability you should retire, not defend. Give each person their own account with the access they actually need. It costs a little more and it makes MFA trivial, because every login has one owner.
Where a shared account cannot be avoided in the short term, at least assign a single owner who holds the authenticator, and record that clearly. Staff turnover makes the case sharper still. When someone leaves, individual accounts let you disable one login cleanly. With a shared password, every departure means a scramble to change it before something goes wrong. Good offboarding and good MFA are the same discipline, and both belong in your operations routine.
Shared logins are not a convenience. They are a security liability that looks like one.
Recovering Access When a Phone Is Lost
The first real test of your rollout is the day someone loses their phone. Plan for it before it happens, or that person is locked out of everything at once.
When each account is enrolled, most services show a set of one time backup codes. Have every staff member save theirs somewhere safe and offline, not in a note on the same phone that generates the codes. A sealed envelope in a locked drawer is fine. Second, designate an administrator who can reset a user's MFA after verifying identity in person or by a known channel, never by an emailed request alone, since that is exactly how attackers slip in. Document the recovery steps once and keep them in your knowledge base so nobody has to improvise under pressure.
Warn. Treat backup codes like keys to the office. Anyone who has them can bypass MFA entirely, so store them with the same care you give a trust account cheque.
Making It Stick After Week One
The technology is the easy part. The partner who insists MFA slows them down is the harder problem, and you will not win with a lecture. Show the numbers instead: the extra step costs a few seconds a day, and it removes the single most common way firms get breached. Frame it as protecting clients, because that is a duty every lawyer already accepts.
Make the second factor stick by keeping it low friction. Most systems let a trusted device stay remembered for a set period, so people are not typing codes hourly. Set that window sensibly, review who has access each quarter, and add MFA enrolment to your onboarding checklist so new hires are covered from day one. If you want the wider security story around all of this, our companion piece on spotting phishing at a firm is a natural next read, and the A1 team keeps adding to the set.
Start this week. Turn MFA on for your own email today, walk one colleague through it tomorrow, and build from there. In a month it will be routine, and your clients will be safer for a change that took less effort than a single contested motion.