Client Confidentiality When Half the Firm Works From Home
Remote work moved privileged files onto home routers, family printers, and laptops that ride around in car boots. Here is where confidentiality actually breaks in a distributed firm, and which controls contain the damage when it does.
Every firm that went hybrid inherited a security perimeter it never designed and has never inspected. The office had a locked door, a supervised printer, a network somebody configured on purpose, and a shredder that got emptied by a contracted service. The home offices that now hold half the firm's working files have none of that, and nobody in the firm can tell you what the router in a senior associate's spare room is actually doing, whether the firmware has been updated since it came out of the box, or who else is on that network at two in the afternoon.
This is not an argument against remote work. It is an argument that confidentiality obligations followed everyone home and the controls did not. A duty of confidentiality is owed by the lawyer, not by the building, and no regulator anywhere has decided that the standard relaxes because the desk moved. What changed is the number of failure points and the fact that almost none of them are visible to whoever is responsible for compliance.
What follows is the physical and technical reality of a distributed firm: the network, the hardware, the shared space, the paper, the disposal, the lost laptop, and the access architecture that determines whether an incident is an inconvenience or a notification event. The specific obligations vary considerably by jurisdiction, so treat everything here as the mechanism rather than the rule and confirm the rule with your own regulator.
The Home Network Is the Part Nobody Audited
The typical home network was set up once, by an internet provider's technician or by the person who lives there, and has not been touched since. That usually means the router is running whatever firmware shipped on it, the administrative password may still be the one printed on a sticker underneath, and the wireless network is shared with a smart television, a games console, a couple of phones belonging to teenagers, a doorbell camera, and whatever a flatmate has connected. Any one of those devices can be compromised without the owner noticing, and once something has a foothold on the same flat network as a work laptop, it is in a far better position than it should ever have been.
The practical fix is not complicated, it is just unowned. Someone at the firm has to actually specify that work devices sit on a separate network segment, usually the router's guest network or a second wireless network with its own password that nothing else in the house joins. Router firmware needs to be current, the admin credential needs to be changed off the factory default, and remote administration of the router from outside the house needs to be switched off, because that feature is enabled by default on a surprising number of consumer devices. None of this requires an IT department, but it does require someone to write it down, walk each person through it once, and record that it was done, because a control nobody verified is a control nobody has.
- Does every remote worker's firm device sit on a network segment separate from household smart devices?
- Has the router admin password been changed off the factory default and firmware updated in the last year?
- Is remote router administration from outside the home disabled?
- Can you name, today, every personal device that has ever opened a client document?
Firm Devices and Personal Devices Are Not the Same Risk
The moment a paralegal opens a client PDF on a home desktop that the rest of the household also uses, the firm has lost the ability to say anything meaningful about where that file went. Personal machines carry other people's logins, browser extensions nobody vetted, consumer backup tools, and often no disk encryption at all. They are also outside any wipe or recovery capability the firm might have. The distinction between a firm-issued device and a personal one is not administrative pedantry, it is the difference between an asset you can account for and one you cannot.
Firms resist buying hardware because laptops are expensive, and then quietly accept an exposure that costs far more to unwind. The middle path most small firms actually land on is a firm-issued laptop for anyone who handles client documents regularly, with full disk encryption switched on and verified rather than assumed, screen lock enforced at a short idle timeout, and a clear rule that client work happens on that machine and nowhere else. For occasional access, a browser session on a personal device is far safer than downloading files onto it, which is one of the underrated advantages of a cloud-native system: Casely has no local install, so the firm's system of record never becomes a database sitting on somebody's home hard drive waiting to be backed up into a personal cloud account.
| Feature | Firm-Issued Device | Personal Home Device |
|---|---|---|
| Disk encryption | Verified by the firm at setup | Unknown, often off by default |
| Remote wipe if lost | Possible | Not possible |
| Other users on the machine | None | Household members, shared profiles |
| Backup destination | Firm-controlled | Personal cloud account, unaudited |
| Recoverable on departure | Yes, hardware returns | No, files stay wherever they landed |
The Sync Problem Nobody Notices Until It Matters
The most common way privileged material leaves a firm's control has nothing to do with attackers. Someone saves a client document to their desktop, and their personal cloud backup, already running on that machine because it came preinstalled, quietly copies it into a consumer account that the firm has never heard of and cannot search, retain, or delete. Multiply that across a year of remote work and the firm has an uncontrolled second copy of its file room distributed across personal accounts belonging to people who may not work there next year.
This is where document handling has to be structural rather than advisory. Telling people not to save files locally is a rule that decays within weeks, because at some point somebody needs to work on a train. What holds is making the system the easiest path: documents stay in the practice management system, encrypted at rest with AES-256 under a key specific to your firm rather than a shared pool, and every version carries a comment field recording what changed and why, so the current copy is unambiguous and nobody needs a personal working copy just to keep track of which draft is live. When the authoritative version is easier to reach than a downloaded one, the downloaded ones stop accumulating.
Shared Space and the Calls Everyone Can Hear
An office conversation is bounded by walls and by the fact that everyone in earshot owes the same duty. A home conversation is bounded by nothing. Spouses, adult children, flatmates, cleaners, and the neighbour on the other side of a thin wall are all people who have made no confidentiality undertaking to anyone. A call about a client's divorce settlement, a corporate matter that has not been announced, or a criminal defence strategy is not protected by the fact that the person listening is unlikely to care, and in a small town the odds that they know the client are not remote at all.
The controls here are unglamorous and effective. Headphones rather than speakerphone, without exception, on any call involving a named client. A door that closes for anything sensitive, and an honest conversation with anyone who cannot achieve that at home about whether they need occasional office time or a different arrangement. Voice assistants and always-listening devices removed from the room used for client work rather than merely muted. And a rule that people say out loud at the start of a call whether anyone else is present in the room, which sounds fussy for exactly as long as it takes to be glad someone asked.
Video Calls Reveal More Than the Person Speaking
Video adds a second channel of leakage that most firms have never thought about. A whiteboard behind someone's head with three client names on it, a stack of files with a visible label, a monitor reflected in a window, or a screen share that briefly shows an inbox with subject lines from unrelated matters are all disclosures, and the last one happens constantly. Screen sharing an entire desktop rather than a single window is the single most common way privileged information about a different client ends up in front of the wrong audience.
Fix the defaults rather than relying on care in the moment. Share a specific application window, never the whole screen. Close every unrelated tab and application before joining a call with anyone outside the firm. Use a plain wall or a solid background for external calls, and check the physical background for anything with a name on it. Turn off desktop notification previews, because a banner showing another client's name and the first line of their message is visible to everyone watching, and the person sharing will not see it happen until someone mentions it.
Home Printing Is the Quiet Failure
Printing at home reintroduces every paper problem the office solved, minus the solutions. The document sits in an output tray in a shared room until someone collects it, which may be hours. It gets read by whoever walks past. It gets used as scrap. It ends up in a household recycling bin that goes to the kerb, which is the single most retrievable place a privileged document can be put. And the multifunction printer that produced it holds an image of the page in memory, and on many models on internal storage, long after the job finished.
The cleanest policy is that client documents are not printed at home at all, and for most firms that is now realistic. Reviewing on screen, marking up in the document system, and signing electronically covers the overwhelming majority of what used to require paper. Where a physical copy genuinely cannot be avoided, the requirement is collection from the tray immediately, secure storage in a locked drawer while it exists, and cross-cut shredding at home rather than transport back to the office in a car boot, which is its own exposure. Strip-cut shredders that produce long ribbons are not adequate for privileged material, and are the type most people already own.
Disposal Is Where Old Exposure Comes Back
Disposal is the failure mode with the longest tail, because the material sits somewhere for years before anybody looks. A laptop replaced two years ago and left in a cupboard still holds a full working set of client files unless its drive was actually wiped or destroyed. A home printer sold on a marketplace site may carry stored scan and print images. An old phone traded in still has a mail account with attachments, and in many cases still has the notes someone took during a client call. None of these are hypothetical routes, they are the routine ones.
Build a hardware retirement step into your offboarding and refresh process and make it a documented event. Drives get cryptographically erased or physically destroyed and the fact recorded against the device. Printers and scanners get factory reset before leaving the household, and where the model stores images on internal media, that media gets removed. Phones get remotely wiped and removed from the firm's accounts rather than merely signed out. And departing staff hand back hardware, which is only possible if the firm issued it in the first place, which is the argument for firm-issued devices restated in a different form.
When a Device Actually Goes Missing
Laptops get left on trains, taken from cars, and stolen from cafe tables, and phones go missing constantly. The relevant question is not whether it will happen but what the first hour looks like when it does. In most firms the honest answer is that the person who lost it spends that hour retracing their steps, tells nobody until the following morning because they are embarrassed, and by then any window for a clean containment has closed. That delay, not the loss itself, is what turns an incident into a problem.
Make reporting immediate, blameless, and specific. Everyone should know exactly who to call, on a number they have saved, within minutes of realising a device is gone, and should know that reporting fast is the expected behaviour rather than an admission of failure. From the firm's side, the response is credential revocation for that user across every system, active session termination, remote wipe where the device supports it, and a written record of what the device could reach. Whether a notification obligation is triggered depends heavily on where you practise. UK and EU firms have a data protection notification clock that runs in parallel with any professional obligation, US firms face state breach notification statutes that differ meaningfully from one another as well as bar duties to inform affected clients, and Canadian and Australian firms operate under their own regimes. Have that determination mapped out before you need it, and confirm it with local counsel or your regulator rather than assuming your neighbour's rule applies.
- 01Device reported missing within minutes, to a named person
- 02Credentials revoked and all active sessions terminated
- 03Remote wipe issued where the device supports it
- 04Written record made of what that device could actually reach
- 05Notification obligations assessed against local rules, not assumed
Access Controls Decide How Bad the Bad Day Gets
Every control above reduces the chance of an incident. Access architecture decides what an incident costs, and it is the part firms consistently underinvest in because its value is only visible on the worst day. If one compromised login can reach every matter the firm has ever opened, then the blast radius of a stolen laptop is the entire practice. If access is genuinely scoped, the same event is contained to what that one person actually needed.
This is why enforcement location matters more than the existence of a permission setting. A restriction implemented by hiding a menu item is not a restriction, because the underlying data is still reachable by search, by a calendar entry, by an export, or by a link someone forwarded. Casely enforces ethical walls at the server and data access layer, so a walled user genuinely cannot reach a restricted matter by any path, including search and a forwarded link, which means a compromised account inherits only the reach that account actually had. Combine that with per-firm document encryption and the practical exposure from a single lost credential drops to a defined, describable set of matters, which is also the only honest way to answer a client asking what was affected.
Client Communication Is Part of the Perimeter
Most firms tighten internal controls and then continue emailing privileged documents to clients as attachments, which sends an unencrypted copy into an inbox with unknown security, on a device the firm knows nothing about, where it will sit indefinitely and be forwarded without anyone's knowledge. Remote work made this worse rather than better, because the informal channel expanded to include personal messaging apps and whatever the client suggested during a call.
The alternative is a single controlled channel that the client actually finds easier than email, because anything harder will lose. A privilege-filtered client portal shows each client only what they are entitled to see, filtered automatically per document rather than by whoever remembered to check, works on a phone so clients actually use it, and handles e-signature inside the same login without a separate account for the client to create and abandon. That last detail matters more than it sounds: every extra account is a reason for the client to ask you to just email it instead, and every one of those emails is a copy you no longer control.
Write It Down, Then Verify It Once
A distributed firm cannot rely on observation, which is what most partners were unconsciously using as their compliance mechanism. Nobody walks past a home office and notices the screen left unlocked or the printed bundle on the side table. That means the standards have to be explicit, and more importantly, somebody has to check once rather than assume. A short, honest attestation covering network separation, disk encryption, printing practice, shredding, and household devices, completed by each person and reviewed by one named individual, will surface more real exposure in an afternoon than a policy document will prevent in a year.
The check is worth repeating annually, because circumstances change quietly. People move house, replace routers, take in a flatmate, buy a smart speaker, or start using a personal tablet for convenience. None of those events generate a notification to the firm, and all of them alter the risk picture. Reviewing hardware and household setup at the same time each year, alongside the access review that asks who can currently reach what, keeps the picture roughly accurate instead of two years stale.
Where to Start if This List Feels Long
Do not try to fix all of this at once, because a firm that attempts everything simultaneously usually completes none of it. Start with the two controls that cap the damage rather than the ones that reduce the frequency: full disk encryption verified on every device that touches client work, and access scoping that means one compromised login cannot reach the whole practice. Those two together turn most realistic incidents into something you can describe accurately to a client and close out, which is a fundamentally different position from not knowing what was exposed.
Then work through the visible physical items, because they are quick and they build the habit. Separate network for work devices, headphones on client calls, no home printing, cross-cut shredder where paper is unavoidable, and a named person to call the moment a device goes missing. After that, move the file room and the client conversation into controlled channels, so the copies stop multiplying into personal accounts and client inboxes. If you want to see what structural enforcement looks like in practice rather than as policy language, the document management side of Casely is a reasonable place to start, and the free plan costs nothing to test against your own real workflow.
The point of all of this is not to make remote work feel risky. It is that confidentiality in a distributed firm has to be built into systems, because the informal supervision that used to do the work silently is gone and is not coming back. Firms that accept that and design for it end up with better control than they had in the office, where a great deal was being held together by the fact that everyone could see each other.
WRITTEN BY
Arusarka B.
Covers legal technology, compliance workflows, and how firms actually adopt new practice management software.
More about the team