A Security Checklist for Taking Your Firm Remote

A practical, plain-language checklist for keeping a distributed firm secure, covering devices, home routers, public Wi-Fi, account hygiene, and the day someone leaves.

A lawyer working on a laptop at a home desk with client files nearby
Photo: Pawel Kadysz / Stocksnap (CC0)
Jump to section
  1. Secure the Devices Before They Leave the Office
  2. Home Networks and Public Wi-Fi Rules
  3. Separating Work and Personal Accounts
  4. Physical Security You Forget About
  5. What to Do the Day Someone Leaves

A laptop full of client files walks out the office door every evening now. It rides transit, sits on kitchen tables, and gets opened in coffee shops with the screen angled toward a stranger. Going remote is not a policy decision anymore, it is just how firms work. The security question is whether you set up controls deliberately or never got around to it.

The good news: most remote security is habit and setup, not expensive software. Below is a checklist you can actually run through with your team in an afternoon. Work top to bottom, tick each item, and you will close the gaps that cause the vast majority of small-firm incidents.

Secure the Devices Before They Leave the Office

A device is the front door to everything a lawyer touches. If it leaves the building unlocked, so does the firm. Handle this first, because retrofitting security onto machines already scattered across the city is much harder.

  • Full-disk encryption on every device. Turn on BitLocker (Windows) or FileVault (Mac). A stolen laptop without encryption gives anyone who finds it full access to every file on it.
  • Automatic lock after a few minutes idle. Set it firm-wide. People forget; the timer does not.
  • Managed updates. Operating system and browser updates should install on a schedule, not when someone finally gets around to it.
  • Reputable endpoint protection. Built-in tools are fine for many firms. The point is that something is watching, and someone checks the alerts.
  • An inventory. You cannot secure what you have not written down. Keep a simple list of who holds what.

Tip. If you can, keep client work on firm-owned devices only. Personal laptops shared with a spouse or a teenager are a different risk category, and a much harder one to defend if a complaint ever reaches your law society.

Multi-factor authentication belongs in this layer too, and it deserves its own attention. We wrote a fuller walkthrough on turning on MFA across a firm that pairs well with this list.

Home Networks and Public Wi-Fi Rules

The office network was somebody's job. The home network is nobody's, which is exactly the problem. Most home routers ship with defaults that were fine in 2015 and are a liability now.

  1. Change the router's admin password. The sticker password is public knowledge.
  2. Use WPA2 or WPA3 for the Wi-Fi itself, never open or WEP.
  3. Update the router firmware, or replace a router the manufacturer stopped supporting.
  4. Put smart-home gadgets on a separate guest network, away from work devices.

Public Wi-Fi is a shorter conversation: treat it as untrusted. The network in the coffee shop is not yours, and you do not know who else is on it. A firm-provided VPN encrypts your traffic over that connection. If you do not have one, a phone hotspot is usually the safer option.

Separating Work and Personal Accounts

The messiest breaches are rarely dramatic. They are a paralegal reusing one password everywhere, or client documents saved to a personal cloud folder that syncs to a home iPad the kids also use. Keep the lines clean.

  • A password manager for everyone. Unique, strong passwords stop being a fantasy the moment nobody has to remember them.
  • Work accounts for work. No client files in personal Gmail, personal Dropbox, or personal messaging apps. This is also a confidentiality obligation, not just a preference. Our note on confidentiality and cloud tools gets into the ethics side.
  • Least privilege. Not everyone needs access to everything. Give people what their role requires and no more.
  • One source of truth. When matters, documents, and communication live in a single system such as A1 CMS rather than scattered across a dozen personal apps, you can actually see and control where client data sits.

If your files today live in fifteen places, a deliberate document management approach is worth an afternoon of planning before you go further remote.

Physical Security You Forget About

Digital controls get all the attention, and then someone reads a privileged affidavit over a stranger's shoulder on the train. Physical security is easy to overlook and it still matters.

Watch out. A locked screen protects nothing if a client's name and file number are printed on paper left on the passenger seat. Remote work multiplies the number of places paper and screens end up.

SituationThe habit
Coffee shop or co-working spaceBack to the wall, privacy screen on the laptop, lock it even for a bathroom break
Home officeA door that closes, and files that are not visible on video calls
TravelDevices never in checked luggage, never left in a car
PrintingShred at home, or better, do not print privileged material at all

What to Do the Day Someone Leaves

Offboarding is where remote firms leak the worst, because there is no security desk to hand a badge back to. A departing articling student or contractor can keep quiet access for months if nobody has a checklist. Write one now, before you need it.

  • Disable accounts and revoke logins the same day, not at the end of the week.
  • Reset any shared passwords the person knew.
  • Recover firm devices, and remotely wipe them if they do not come back.
  • Transfer ownership of their files and matters before the account goes dark.
  • Remove them from every third-party tool, not just email.

This is also when a solid backup and recovery plan proves its worth. If someone deletes or takes something on the way out, backups determine whether you lose data or just lose a few hours recovering it.

None of this is exotic. Encryption, unique passwords, a clean line between work and personal, a screen that locks, and a same-day offboarding routine will carry a small firm most of the way. Run the list once with your team, fix what is broken today, and put a reminder in the calendar to run it again in six months. Security is not a project you finish, it is a habit you keep, and remote work only raises the stakes on getting the habit right. For the wider picture, our legal tech and AI writing and the pieces from the A1 CMS team are a good next stop.

The A1 CMS Team

Editorial desk

Notes, guides, and product thinking from the people building A1 CMS.

Run your firm on one calm platform

Matters, billing, trust accounting, client portal, and automation, together in A1 CMS. Try it free, no card required.