Browser isolation for law firms
Shield moves page execution off-device. See how that fits law-firm work. Review remaining risks, provider access, and retention.

Law firm work often crosses a browser. Research, court portals, client systems, and outside links converge there. The browser deserves a defined security boundary.
Quick answer: Shield runs the page in an off-device browser. Page code runs there. Shield does not decide privilege, confidentiality, or ethics compliance.
This guide provides general security information. It is not legal advice. Check your jurisdiction's rules, client instructions, contracts, and applicable law.
Why the browser boundary matters
The browser joins outside content with firm systems. Links can lead to research or filing portals. They can also carry social-engineering attempts. Each workflow exposes different code, credentials, files, and client information.
On May 23, 2025, the FBI described Silent Ransom Group. The FBI observed consistent U.S. law-firm targeting. It began in spring 2023. The group used callback phishing and remote-access software. It also used phone calls and in-person device access. Shield only changes a supplied page's execution boundary. It does not stop the full campaign.
CISA describes off-device web processing. It calls browser isolation a logical barrier. Files, policy, identity, and endpoints still need separate controls.
Ethics starts with context
ABA Model Rule 1.6, paragraph c requires reasonable efforts. Those efforts address unauthorized access. They also address inadvertent or unauthorized disclosure. Comment 18 makes the analysis contextual. It considers sensitivity and disclosure likelihood. It also considers cost and implementation difficulty. Effects on representation matter too.
Rule 1.1 Comment 8 also addresses technology competence. Lawyers should understand relevant technology's benefits and risks. The ABA Model Rules remain models. Each jurisdiction controls its adopted rules.
No browser product can preserve privilege by itself. Confidentiality, privilege, and work product are related. They are not interchangeable. Facts and governing law decide the result.
What Shield changes
Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device. Shield is the relevant mode here. It changes the page-execution boundary.
| Question | What Shield changes | What remains |
|---|---|---|
| Where does page code run? | In an isolated browser off your device | The endpoint still needs its own controls |
| Does the page become trustworthy? | Nothing about the site's identity | Verify the destination before acting |
| Can a page receive entered credentials? | Nothing about deliberate input | Yes. Entered data reaches the page |
| What about uploads and downloads? | The page runs off-device | Transferred files cross the isolation boundary |
| Does close erase every record? | The active isolated session ends | Sites and providers may retain separate records |
| Does this establish compliance? | No | The firm applies its facts and governing rules |
The technical boundary guide explains these limits. Credential entry remains credential entry. Copied data crosses the boundary. So do files explicitly saved to your device. Sensitive workflows require separate retention verification.
Where a firm may test it
Unfamiliar links
Start with a non-client link. Shield keeps that page's code away from the daily browser. Staff should still verify the destination. They should not enter credentials into an unverified page.
Outside portals
Court, client, and discovery portals need workflow testing. Confirm sign-in, MFA, uploads, downloads, clipboard behavior, accessibility, and support. Do not assume compatibility from a successful page load.
Research without a returning profile
A fresh session separates research from daily browser state. It does not make research invisible. Websites and search providers may retain records. Networks may retain connection records. The isolation provider may retain operational records.
Off-device execution adds vendor questions
Moving page execution off the endpoint changes one risk. It also places an outside provider in the data path. That tradeoff deserves the same diligence as other legal technology.
California, New York, and North Carolina opinions use fact-specific review. Together, they cover security and provider access. They also cover availability, retrievability, client instructions, and technology changes. None prescribes browser isolation.
- Map every credential, upload, download, and clipboard path.
- Verify session storage, logs, retention, and deletion.
- Ask who can access sessions for support.
- Review hosting locations, subprocessors, and incident terms.
- Confirm failure, recovery, and account-removal behavior.
- Reassess the provider after material changes.
Use Comment 18 as the test
- Classify the information. Identify the matter and sensitivity.
- Describe the threat. Separate link risk from credential and endpoint risk.
- Measure the control. Test what runs, transfers, persists, and fails.
- Count the tradeoffs. Include cost, friction, availability, and client impact.
- Check outside duties. Review client terms, court rules, contracts, and local law.
- Record the decision. State approved uses, prohibited data, owners, and review dates.
A low-data link check may pass quickly. A privileged portal workflow deserves deeper review. The same product can produce different answers under different facts.
Run a controlled pilot
- Choose a non-client page and dummy account.
- Use a managed computer running desktop Chrome.
- Verify the destination before entering anything.
- Test MFA, files, clipboard, and session closure.
- Inspect endpoint records and documented provider retention.
- Write the approved and prohibited workflows.
- Repeat testing after material product changes.
Browser isolation belongs inside layered security. Keep identity and endpoint controls. Keep email defenses, backups, training, and incident response. A VPN changes the route. Shield changes where the page runs. Neither replaces the other controls.
Sources checked
- ABA Model Rule 1.6 and Comment 18
- ABA Rule 1.1 Comment 8
- FBI law-firm alert
- CISA browser-security guidance
- California Formal Opinion 2010-179
- New York Ethics Opinion 842
- North Carolina 2011 Formal Ethics Opinion 6
- Current Legba product boundary
Sources and product claims were last verified September 3, 2026.
Continue the control review
Read the product boundary, accounting guide, and current exposure guidance.
Browser isolation for tax and accounting firms
Browser isolation changes where tax-firm pages run. Review WISP fit, client-data flows, providers, and remaining controls.
How Legba browser isolation works
Shield runs the page in an isolated browser. That browser is off your device. See what happens when you open the tab. See what ends when you close it.
Your Data Is Already Out There: Why Even Security Experts Aren't Safe
24 billion credentials on the dark web. Learn how exposure happens and where isolated page execution changes the risk.
Free for 30 days. No card required.
Test one browser boundary.
Start with a non-client page. Verify credentials, transfers, retention, and firm policy before sensitive work.