The modern lawyer doesn't work behind one neatly defined network perimeter. They might begin the day working from home, spend the afternoon at a client site and access documents from the office the following morning. They expect email, files, matter systems and collaboration tools to be available wherever they need to work.
For IT teams, that creates a very different security challenge. Who is signing in? What device are they using? Where are they connecting from? What are they trying to access? And should they have access to it?
Traditional security models were often built around protecting the network perimeter. Once somebody was inside that trusted environment, they could generally access the systems and information their credentials allowed.
Modern legal work makes that distinction increasingly difficult to maintain. That's where Zero Trust becomes useful — not as another security product, but as a different way of deciding who and what should be trusted. And implemented well, it doesn't have to make lawyers' jobs harder.
Zero Trust Doesn't Mean Trusting Your Lawyers Less
The name can be misleading. Zero Trust isn't about assuming employees are untrustworthy. Nor does it mean forcing users through endless authentication checks every time they try to work.
The principle is better understood as: Don't automatically trust an access request simply because it comes from inside the organisation. Verify it using the information available.
That means considering factors such as the user's identity, device, location, behaviour and the sensitivity of whatever they're trying to access.
A lawyer signing into a familiar application from their managed laptop in Adelaide may present a very different risk profile from the same account suddenly attempting to access sensitive information from an unfamiliar device or unusual location.
Zero Trust gives IT teams a framework for recognising that difference. The goal isn't to create more barriers for legitimate users. It's to make better decisions about when those barriers are actually necessary.
1. Start With Identity
When applications and information can be accessed from almost anywhere, identity becomes one of the most important security boundaries. A username and password alone shouldn't necessarily be enough to establish trust.
That's why identity security is typically one of the first areas to address in a Zero Trust strategy. Multi-factor authentication is an important foundation, but there are other questions worth considering.
Are stronger authentication methods used for sensitive or privileged accounts? Can access policies respond to unusual sign-in behaviour? Are dormant accounts removed? Are former employees promptly offboarded? Do administrators use the same accounts for everyday work and privileged tasks?
Technologies such as Conditional Access can add context to these decisions by considering factors such as user, device, location, application and detected risk before granting access.
That allows IT teams to move beyond a simple “correct password = access granted” model. The question becomes: Is this the right person, accessing the right resource, under circumstances we're comfortable with?
2. Trust the Device — Not Just the Password
Knowing who is signing in is only part of the picture. The device they're using matters too. Imagine a lawyer successfully authenticates to a sensitive system. Their identity is legitimate, but they're accessing it from an unmanaged personal device with outdated software and no endpoint protection.
Should that request be treated exactly the same as one coming from a firm-managed, compliant laptop? Probably not. A Zero Trust approach can incorporate device posture into access decisions. That might include checking whether:
- the device is managed;
- required security updates are installed;
- endpoint protection is active;
- encryption is enabled;
- the device meets compliance requirements; and
- there are signs that the endpoint may be compromised.
The response doesn't always have to be “block access.” Depending on the situation, IT might allow normal access from a compliant device while restricting sensitive actions from an unmanaged one. That creates a much more nuanced approach than treating every device as equally trustworthy.
3. Give People the Access They Need — Not Everything They Might Need
Access tends to accumulate. Someone joins the firm and receives access appropriate to their role. They move practice groups, become involved in different matters, take on new responsibilities and receive additional permissions.
Years later, they may still have access to information they no longer require. Zero Trust applies the principle of least privilege: users should have the access required to perform their role, without unnecessary permissions being retained indefinitely.
For law firms, that can mean reviewing access across matter information, document repositories, business applications, shared locations and privileged systems.
This isn't simply about reducing the impact of a compromised account. It's becoming increasingly relevant as AI enters the workplace. AI tools connected to organisational information can make data considerably easier to discover. Information that somebody technically had permission to access — but would previously have struggled to find — may become much easier to surface through a natural-language query.
That makes a simple question increasingly important: If someone can access this information, should they still be able to? Zero Trust and good information governance increasingly go hand in hand.
4. Use Context to Reduce Friction
One of the common objections to stronger security controls is user friction. And it's a reasonable concern. If every application constantly requests additional authentication, every remote connection becomes difficult and legitimate users are repeatedly blocked, people will become frustrated.
They may also look for ways around the controls. Good Zero Trust architecture should do the opposite. By using context, IT can apply additional controls when the level of risk justifies them, rather than treating every interaction as equally suspicious.
A familiar user on a compliant corporate device accessing a routine application may require relatively little friction. The same user attempting a sensitive action from an unfamiliar device or unusual location may warrant additional verification.
This is where Zero Trust can actually improve the balance between security and productivity. The goal isn't more authentication. It's better authentication at the moments that matter.
5. Protect Lawyers Wherever They Work
Hybrid work has permanently changed where legal work happens. The office network can no longer be the only place where strong security controls exist. Lawyers may work from home, court, client sites, airports, hotels or other locations. They still need access to the information required to do their jobs.
A Zero Trust model allows security to follow the identity, device and resource, rather than depending entirely on whether somebody happens to be sitting inside a particular office. That can include:
- secure identity-based access;
- compliant device requirements;
- endpoint detection and response;
- appropriate encryption;
- risk-based access policies; and
- controls around sensitive information.
The aim is consistency. A lawyer shouldn't need to understand a completely different security model depending on where they're working. The controls should travel with the work.
6. Don't Forget Applications and Information
Zero Trust is sometimes discussed almost entirely in terms of user authentication. But ultimately, identity is being verified because somebody wants access to something.
That something might be email, a document repository, a practice management platform, financial information, a cloud application or sensitive matter data. Different resources may justify different levels of protection.
Access to a relatively low-risk internal application doesn't necessarily need to be treated in exactly the same way as privileged administration or highly sensitive client information. This is where classification and understanding business context become valuable.
IT teams need to know which systems and information matter most, who should be able to access them and what conditions should apply. The result is a security model built around the value and sensitivity of the resource — not simply whether it sits “inside” or “outside” the network.
7. Authentication Isn't the End of the Story
A user successfully signs in. Their identity checks out. Their device is compliant. Access is granted. Job done? Not necessarily. One of the important principles behind Zero Trust is that trust shouldn't become permanent simply because an initial authentication was successful.
Behaviour can change. An account could suddenly begin accessing unusual volumes of information. A user could attempt to reach resources they've never accessed before. A device could become compromised after the initial login. Continuous monitoring helps IT teams identify those changes. That can include looking for:
- unusual authentication activity;
- suspicious endpoint behaviour;
- unexpected privilege changes;
- abnormal data access;
- risky application activity; and
- other deviations from normal behaviour.
The purpose isn't to scrutinise everything employees do. It's to identify signals that suggest a previously legitimate session or identity may no longer be behaving legitimately. Verify first — then keep paying attention.
8. Zero Trust Doesn't Have to Be a Massive Project
One reason organisations hesitate over Zero Trust is the perception that it requires replacing their entire security architecture. It doesn't. In most environments, Zero Trust is better approached as a progressive security strategy.
A law firm could begin by strengthening identity. Enforce appropriate MFA. Review privileged accounts. Improve onboarding and offboarding. Introduce risk-based access policies.
Then look at devices. Understand which endpoints are managed, establish appropriate compliance requirements and make endpoint health part of access decisions. Next, review access. Identify excessive permissions, stale accounts and areas where least privilege can be improved.
Then consider applications and information. Which systems are most sensitive? Which data requires additional protection? Are controls consistent across cloud and on-premises environments? Finally, improve visibility. Bring identity, endpoint, application and security monitoring together so unusual activity can be identified and investigated more effectively.
The exact sequence will vary from firm to firm. What matters is that Zero Trust becomes a direction of travel, rather than an all-or-nothing technology project.
Security Lawyers Don't Have to Think About
The strongest security controls aren't necessarily the ones users notice most. Often, they're the ones working quietly in the background. A compliant laptop is recognised automatically. A normal sign-in proceeds without unnecessary friction. Access reflects the person's actual role. Additional verification appears when something unusual happens.
From the lawyer's perspective, they can simply work. From IT's perspective, every request isn't automatically trusted just because the credentials were correct or the user happened to be connected to the office network.
That's the balance Zero Trust should aim for. Make legitimate work easy. Make inappropriate access difficult.
For law firms, where employees need flexibility without compromising access to sensitive client and matter information, that principle is particularly valuable. Zero Trust isn't about putting more obstacles between lawyers and their work. Implemented well, it's about creating a security architecture that understands when an obstacle is actually needed — and when it isn't.
Tags:
Legal Services
2 December 2025, 11:44:31 GMT+10:30
Comments