Security · IT Support
Who Holds the Keys to Your Law Firm?
20 July 2026

Every matter file, every client email and every payment instruction in your firm sits behind a login.
Which means every login is a key — and attackers know it.
For most SME law firms, the honest question is not whether access is controlled. It is whether anyone could prove who can see what — and whether a single phished password would be enough to get inside. As firms centralise matter management, billing and communication on platforms like Clio, the value concentrated behind each set of credentials keeps growing.
This article relates to the Passwords & Access domain of the Technology Resilience Score. It looks at whether your firm controls who can access client data and client money — and whether you could evidence it.
Why identity is the front door to client money
Email compromise is the most common route into conveyancing and client-account fraud. The pattern is well established: a fee earner's password is phished, the attacker reads correspondence quietly, learns the rhythm of a transaction, and sends a convincing payment redirection at exactly the right moment.
None of that requires malware. It requires one password — and the absence of a second factor.
For a law firm, weak access control is not an IT shortcoming. It is a direct threat to client money, confidentiality and the firm's standing with the SRA and its insurer.
The questions insurers and clients now ask
Professional indemnity proposal forms and client panel questionnaires increasingly ask the same things: Is multi-factor authentication enforced for every user? Are admin accounts separated from day-to-day accounts? How quickly is a leaver's access removed? Firms that cannot answer confidently pay for it — in premiums, in panel reviews, and occasionally in the worst way.
Is your firm's technology environment resilient?
Find out where your firm stands on access control, and every other domain of resilience, with a free assessment written for law firms.
Get your firm's Technology Resilience ScoreWhere access control quietly breaks down
Few firms decide to run weak access control. It accumulates. A partner who has "always had" admin rights. A departed paralegal whose account was never disabled because nobody owned the task. A shared login for the accounts system because it was quicker during an audit. MFA rolled out to email but never to the practice management system.
Each one feels small. Together they mean the firm cannot say, with confidence, who can touch client data today — and that is exactly the gap an attacker, or a regulator, will find first.
What good looks like
In a well-run firm, multi-factor authentication is enforced for every user on email and the practice management system — no exceptions for seniority, and no exceptions for convenience. Admin rights are separated from daily-use accounts. When someone leaves, their access is removed the same day, and someone can show the record. Access is reviewed periodically, so the answer to "who can see this matter?" is a report, not a guess.
In that environment, a stolen password gets an attacker almost nowhere — and the firm can evidence its position to clients, insurers and the SRA on request.
How this TRS domain helps law firms improve
The Passwords & Access domain of the Technology Resilience Score helps firms assess how well identity is controlled. It asks questions such as:
- Is multi-factor authentication enforced for every user, on every core system?
- Are privileged accounts separated from day-to-day accounts?
- How quickly is a leaver's access removed — and can we prove it?
- Who has access to the client account and payment processes?
- When did we last review who can see what?
The result is a score out of 5. That score provides a clear baseline and a structured path to improvement — and it is one of the first things we strengthen for firms, because it carries the most risk reduction per pound spent.
The Technology Resilience Score gives SME law firms a clear benchmark across 10 domains, including Passwords & Access. As a Clio partner, Little Big Tech helps firms build an environment where access is controlled, evidenced and ready for scrutiny. Find out more about our approach at our Technology Resilience Score™ framework.
Related reading
Is your firm's technology environment resilient?
Find out how well protected your matter files, client account and email really are, with a free Technology Resilience Score™ written for law firms.