blog

The Law Office Has Left the Building. Your Security Needs to Keep Up

Written by Nick Stevens | Aug 6, 2026, 7:00:00 PM

The office has left the building. Here's what securing a distributed law firm actually requires and where most firms fall short without realizing it. 

TL;DR: Remote and hybrid work is permanent in legal, and the security obligations that govern client data didn't stay behind when attorneys left the office. Most firms secured the building. Far fewer secured the environment their attorneys actually work in, which now includes home networks, personal devices, coffee shop Wi-Fi, and whatever collaboration tools someone downloaded because the approved options were too slow. The gaps that open up in that environment are where most remote-related incidents start. Closing them isn't complicated, but it does require treating off-site work as a first-class security problem rather than an edge case.

Think about the moment a teenager gets their driver's license. You spent years building safety into the home: rules, routines, known quantities. Then they take the keys and drive somewhere you've never been, on roads you can't see, and you realize pretty quickly that all that work you did inside the house doesn't follow them out the door. What follows them out the door is the car. So you make sure the car has every safety feature available, because that's the thing you can actually control once they leave.

Remote work in a law firm works the same way. The office got built out carefully: firewalls, access controls, monitored networks, vetted devices. Then the attorneys took the work home, to the courthouse steps, to the hotel room the night before a deposition, and the carefully built office environment stayed behind. What traveled with them was a laptop, a phone, and a home Wi-Fi network shared with two teenagers and a smart TV from 2019.

According to the ABA, 87 percent of law firms now allow attorneys to work remotely, and NALP's research found that 98 percent operate in some kind of hybrid model. Remote work isn't an accommodation anymore. It's just how legal work happens. The security infrastructure has to reflect that reality, not the one that existed before 2020.

The ABA's ethics rules never got the memo that work was supposed to stay in the office. Model Rules 1.1, 1.6, and 5.3 apply wherever the attorney is sitting. The obligation to protect client data doesn't have an out-of-office reply. Most firms have done the work inside the building. This post is about everything outside it.

Table of Contents

  1. What the ABA Actually Requires When Attorneys Work Remotely
  2. The Security Gaps That Open Up Off-Site
  3. The Devices and Networks Attorneys Actually Use
  4. The Offboarding Gap Nobody Notices Until It's Too Late
  5. What a Secure Remote Work Policy Actually Covers
  6. The Car Needs to Be Safe Before It Leaves the Driveway
  7. Key Takeaways
  8. Frequently Asked Questions

What the ABA Actually Requires When Attorneys Work Remotely

The short version of ABA Formal Opinion 498 is this: the ethics rules didn't change when attorneys left the office. They just became harder to comply with.

Opinion 498, issued in March 2021, defines virtual practice as "technologically enabled law practice beyond the traditional brick-and-mortar law firm" and makes clear that the duties of competence, diligence, confidentiality, and supervision apply exactly the same way whether an attorney is in a conference room or a kitchen. Model Rule 1.1 requires lawyers to stay current on the benefits and risks of the technology they use. Model Rule 1.6 requires reasonable efforts to prevent unauthorized disclosure of client information. Model Rule 5.3 requires supervising attorneys to ensure that subordinate lawyers and nonlawyer staff comply with those same obligations, regardless of where they're working.

That last one tends to get overlooked. A partner who allows a paralegal to work from home on a personal device without any firm-managed security controls has a supervision problem, not just an IT problem. The ABA is explicit on this: firms that allow subordinates to use personal devices for work need policies that include remote-wiping capabilities, protections against access by family members, and archiving of client-related data. That's not optional guidance. It's the baseline.

For West Coast firms with clients in California, Oregon, and Washington, the regulatory layer goes further. The FTC Safeguards Rule, which requires financial institutions to maintain written information security programs with MFA, encryption, access controls, and incident response plans, can apply to law firms engaged in activities that are financial in nature. The California Consumer Privacy Act, Oregon's Consumer Privacy Act, and Washington's My Health MY Data Act each impose additional requirements for firms handling personal data of residents of those states. The ethics obligations are the floor, not the ceiling.

The Security Gaps That Open Up Off-Site

Remote work didn't invent new security vulnerabilities. It moved existing ones out of the controlled environment where most firms had built their defenses and into environments where those defenses don't reach.

The numbers on how that's playing out are pretty clear. According to Bitdefender, 61 percent of IT security leaders attribute recent breaches directly to remote workers. Seventy-eight percent of organizations reported at least one security incident linked to remote work in 2025. And breaches involving remote workers cost an average of $1.07 million more than those involving on-site employees, largely because detection takes longer and the blast radius is harder to contain when you can't see the environment the incident started in.

For law firms, the exposure is specific. The greatest threats in remote legal work fall into a few predictable categories: attorneys connecting to firm systems over networks nobody vetted, work happening on personal devices that never went through security review, collaboration tools adopted because the approved ones were too slow, and former employees whose access was never revoked because the physical cues that trigger offboarding aren't there when someone works remotely.

None of these are exotic attack scenarios. They're the everyday operational reality of a distributed workforce, and they show up in breach reports with remarkable consistency. The next three sections break each one down.

The Devices and Networks Attorneys Actually Use

Here's the honest version of what remote legal work looks like in practice. An attorney is reviewing a settlement agreement at 9 p.m. on a personal laptop, connected to a home Wi-Fi network shared with two kids, a gaming console, and a smart TV that last saw a firmware update during a previous administration. The document is open, the data is real, and none of the security controls the firm built around the office are present in that room.

The device problem is specific. Personal laptops and phones don't go through an IT security review. They don't have firm-managed endpoint protection. They run whatever software the owner installed, updated on whatever schedule the owner got around to. Thirty-six percent of employees using personal devices for work admit to delaying security updates, and 48 percent of organizations suffered data breaches linked to unmanaged personal devices in the past year. For a law firm, where the data on those devices is privileged and regulated, the exposure is direct.

ABA Formal Opinion 498 is explicit about what's required when attorneys use personal devices for work: remote-wiping capabilities in case a device is lost or stolen, protections against access by family members or others in the household, and archiving of client-related data for later retrieval. Those aren't suggestions. They're the baseline the ABA expects firms to have in place.

The network problem compounds the device problem. Home networks aren't configured to enterprise security standards. Most run on routers with default credentials nobody changed, shared with devices the firm has no visibility into. Twenty-nine percent of all ransomware attacks in 2025 originated from home office environments. The attorney's laptop may be the entry point, but it's the network it's sitting on that makes the attack possible. A firm-managed VPN or zero-trust access solution addresses the transit problem. It doesn't fix the underlying network, but it closes the gap that matters most.

The Offboarding Gap Nobody Notices Until It's Too Late

Remote work makes a lot of things easier. Offboarding isn't one of them.

When someone leaves a firm where everyone works in the same office, the physical departure creates natural cues: return the badge, hand back the laptop, clear the desk. Those cues prompt the access revocation that needs to happen. When someone works remotely, those cues aren't there. The departure happens over email or a video call, the laptop gets shipped back eventually, and the access revocation happens whenever someone gets around to it, which is often later than it should be and sometimes not at all.

According to Intermedia's research, 89 percent of former employees can still access at least one corporate application after leaving. Twenty percent of organizations have experienced a data breach traced to an ex-employee. For a law firm, a former associate or paralegal with lingering access to client files, email, or practice management platforms isn't just a technology problem. It's a confidentiality problem with ethics implications.

The fix is a documented offboarding protocol that treats access revocation as incident-class work rather than a checklist item someone gets to when they have time. Identity revocation first, on the last day or before it. Application access second, covering every platform the departing employee used, not just the obvious ones. Device management third, including the removal of firm data from any personal device that was used for work. Done consistently, with documentation, this gap closes. Left to informal processes and institutional memory, it stays open indefinitely.

What a Secure Remote Work Policy Actually Covers

Most law firms have something that gets called a remote work policy. Most of those documents address where attorneys can work and what hours they're expected to be reachable. Very few address the technology in the kind of specific detail that actually closes the gaps the previous sections described.

A remote work policy that satisfies ABA Opinion 498 and holds up under scrutiny covers a few specific things. Which devices are approved for firm work, and what minimum security configuration is required. How attorneys connect to firm systems remotely, whether that's a firm-managed VPN, zero-trust access, or something else. Which collaboration and file-sharing tools are sanctioned for client work, and which aren't. What happens to firm data on a personal device when someone leaves. And how incidents get reported when something looks wrong.

That last one is worth emphasizing. A firm where attorneys don't know who to call when they receive a suspicious email, or aren't sure whether something qualifies as a security incident, has a gap that no technical control closes. The policy is also what gets produced when a bar inquiry, a cyber insurance renewal, or a client due diligence request asks for evidence of the firm's security practices. Verbal assurances don't hold up the way a documented, current policy does.

For a broader look at what strong IT support for a law firm actually requires across the full environment, Your Law Firm's IT Partner Is Either an Asset or a Liability. Which One Do You Have? covers the complete picture.

The Car Needs to Be Safe Before It Leaves the Driveway

Remote and hybrid work didn't create new ethical obligations for law firms. It just moved the work into environments where the security infrastructure most firms built wasn't designed to follow. The attorneys took the keys and drove somewhere new, and a lot of firms are still securing the garage.

The good news is that the gaps are well understood and consistently fixable. Firm-managed devices or documented BYOD policies, VPN or zero-trust access, a remote work policy that covers the specifics rather than the generalities, and an offboarding protocol that treats access revocation as a defined process rather than a checklist item. None of that is exotic. All of it matters more the more distributed the practice becomes.

Heroic Technologies works with law firms and professional services organizations across Oregon, Washington, and California. They've spent 14-plus years building security programs for firms that hold sensitive, privileged, and regulated data, which means remote work security isn't a new conversation for them. It's one they've been having with clients since before most firms realized it was a conversation worth having.

When it comes to securing a distributed legal workforce specifically, that means auditing the current environment to find where the gaps actually are, building the policy and technical framework that closes them, and making sure the documentation holds up when someone asks for proof. The car can be safe before it leaves the driveway. Get in touch with Heroic Technologies and let's make sure yours is.

Key Takeaways

  • Remote and hybrid work is permanent in legal. According to the ABA, 87 percent of law firms now allow attorneys to work remotely, and NALP found that 98 percent operate in some kind of hybrid model. The security infrastructure has to reflect that reality.
  • ABA Formal Opinion 498 makes clear that the duties of competence, confidentiality, and supervision apply wherever the attorney is sitting. The ethics obligations don't have an out-of-office reply.
  • Sixty-one percent of IT security leaders attribute recent breaches to remote workers, and breaches involving remote workers cost an average of $1.07 million more than those involving on-site employees. The exposure is real and measurable.
  • Personal devices and home networks are where most remote-related incidents start. Forty-eight percent of organizations suffered breaches linked to unmanaged personal devices last year, and 29 percent of all ransomware attacks in 2025 originated from home office environments.
  • The baseline for secure remote legal work includes firm-managed or firm-approved devices with endpoint protection, a VPN or zero-trust connection, MFA on every account, vetted collaboration tools, and a documented offboarding protocol. None of it is exotic. All of it is skipped more often than it should be.
  • A remote work policy that closes these gaps covers approved devices, connection requirements, sanctioned tools, offboarding procedures, and incident reporting. Verbal assurances don't hold up the way documented policies do.

Frequently Asked Questions

1. Does ABA Formal Opinion 498 require law firms to have a written remote work policy?
Opinion 498 doesn't mandate a specific document by name, but it requires firms to adopt and tailor policies and practices that ensure ethical conduct by attorneys and staff working remotely. In practice, that means a written policy covering approved technology, confidentiality obligations, supervision procedures, and incident reporting. Without one, demonstrating reasonable efforts under Model Rules 1.1, 1.6, and 5.3 becomes very difficult if a bar inquiry or breach investigation ever asks for proof.

2. Can attorneys use personal devices for client work, and if so, what does the firm need to have in place?
Yes, with the right controls. ABA Formal Opinion 498 specifically addresses personal device use and requires firms to have remote-wiping capabilities in case a device is lost or stolen, protections against access by household members, and archiving of client-related data. A documented BYOD policy, mobile device management enrollment, and endpoint security on any personal device used for firm work are the practical requirements that satisfy those obligations.

3. What's the single most important thing a law firm can do to improve remote work security right now?
Audit what's actually happening. Most firms have a gap between their official remote work policy and how attorneys actually work day to day. A structured assessment of which devices are being used, how attorneys are connecting to firm systems, which tools are being used for client communication, and whether former employee access has been fully revoked will surface the specific gaps worth addressing. Everything else follows from knowing where you actually stand.