Join our Newsletter — 33% off our NHI Course
Home FAQ Authentication, Authorisation & Trust How should law firms reduce phishing risk without…
Authentication, Authorisation & Trust

How should law firms reduce phishing risk without creating more login friction for attorneys?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 10, 2026 Domain: Authentication, Authorisation & Trust

Law firms should move from password-based MFA to phishing-resistant, passwordless authentication that uses device and biometric factors instead of reusable secrets. The goal is to remove the attack path that phishing and session hijacking exploit while keeping access fast enough for busy legal teams. A good rollout also preserves coverage across cloud, on-prem, and legacy applications.

Why Reducing Friction and Reducing Phishing Are the Same Problem

Law firms usually feel phishing as an access problem, but the business problem is broader: attorneys need fast, reliable access to client, matter, and court systems without giving attackers a reusable secret to steal. Password-based MFA still leaves room for phishing, push fatigue, token replay, and help-desk abuse. Phishing-resistant authentication changes the economics by making the login process harder to spoof while often making the user experience simpler.

This matters because legal workflows are high tempo and highly interrupt-driven. If controls slow attorneys down, they will work around them; if controls are too weak, a single compromised inbox or session can expose privileged client data, engagement records, or signing authority. NHI Management Group’s guidance on machine and credential governance reinforces the larger lesson that durable access paths must be both governable and low-friction, not one or the other. In practice, many firms discover that the most effective anti-phishing control is also the least annoying one once it is deployed consistently.

The practical shift is from reusable secrets to authentication methods that bind the login to a legitimate device and, where appropriate, a local user gesture such as biometrics or a security key touch. That removes the main value of a phishing page: there is no password for an attacker to reuse, and no one-time code to intercept and replay. For firms, the design goal is not “more security steps,” but fewer high-risk steps that can be copied outside the trust boundary.

In a law-firm environment, that usually means different treatment for different access paths. Cloud apps and modern SaaS should move first, because they can often support phishing-resistant methods with minimal user disruption. Legacy systems may need federated access, brokered sign-in, or compensating controls until they can be modernised. Attorneys who move across offices, courts, and client sites also need conditional access that does not create constant prompts when risk is low, but tightens when the device, location, or session looks unusual.

  • Use passwordless or phishing-resistant sign-in for high-value systems first, especially email, document management, e-billing, and matter platforms.
  • Prefer device-bound authentication over SMS codes or reusable OTPs, because those can still be phished or relayed.
  • Maintain a break-glass path for outages, but keep it rare, monitored, and time-limited.
  • Preserve coverage for legacy applications through federation, proxies, or step-up controls rather than leaving them on weaker login paths.

NIST Cybersecurity Framework 2.0 is useful here because it frames identity as a control outcome tied to access, protection, and recovery rather than as a single product decision. For a deeper NHI-specific view of why reusable secrets keep failing, NHI Management Group’s Ultimate Guide to NHIs — Key Challenges and Risks shows how long-lived credentials widen exposure over time.

These controls tend to break down when firms leave a parallel password path in place for “special cases,” because attackers naturally target the weakest remaining login route.

Where Law Firms Usually Get the Balance Wrong

Tighter authentication often increases rollout overhead, so firms must balance attorney convenience against the operational cost of migration. The common mistake is to treat friction as the only thing that matters and to preserve weak sign-in methods for convenience. That keeps the user experience comfortable while leaving the firm exposed to session theft, inbox compromise, and downstream fraud.

The better compromise is selective hardening: make the highest-risk systems phishing-resistant first, then use policy-based exceptions only where there is no alternative. Current guidance suggests that firms should also test recovery and onboarding paths early, because passwordless programmes often fail not on normal daily use, but on device replacement, travel, privilege elevation, or emergency access. Where firms still rely on a small number of administrators or office staff to approve access workarounds, the real risk becomes process abuse rather than technical bypass. A short, predictable sign-in is valuable, but only if it does not reintroduce shared secrets through the back door.

For practitioners, the key signal is whether attorneys can authenticate quickly without creating a parallel “legacy exception” population that is easier to phish than the rest of the firm. NHI Management Group’s Top 10 NHI Issues is a useful companion for understanding how poor credential governance tends to persist once exceptions become normalised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementPhishing-resistant sign-in reduces account compromise paths and weak authentication exposure.
Recommendation — Replace phishable sign-in methods with stronger authentication for high-value firm systems.
NIST CSF 2.0PR.AA-01 — Identity Management, Authentication, and Access ControlThe question centers on authentication strength without adding user friction.
PR.AA-03 — Remote Access and Session SecurityLaw firms need secure access across remote, mobile, and cloud work patterns.
PR.AA-04 — Access Permissions and AuthorizationReducing login friction must not expand standing access or weaken authorization boundaries.
Recommendation — Adopt phishing-resistant authentication for critical access paths and retire reusable secrets. Bind remote sessions to trusted devices and tighten step-up controls for higher-risk access. Limit privileged access and require stronger checks before sensitive actions are approved.

Practitioner Guidance

What to prioritise: Start with email, document management, and case or matter systems, because those are the entry points most likely to be used for phishing, impersonation, and downstream privilege abuse. If those paths become phishing-resistant, the firm materially reduces both compromise probability and the chance of silent session takeover.

Decision rule: If a login method can be copied, relayed, or reused outside the intended device or browser session, treat it as a transition method only. If the application can support a stronger method, do not keep the weaker one just because it is familiar.

What to verify: Confirm that recovery, mobile replacement, partner onboarding, and emergency access do not silently fall back to passwords or one-time codes. The control is only as strong as its weakest exception path.

Practitioner takeaway: The right balance is not “secure versus convenient”; it is “secure enough that attorneys will actually use it, and strong enough that a phished credential has no value.”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 10, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org