
Article Summary
- Understanding the specific confidentiality risks that arise when attorneys access client files from home networks and personal devices provides managing partners with the context they need to treat remote work IT as a professional conduct obligation, not just an operational convenience.
- Knowing the difference between a VPN and a virtual desktop for lawyers, and when each is the right tool, helps your firm deploy remote access infrastructure that actually protects client data rather than creating a false sense of security.
- Learning what a complete, ABA-aligned remote-work IT setup looks like in practice gives your firm a concrete framework for supporting hybrid attorneys without exposing it to the confidentiality, compliance, and malpractice risks that unsecured remote access creates.
An attorney working from home opens their personal laptop, connects to the family Wi-Fi router, and pulls up a client’s case file to prepare for a deposition. The router is running firmware from three years ago that has never been updated. The laptop has no endpoint protection beyond the consumer antivirus software that came pre-installed when the machine was purchased. There are three other devices on the same network: a teenager’s gaming console, a smart TV, and a security camera that has not received a firmware update since it was unboxed. Any one of those devices could be compromised without the attorney knowing, and everything on that network, including the client’s case file, the settlement figures, and the deposition outline, is accessible to anything else on it. Remote work IT for law firms is the discipline that prevents that scenario from becoming a bar complaint, a malpractice claim, or a breach notification obligation.
Hybrid work is now the operational reality for most Philadelphia-area law firms. Attorneys split their time between the office, their homes, client locations, and courthouses. Malvern practices that grew from single-office operations now have attorneys working remotely on a regular basis. Wilmington firms handling complex corporate matters have partners who work from home in the evenings and on weekends when deal deadlines demand it. The technology infrastructure that those firms built for office-based work was not designed to support this reality securely, and the gap between how attorneys are working and how the firm’s IT environment was designed to protect them is where the confidentiality risk lives.
What the ABA says about remote access for attorneys
ABA Formal Opinion 477R, issued in 2017 and updated subsequently, is the most specific guidance the ABA has provided on the security obligations that attach to electronic communications in legal practice, including remote access to client files. The opinion addresses the question of what reasonable measures an attorney must take when transmitting or accessing confidential client information electronically, and its answer is more demanding than many managing partners expect.
The opinion states that attorneys must consider the sensitivity of the information, the likelihood of unauthorized access given the communication method, and the extent to which privacy is appropriate given the circumstances. It identifies specific technical controls, including end-to-end encryption, virtual private networks, and multi-factor authentication, as components of a reasonable remote access program for sensitive legal matters. The opinion also establishes that the appropriate level of protection scales with the sensitivity of the information involved: accessing routine scheduling information over a home network raises fewer concerns than accessing a client’s financial records or active litigation strategy.
How ABA Formal Opinion 477R creates a practical IT checklist
The practical implication of ABA Formal Opinion 477R is that law firms cannot treat remote access as a technology preference. It is a professional conduct obligation with defined standards for what constitutes reasonable protection. An attorney who accesses client files over an unencrypted connection, without multi-factor authentication, on a device without endpoint protection is not meeting the ABA’s articulated standard, regardless of whether an incident occurs.
Partners Plus uses ABA Formal Opinion 477R as a framework for evaluating every law firm’s remote work IT environment, mapping the firm’s current remote access infrastructure against the ABA’s identified controls for reasonable electronic communication security. The result is a gap analysis that gives the managing partner a clear picture of where the firm’s current remote access program falls short of the standard it is ethically obligated to meet, before that gap is identified by a bar investigator or exploited by an attacker.
State bar obligations that layer on top of ABA guidance
Pennsylvania and Delaware both incorporate technology competence requirements into their rules of professional conduct, and both states have breach notification laws that create time-sensitive obligations when client data is compromised. For Philadelphia and Wilmington law firms, the ABA’s guidance on remote access is reinforced by state-level obligations that make the consequences of inadequate remote work IT concrete and local.
Pennsylvania’s breach notification statute requires firms to notify affected individuals within a defined timeframe when personal information is compromised in a security breach. If an attorney’s compromised home network results in unauthorized access to client files containing personal information, that event triggers a notification obligation that the firm must execute under time pressure, whether it has a documented incident response plan in place or not. Partners Plus helps Philadelphia and Wilmington law firms build remote-work IT programs that reduce breach risk and ensure incident response plans are in place before an event forces the issue.
The difference between a VPN and a virtual desktop for law firms
A VPN, or Virtual Private Network, creates an encrypted tunnel between a remote device and the firm’s network, allowing the attorney to access network resources as if they were physically in the office. For many law firms, a VPN was the first remote access solution deployed, and for less sensitive tasks it provides a meaningful baseline of protection. The limitation is that a VPN extends network access to the remote device itself, meaning that any malware or attacker already on that device is now effectively inside the firm’s network through the VPN connection.
A virtual desktop, sometimes called VDI or Virtual Desktop Infrastructure, takes a fundamentally different approach. Instead of extending network access to the remote device, a virtual desktop delivers a computing session that runs entirely on servers in the firm’s data center or cloud environment. The attorney sees and interacts with a desktop interface on their local device, but no firm data ever actually moves to that device. The case file, the document being drafted, and the email being composed all stay on the firm’s servers. If the attorney’s home laptop is compromised, the attacker gains access only to what is visible on the screen, not to the underlying data.
For law firms handling highly sensitive matters, this distinction is significant. Partners Plus implements Microsoft Azure Virtual Desktop environments for law firms that require the strongest available separation between attorney devices and firm data, deploying a configuration in which attorneys access a fully managed virtual desktop session that enforces security policies, prevents data downloads to personal devices, and logs all session activity for audit purposes. For firms whose attorneys primarily need access to email and document collaboration rather than sensitive case management systems, a properly secured VPN combined with Microsoft 365 cloud access may be a proportionate solution. The right architecture depends on the sensitivity of the data being accessed and the firm’s risk tolerance, and Partners Plus evaluates both before making a recommendation.
How mobile device management protects firm data on personal devices
Mobile device management, commonly called MDM, is a set of technologies and policies that allow a firm’s IT provider to enforce security requirements on devices used to access firm resources, including personal devices owned by attorneys and staff. For law firms operating hybrid work models, MDM is the control that bridges the gap between the firm’s security requirements and the reality that attorneys are using personal phones, tablets, and laptops to access client data.
A properly configured MDM solution can enforce password requirements and screen lock policies on enrolled devices, require device encryption, remotely wipe firm data from a device that is lost or stolen, and prevent firm data from being copied to personal applications or storage locations that the firm has not approved. Microsoft Intune, which is included with Microsoft 365 Business Premium, is the MDM platform Partners Plus deploys for most law firm clients because it integrates directly with the firm’s existing Microsoft 365 environment and allows a single administrative console to manage both corporate and personally owned devices under the firm’s security policies.
The most common objection managing partners raise to MDM for personal devices is that attorneys will resist having the firm’s IT provider manage their personal phones. This concern is addressed through a configuration approach that separates firm data from personal data on the device without giving the IT provider visibility into the attorney’s personal applications, photos, or content. The MDM policy applies only to the firm’s applications and data containers, not to the device as a whole. Partners Plus explains this distinction during every MDM deployment for law firms because attorney adoption depends on the firm’s IT provider being transparent about exactly what the MDM solution does and does not control.
What a secure remote work setup looks like for a law firm in practice
Building a secure remote work IT program for a law firm is not a single technology decision. It is a layered architecture that addresses device security, access security, data protection, and ongoing monitoring as connected components of a unified program. Each layer reinforces the others, and gaps in any one layer can undermine the protection provided by the others.
The device layer covers every endpoint that accesses firm data remotely. Each device, whether firm-issued or personally owned, must have endpoint detection and response software installed, must meet defined security standards before being granted access to firm resources, and must be enrolled in the firm’s MDM program so that access can be revoked and firm data can be wiped if the device is lost, stolen, or compromised. Devices that do not meet these standards should not be permitted to access firm resources, regardless of the device’s owner or the attorney’s seniority.
The access layer covers how attorneys authenticate to firm systems and what they can access once authenticated. Multi-factor authentication is non-negotiable: every system that an attorney accesses remotely should require a second verification factor in addition to a password. Access controls should be role-based, limiting each attorney to the matters and systems relevant to their work rather than providing broad access to all firm resources. Session timeout policies should log users out after a defined period of inactivity, preventing an unlocked session on an unattended device from becoming an access point.
The monitoring layer ensures that remote access activity is logged and reviewed for anomalies that indicate a compromised account or an unauthorized access attempt. Partners Plus monitors remote access logs for every law firm it supports, watching for authentication events that do not match the attorney’s normal access patterns: logins from unexpected geographic locations, access attempts outside normal working hours, or credential use that follows a pattern consistent with brute-force testing. This monitoring capability is supported by the Partners Plus offices in Philadelphia, Malvern, Wilmington, and Middletown, giving East Coast law firms a monitoring team that has been protecting legal practices since 1991 and understands the access patterns and risk profile specific to legal practice.
The full remote work IT program Partners Plus delivers for law firms connects directly to the IT Services Designed for Law Firms framework, a comprehensive approach to legal technology that integrates remote access security with network security, cybersecurity, cloud infrastructure, compliance management, and managed IT support. Secure remote work is not a standalone product. It is a critical layer of a well-managed legal IT environment, and it works best when designed alongside the security controls and cloud architecture that protect the data attorneys access remotely.
Every day a Philadelphia, Malvern, or Wilmington law firm allows attorneys to access client data through unsecured home networks and unmanaged personal devices is a day the firm is accepting professional conduct risk it cannot fully quantify. The ABA has defined what reasonable remote access protection looks like. The question is whether the firm’s current IT environment meets that standard. Contact Partners Plus today to schedule a remote work IT assessment and find out exactly where your firm stands.
Frequently Asked Questions About Remote Work IT for Law Firms
Why Partners Plus
Partners Plus has been building and managing remote work IT programs for East Coast law firms since 1991, with offices in Philadelphia, Malvern, Wilmington, and Middletown, delivering both the technical infrastructure and the ongoing monitoring that secure remote access requires. Every remote work IT program Partners Plus implements for a law firm is aligned with ABA Formal Opinion 477R, Pennsylvania and Delaware bar requirements, and the specific confidentiality obligations that legal practice demands, covering virtual desktop deployment, MDM enrollment, multi-factor authentication, and endpoint security across every device that touches firm data. Remote access monitoring runs continuously, ensuring that compromised credentials and unauthorized access attempts are identified and contained before they reach the case files and client records that attorneys are working to protect. Contact the Partners Plus team today to schedule a remote work IT assessment for your firm.
Our Locations:
- Managed IT Services in Philadelphia: In the city’s heart, our Philadelphia location stands as the cornerstone of our operations, delivering robust IT frameworks and cybersecurity defenses to a diverse clientele.
- Managed IT Services in Malvern: Serving the dynamic businesses in Malvern, our team specializes in custom IT strategies that drive growth, streamline operations, and protect against cyber threats.
- Managed IT Services in Wilmington: Our Wilmington branch focuses on delivering top-tier managed IT services, ensuring businesses operate smoothly with state-of-the-art technology and fortified security measures.
- Managed IT Services in Middletown: The latest addition to our network, the Middletown office, extends our reach, offering comprehensive IT solutions that support businesses in adapting to the digital age, emphasizing innovation and security.
Our Services:
- Customized IT Support: Understanding that each business’s needs are unique, we offer personalized IT support plans to ensure your technology aligns with your business goals.
- Cybersecurity Solutions: With cyber threats evolving daily, our advanced cybersecurity services are designed to protect your business from the latest digital threats, ensuring your data and operations are secure.
- Cloud Computing Services: Leverage the power of the cloud with our cloud computing solutions, facilitating seamless access to data and applications, enhancing collaboration, and optimizing operational efficiency.
- Data Backup and Recovery: Our comprehensive data backup and recovery services protect your critical business data against loss with robust recovery solutions to minimize downtime during a disaster.
- Strategic IT Consulting: Navigate the complex technology landscape with our expert IT consulting services. From strategic planning to implementation, we guide you through every step to ensure your IT investments deliver maximum value.










