Of all the security measures available to a law firm, few do as much for as little effort as multi-factor authentication. It's inexpensive, quick to set up, and stops the large majority of account compromise attempts cold. It's also one of the most commonly skipped protections we see - usually not out of any real objection to it, just because it was never made a priority.
What It Actually Does
A password alone proves one thing: that someone typed in the right string of characters. It doesn't prove that person is actually who they claim to be, which matters because passwords get guessed, reused across sites, or exposed in breaches that have nothing to do with the firm itself. Multi-factor authentication adds a second proof - a code sent to a phone, an approval tapped in an app - so a stolen or guessed password alone isn't enough to get into an account.
Why This Matters More for a Law Firm
A compromised email account at a law firm isn't just an inconvenience. It can expose privileged client communications, give an attacker a foothold to intercept wire transfer instructions, or let someone impersonate an attorney in correspondence with a client or opposing counsel. The accounts most worth protecting with multi-factor authentication are exactly the ones a firm already treats as sensitive: email, case management systems, and anything touching client funds.
Why Firms Still Skip It
- An assumption that a strong password is already enough protection
- Concern that it will slow staff down or create friction during busy periods
- Simply never having gotten around to turning it on across every account that matters
In practice, the friction is minor - usually a few seconds per login - and it's a small cost measured against what a single compromised account can expose.
Where to Start
Email and case management systems are the highest-value accounts to secure first, since they're the ones most likely to hold privileged information or provide a path to client funds. From there, extending the same protection to every other system that touches firm or client data is a matter of working through the list methodically rather than leaving it to chance.
Frequently Asked Questions
Will multi-factor authentication slow down how staff log in every day?
There's a small amount of added time - typically a few seconds - but most staff adjust to it quickly, and the protection it adds is disproportionate to that minor inconvenience.
Which accounts should get this protection first?
Email and case management systems are the highest priority, since they're most likely to hold privileged client information or provide a path to firm or client funds.
Isn't a strong, unique password enough on its own?
A strong password helps, but it doesn't protect against a password that's exposed in a breach unrelated to the firm, or guessed through other means. Multi-factor authentication protects the account even when the password itself is compromised.
Can this be turned on without disrupting how our firm currently works?
In most cases, yes. It's typically a configuration change rather than a system overhaul, and it can be rolled out system by system rather than all at once.
Next Step
If you'd like a plain, specific look at how your firm's current setup actually stacks up, we offer a 15-minute call to see if we're a fit. No pitch, no obligation.
Managing partners and office administrators can reach us at 325-643-8184 or through the contact form at apollocomputers.com.


