Appearance
Security Best Practices Checklist β
Print or bookmark this practical checklist to keep your practice secure against unauthorized access, accidental data disclosure, and digital fraud.
π Checklist for Every Legal Practitioner β
Use this quick checklist to audit your daily digital habits:
Password & Account Hygiene β
- [ ] Unique Password: My MtaaLex password is unique and not reused on my personal email, social media, or banking.
- [ ] Strict Privacy: I have never shared my login credentials with colleagues, pupils, or administrative staff.
- [ ] No Written Passwords: My password is not written on sticky notes, notebooks, or stored unencrypted on my desktop.
- [ ] Official Email: My account is registered under my official law firm email address.
Physical & Device Security β
- [ ] Screen Lock: My laptop, phone, and tablet lock automatically after 3 to 5 minutes of inactivity.
- [ ] Lock When Away: I lock my computer screen (
Windows + LorCmd + Ctrl + Q) whenever I step away from my desk. - [ ] Software Updates: My operating system and web browser (Chrome, Edge, Safari, Firefox) are set to install security updates automatically.
- [ ] Clean Downloads: I regularly clear confidential pleadings and client evidence from my computer's local Downloads folder.
Working Outside Chambers (Courts & Travel) β
- [ ] No Public Computers: I avoid accessing client matters on public cybercafΓ©s or court registry computers whenever possible.
- [ ] Sign Out When Shared: If I use an office reception computer or colleague's screen, I always click Sign out explicitly.
- [ ] Never Save on Shared PCs: I never allow shared browsers to "remember" my login credentials.
- [ ] Secure Hotspot: When in court or transit, I use my encrypted mobile phone hotspot rather than open, password-free public Wi-Fi networks.
Vigilance Against Scams β
- [ ] Check Senders: I carefully verify sender email addresses before clicking links in emails claiming to be from MtaaLex, e-Filing, or KRA.
- [ ] Zero Password Sharing: I remember that MtaaLex support will never ask for my password or verification code.
- [ ] Prompt Reporting: If I suspect an unauthorized login, I immediately change my password and notify my Managing Partner.
βοΈ Checklist for Managing Partners & Administrators β
Use this checklist to govern your firm's workspace and regulatory compliance:
Access & Role Governance β
- [ ] Least Privilege Assigned: All staff members are assigned the lowest role needed for their daily tasks (e.g., pupils do not have administrative roles).
- [ ] Admin Roles Restricted: Full administrative and financial rights are limited strictly to Managing Partners and authorized finance officers.
- [ ] Quarterly User Audits: Our firm reviews the active user list every three months to verify that all listed individuals still work at the firm.
- [ ] Stale Invites Purged: Any unaccepted or outdated user invitations are cancelled.
Onboarding & Offboarding Staff β
- [ ] Verified Invitations: All new staff invitations are sent only to confirmed, official work email addresses.
- [ ] Immediate Offboarding: When a lawyer or staff member departs, their MtaaLex account is deactivated on their final working day.
- [ ] Case Reassignment: All active matters handled by departing advocates are reassigned to continuing partners or associates.
- [ ] Historical Records Preserved: Past case notes, pleadings, and fee notes remain safely archived in the firm's permanent record.
Confidentiality & Compliance β
- [ ] Client Representation Verified: Before opening a matter, client details are confirmed to avoid internal conflicts of interest.
- [ ] Sensitive Files Restricted: High-profile litigation or sensitive corporate transactions are restricted to designated lead counsel and approved collaborators.
- [ ] Firm Incident Plan: Our firm has a clear protocol for reporting lost laptops, suspected email compromise, or data leaks.
