NFPA Paralegal Core Competency Exam (PCCE)Paralegal PracticeMedium
A paralegal is responsible for managing the firm's electronic document system and often works remotely. The firm has a strict policy requiring multi-factor authentication (MFA) for all remote access and encrypted hard drives for all firm-issued devices. One day, the paralegal receives an email appearing to be from the IT department, asking them to click a link to 'verify their login credentials due to a system update.' What is the most ethical and secure course of action for the paralegal?
- AReply to the email asking for more information before proceeding.
- BIgnore the email, as it is likely spam and not relevant to their work.
- CClick the link and enter the credentials, assuming it is a legitimate request from IT.
- DForward the email to the IT department for verification and do not click the link.
Show answer & explanationAnswer & explanation
Correct answer: D. Forward the email to the IT department for verification and do not click the link.
This scenario describes a classic phishing attempt. The most ethical and secure action is to avoid clicking suspicious links and to verify the legitimacy of such requests directly with the IT department through an official, known channel, not by replying to the potentially malicious email.
Why the other options are wrong
- A. Replying to a phishing email confirms your email address is active and can lead to further targeted attacks, compromising security.
- B. Ignoring the email might prevent personal compromise but fails to alert the firm to a potential widespread threat, which is a professional responsibility.
- C. Clicking the link and entering credentials would compromise security and is a common trap in phishing schemes.
Cybersecurity Best Practices for Paralegals
Paralegals must adhere to strict cybersecurity protocols to protect sensitive client data, including recognizing phishing attempts, using strong passwords, and ensuring data encryption.
- Always verify suspicious communications through official channels.
- Use multi-factor authentication where available.
- Ensure client data is encrypted and securely stored.
Memory trick: Verify, Encrypt, Report – Keep Client Data Sport!