CAOC Forum - September/October 2026

Technology’s Effect on Advocacy

may not catch the real threat: middle-of-the-night login from outside the country, allowing hours of open access before anyone at your firm wakes up. This is a major one: setting up your Global Administrator. Typically, whoever first signed the office up for email still holds Global Administrator on the account they personally use all day. That one account reads the mail, opens the attachments, browses the web, and has complete control of the environment sitting directly behind it. Microsoft is blunt on the subject: Global Administrator belongs to emergencies, and administration belongs on a separate account. To put it more clearly, if a partner at a law firm signs the contracts to set up Microsoft accounts, by default, the partner, and their connected email address, becomes the Global Administrator. Instead, a different user should be created not connected to a day-to-day email address. Without doing this, one convincing message from or to that mailbox is not a minor incident - it exposes the entire firm. Do you know who at your firm can create new shared workspaces, public folders, or even create email forwarding rules? After a few years, a single staff member can unknowingly, and unintentionally, create dozens of digital workspaces and public folders, full of client material, with no owner and nobody checking access. None of that is the platform being careless. Defaults get written for smooth adoption and broad compatibility, reasonable for a software company and poor for an office holding privileged files. It is common for staff to also be able to create rules for email forwarding, even to emails outside the firm’s email domain. This is problematic for firms because

October is National Cybersecurity Awareness Month. Protect your clients by protecting their data.

forwarding rules outlive a password change! A default is a floor. Everyone at the firm should follow the same configuration rule: support staff and attorneys should have access to what their job requires and nothing beyond it. It sounds obvious, but it’s a common misstep, especially for growing firms. You don’t need a specialist to get the basics in order. Better protect your firm today by completing the following: Invest in a hosted platform like Microsoft 365 or Google Workspace. Require multi-factor authentication at every sign- in, not only when the platform decides a login looks risky. Start with email accounts, as email can reset all other platforms attempting logins. Move Global Administrator off any account used for daily work and create a separate account for administration. Narrow permissions to match job responsibilities. Review who can create sites, groups, and shared workspaces, and move default sharing off its most permissive setting. Restrict automatic forwarding to outside addresses, and limit who can create mailbox rules. Teams change, tools change, people leave the firm. Never adjusting settings does not make you or your firm unlucky when it comes to cyberattacks – it will put you next in line.

25

Consumer Attorneys of California

FORUM September/October 2026

Made with FlippingBook - Online catalogs