Management matters: Enhance your solo or small firm’s cyber security in 2026
Vol. 81, No. 6 / November-December 2025

Jeffrey S. Krause is a senior consultant at Affinity Consulting Group LLC.
There is a common misperception that solo and small firm lawyers cannot afford the same level of tech security as larger firms. While it is true that firms with larger budgets can afford a larger security infrastructure, it does not necessarily mean their security is better than what a smaller firm can obtain.
More likely, a larger security infrastructure results from more employees, including those whose job it is to maintain security, and from being a more prominent target. Small firms can also implement robust security to protect their firms and clients. Smaller firms may have fewer weak spots to protect, but they need to know those weak spots and implement security to guard them. They might also find they already pay for the tools they need.
Here are some easy ways to greatly enhance your firm’s security going into 2026 while spending little-to-no money.
Duty
One thing is clear: All lawyers have a duty to protect their clients’ data. The Missouri Rules of Professional Conduct, Rule 4-1.6(c) states: “A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of the client.”
Unless you want to argue about reasonableness, Rule 4-1.6(c) does not provide an exception for solo and small firm lawyers, giving them leeway due to firm size or budget. The duty is the same — you must take reasonable steps to protect client information. In doing so, you are also taking reasonable steps to protect business and personal information.
Security weak spots
High-profile security breaches are often reported as if a genius hacker cracked an elaborate system designed to prevent unauthorized access. While this occasionally happens, most security breaches are much less interesting. Users are careless with already-weak passwords that they may use on multiple sites.
For example, an employee’s password to the firm’s Clio may be the same as their Netflix password, their Facebook login, and, most dangerously, that one sketchy website they visited four years ago. Affinity Consulting’s resource on password managers, located in the connect.MOBAR forms bank, can help you familiarize yourself with good password principles and password management programs.
Some organizations do not require strong passwords or an additional layer of security if a password is compromised. Devices may be lost without the data being properly secured. In other words, solo and small firm data security is about protecting data from our own mistakes.
Microsoft 365
The good news is that you likely have the tools to provide sophisticated security to your clients and their data. Microsoft 365 is nearly ubiquitous among solo and small firms and provides many of the features needed to protect data. Microsoft 365 Business Standard costs $12.50 per user per month and provides almost everything you need. You might also consider Microsoft 365 Business Premium, which has additional features related to security, at $22 per user per month.
Both the standard and premium plans include multi-factor authentication and an extensive list of security defaults. Both plans provide anti-spam, anti-malware, and anti-phishing features, and allow users to control access to SharePoint and OneDrive files. Correctly using these features provides a significant level of security.
The premium plan adds conditional access features, advanced anti-phishing, safe links and safe attachments, sensitivity labels, and data loss prevention services. You may decide the $9.50 per user per month is worth it to protect yourself from unforced errors. For example, the data loss prevention service notifies you when you attempt to share credit card numbers or content falling under HIPAA and may catch you from sharing that information in an insecure way. The service also provides a report of any information you shared. Proactive features like this help prevent errors, break bad sharing habits, and give you a list of information you have released “into the wild.”
Passwords and multi-factor authentication
An easy way to address security weak spots is to consider password strength. With any Microsoft 365 plan, you can set password policies. Interestingly, Microsoft’s guidance regarding passwords is different than what you may have heard previously. While it does caution against easy-to-guess passwords or passphrases, it does not state that longer is necessarily better, complex character requirements are necessary, or periodic resets serve a purpose. Instead, much of the guidance centers around multi-factor authentication.
Most of us are familiar with MFA. It requires the user to provide two or more verification factors to gain access. For example, when a user attempts to log in from a new device or location, they enter their login and password as normal. If this information is correct, a message is sent to their phone. The message contains a code that must be entered before the user can proceed.
Not only does Microsoft include MFA for Microsoft 365 components, MFA can also be configured to work with other applications via Azure AD (Active Directory). In addition to text message-based codes, many sites offer software-based codes, which can be stored and viewed in programs such as Microsoft Authenticator, Google Authenticator, or Twilio’s Authy.
With MFA, compromised passwords cannot be used to gain full access unless the bad actor also possesses and is able to successfully log in to the device to which the message is sent. This is where device encryption comes in.
Device encryption
Encrypting your computers, laptops, tablets, and phones is another critical step in protecting data. If you enter a code to access your tablet or phone, you are already using encryption. Entering the wrong code too many times can lock or even erase the device. Good luck getting the MFA code from a locked phone. This simple encryption protects against a lost or stolen phone being used to compromise your data.
For computers and laptops, a little more work is required. For Windows Pro devices, turn on BitLocker to encrypt the device hard drive. It does not stop someone with the credentials from accessing the computer. However, a thief would have to know how to access the stolen laptop. If they do not know the credentials, they may attempt to remove the hard drive and access data that way. They cannot do this without the BitLocker code. A similar encryption tool, FileVault, is available for Mac users.
Conclusion
No security is bulletproof, and a short article cannot cover every aspect of security. However, Microsoft 365 and Windows, which most solo and small firms already use, offer powerful security features. Implementing just a few of them can fortify the most common weak points in your firm’s security. Combined with strong passwords, your security fortifications will rival most firms, irrespective of size.
