Jump to section
A small firm in a mid-size city loses its front-desk staffer on a Friday. The following Tuesday, someone logs into the firm inbox from an address nobody recognizes. The password had never changed. It was still taped to the underside of a drawer, and it still worked. That is not a hacking story. That is a housekeeping story, and housekeeping is something you can actually fix.
Most breaches at firms your size are not clever. They are the result of a login that outlived its usefulness, a shared password that spread further than anyone tracked, or a second factor nobody bothered to turn on. Below are twelve habits, grouped the way you would actually work through them. Treat this as a checklist you can run against your practice this week.
Give Every Person Their Own Login
Shared credentials feel efficient right up until you need to answer a hard question: who opened that file, who sent that email, who changed that trust ledger entry? A shared login cannot answer any of it.
- One human, one account. No "reception@" that four people log into with the same password. Give the front desk role its own named seats, or a shared mailbox that individuals access through their own credentials.
- Kill the generic admin account. The login called "admin" with a password three partners know is a liability. Name it after a person who is accountable for it.
- Turn on audit logs and actually glance at them. Individual logins only pay off if the system records who did what. Most practice tools keep an activity log. Check it after any staff change.
Note. Individual accounts are also a professional obligation in disguise. When you cannot say which person touched a client's confidential file, you cannot honestly answer a law society inquiry about it either.
Turn On Two Factor Everywhere Client Data Lives
A password is one layer of protection. A second factor adds another. If a login protects client information, it needs both.
- Enable two factor on email first. Your email account is the master key to almost everything, because most password resets flow through it. Start here, today.
- Cover the client portal and document storage. Anywhere a client's file can be read or downloaded, require a second factor. If your document and portal tools support it, there is no reason to leave it off.
- Prefer an authenticator app over text messages. Codes sent by text can be intercepted or redirected. A free authenticator app on each person's phone is stronger and just as fast.
A password confirms you know the secret. A second factor confirms you are the person who is supposed to know it.
Use a Firm Password Manager, Not Sticky Notes
Nobody can remember forty strong, distinct passwords. So they reuse one, or they write it down. A password manager removes the excuse.
- Adopt one manager for the whole firm. Pick a reputable tool with a business plan, roll it out to everyone, and make it the only sanctioned place a password lives.
- Share through the vault, never over email or chat. When two people genuinely need the same login, share it inside the manager so access can be revoked in one click, not chased across a dozen threads.
- Let it generate long, random passwords. Length beats cleverness. A random string you never memorize is far safer than a "strong" password you reuse on three sites.
Tip. Roll the manager out to one small team first, work out the friction, then expand. A messy firm-wide launch is how these projects die.
Kill Access the Day Someone Leaves
Departures are where offboarding steps get skipped. The person is gone, the work moves on, and their access stays active for months.
- Build an offboarding checklist and run it same-day. Disable email, revoke portal and storage access, remove them from the password manager, and reclaim any second-factor devices. Every departure, no exceptions, including contractors and summer students.
- Rotate anything they shared. If a departing person knew a shared login, that login is now compromised. Change it. This is the single habit that would have stopped the story at the top of this article.
Keep the checklist somewhere the office manager owns, and tie it to the same moment you collect keys and the building fob. If your security basics already cover physical offboarding, fold the digital steps into the same routine so neither gets skipped.
Protect the Accounts That Reset All Others
Some logins are the entry point to everything else. The account that administers your email domain, your practice software, or your DNS can unlock or lock out the whole firm. Treat these differently.
- Guard the master accounts hardest. Use your longest passwords, mandatory two factor, and a very short list of people who hold them. Store recovery codes offline in a sealed, dated envelope in the safe, and make sure a second partner can reach them if the first is unreachable.
| Account type | Minimum standard |
|---|---|
| Everyday staff login | Unique account, manager-generated password, two factor |
| Client portal and storage | Same, plus regular access review after staff changes |
| Master and admin accounts | Above, plus offline recovery codes and a two-person rule |
You do not need to do all twelve today. Pick the three that make you wince, because you already know which ones those are, and close them this week. Then book an hour next month for the rest. Strong authentication is not a product you buy once. It is a set of small habits your firm keeps, the same way you keep a clean trust ledger and a current conflict check. A tool like A1 CMS can hold the individual logins, the portal access, and the audit trail in one place, but the habits are yours to keep. The firm that runs this checklist twice a year is the one that never has to write the incident report.