Table of Contents
The Duty You May Not Know You Have
Most conversations about law firm cybersecurity start in the wrong place — with a product. A firewall, an antivirus subscription, an encryption tool. The better starting point is the obligation, because the obligation is what a disciplinary body, a malpractice carrier, or a client’s general counsel will actually measure you against.
The foundational one is not a security rule at all. It is the competence rule. In 2012 the ABA amended Comment [8] to Model Rule 1.1 to read:
“To maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology, engage in continuing study and education and comply with all continuing legal education requirements to which the lawyer is subject.” [1] ABA Model Rules of Professional Conduct Rule 1.1: Competence — Comment View source ↗
Twelve words in the middle of that sentence — including the benefits and risks associated with relevant technology — converted technology from an administrative concern into an ethical one. Competence is no longer only about knowing the law. It includes understanding the tools you use to practice it.
This is not confined to the model rules. Tracking by LawSites puts adoption at 40 states plus the District of Columbia and Puerto Rico, including Illinois. [7] LawSites (Robert Ambrogi) Tech Competence — tracker of jurisdictions adopting the duty of technology competence View source ↗ Adoption is not uniform, though: some jurisdictions took the ABA language verbatim, others adopted a modified or narrower version. Your own state’s rule is the one that binds you, and it is worth reading rather than assuming.
Why this matters before any product discussion
The competence duty is what makes every obligation below enforceable against a lawyer rather than against an IT department. You cannot delegate the duty. You can — and generally should — delegate the work.
Rule 1.6(c) and What “Reasonable Efforts” Means
The operative security provision was added in the same 2012 amendments. Model Rule 1.6(c) states:
“A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.” [2] ABA Model Rules of Professional Conduct Rule 1.6: Confidentiality of Information View source ↗
Two features of that sentence deserve attention.
First, it reaches unauthorized access, not just disclosure. A ransomware operator who exfiltrates a matter folder has accessed client information even if nothing is ever published. The obligation is engaged at the intrusion, not at the leak.
Second, it is a reasonable efforts standard, not a guarantee. This is the part firms most often misread, in both directions — some assume any breach is automatically an ethical violation, others assume the standard is so soft it means nothing. Neither is right. The comments to the rule establish that a breach is not itself a violation where reasonable efforts were made, and set out the factors that determine what is reasonable: [2] ABA Model Rules of Professional Conduct Rule 1.6: Confidentiality of Information View source ↗
- the sensitivity of the information;
- the likelihood of disclosure if additional safeguards are not employed;
- the cost of employing additional safeguards;
- the difficulty of implementing the safeguards; and
- the extent to which the safeguards adversely affect the lawyer’s ability to represent clients.
The standard is sliding, not fixed
Read those five factors together and a structure emerges. Cost and difficulty are genuine defenses — a two-attorney firm is not held to the control set of an AmLaw 100 firm. But they are weighed against sensitivity and likelihood. As the sensitivity of a matter rises, the cost you are expected to absorb rises with it.
The practical consequence: “we couldn’t afford it” is an argument that gets weaker every year, because the cost of the baseline controls keeps falling. Multi-factor authentication was once a project. It is now a setting.
Note also the breadth of what is protected. Rule 1.6 covers “information relating to the representation of a client” — considerably wider than privileged communications or work product. Client lists, billing records, calendar entries, and the mere fact of a representation can all fall inside it.
Formal Opinion 477R: How You Communicate
In May 2017 the ABA’s ethics committee applied Rule 1.6(c) to electronic communications, superseding a 1999 opinion that had broadly blessed unencrypted email. [3] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 477R: Securing Communication of Protected Client Information (May 22, 2017) View source ↗
The headline holding is reassuring: “the use of unencrypted routine email generally remains an acceptable method of lawyer-client communication.” [3] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 477R: Securing Communication of Protected Client Information (May 22, 2017) View source ↗ Firms sometimes stop reading there. The sentence that follows is the one that matters:
“[C]yber-threats and the proliferation of electronic communications devices have changed the landscape and it is not always reasonable to rely on the use of unencrypted email.” [3] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 477R: Securing Communication of Protected Client Information (May 22, 2017) View source ↗
The opinion declines to issue a universal rule, holding instead that “what constitutes reasonable efforts is not susceptible to a hard and fast rule, but rather is contingent upon a set of factors.” [3] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 477R: Securing Communication of Protected Client Information (May 22, 2017) View source ↗ It states that “particularly strong protective measures, like encryption, are warranted in some circumstances” [3] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 477R: Securing Communication of Protected Client Information (May 22, 2017) View source ↗ — where a client agreement or a law requires it, or where the sensitivity of the information demands it.
In practice this means the analysis is per-matter, not per-firm. A scheduling email and a draft merger agreement do not warrant the same handling, and a firm whose only answer is “we use email” has not performed the analysis the opinion contemplates. Where a matter is sensitive enough that ordinary methods are inadequate, the opinion directs the lawyer to discuss it with the client and agree on an approach — a Rule 1.4 communication obligation sitting on top of the Rule 1.6 security one. [6] ABA Model Rules of Professional Conduct Rule 1.4: Communications View source ↗
A workable way to operationalize this
Most firms cannot run a fresh security analysis for every email, and the opinion does not ask them to. What works is tiering: define two or three sensitivity levels, decide in advance which transport each one gets (ordinary email, encrypted mail, or a client portal), and write the tiers into your engagement letter so the client has agreed to them at the outset. That converts a per-message judgment into a per-matter one made once.
Formal Opinion 483: What Happens After a Breach
In October 2018 the committee turned to the aftermath, addressing lawyers’ obligations following an electronic data breach or cyberattack. [4] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack (October 17, 2018) View source ↗ This is the opinion that most directly shapes what a firm’s IT environment must be able to do, as opposed to what it must prevent.
The opinion frames a data breach broadly: an event involving the misappropriation, destruction, or compromise of client confidential information, or one where a lawyer’s ability to perform the legal services for which the lawyer was hired is significantly impaired. [4] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack (October 17, 2018) View source ↗ That second limb is easy to overlook and important — a ransomware event that encrypts your document management system but exfiltrates nothing still qualifies.
On response, the opinion holds that when a breach of protected client information is suspected or detected, Rule 1.1 “requires that the lawyer act reasonably and promptly to stop the breach and mitigate damage resulting from the breach.” [4] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack (October 17, 2018) View source ↗
On notification, it holds that lawyers have a duty to notify clients of a data breach under Model Rule 1.4 “in sufficient detail to keep clients ‘reasonably informed’” and with an explanation “to the extent necessary to permit the client to make informed decisions regarding the representation.” [4] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack (October 17, 2018) View source ↗ The obligation continues past the initial disclosure — clients must be kept apprised of material developments in the post-breach investigation. [4] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack (October 17, 2018) View source ↗
The detection duty is the one with real IT consequences
Opinion 483 contemplates an ethical violation where lawyers fail to employ reasonable efforts to avoid data loss or to detect a cyber-intrusion, and that failure causes a breach. [4] ABA Standing Committee on Ethics and Professional Responsibility Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack (October 17, 2018) View source ↗
Read that against the notification duty and a hard requirement falls out. You cannot notify a client of a breach you never detected, and you cannot describe it “in sufficient detail” without records of what happened. That is a technical capability, not a policy: centralized logging, retention of those logs long enough to investigate, alerting that reaches a human, and enough endpoint and identity telemetry to reconstruct which matters were touched.
A firm with strong preventive controls and no detection capability can satisfy Rule 1.6(c) and still fail Opinion 483 — because it has no way to know whether it needs to pick up the phone.
You Are Responsible for Your Vendors
Firms frequently assume that outsourcing IT outsources the obligation. It does not. Model Rule 5.3 governs a lawyer’s responsibilities regarding nonlawyer assistance, and its comments were amended in the same 2012 package to address service providers outside the firm.
The comment expressly contemplates the arrangements a modern firm actually uses — retaining an investigative or paraprofessional service, engaging a document management company for complex litigation, sending client documents to a third party for printing or scanning, and using an internet-based service to store client information. [5] ABA Model Rules of Professional Conduct Rule 5.3: Responsibilities Regarding Nonlawyer Assistance — Comment View source ↗ Where a lawyer uses such services, the lawyer must make reasonable efforts to ensure that the services are provided in a manner compatible with the lawyer’s own professional obligations. [5] ABA Model Rules of Professional Conduct Rule 5.3: Responsibilities Regarding Nonlawyer Assistance — Comment View source ↗
Practically, that means your cloud provider, your document management platform, your e-discovery vendor, and your managed IT provider are all inside your ethical perimeter. Choosing one is a diligence exercise, and the diligence should leave a record: what you asked, what they showed you, and what the contract says about confidentiality, breach notification timing, and data location.
Two questions worth asking any provider
1. What independent assurance can you show me? A current SOC 2 Type II report is the common answer. Ask for the report itself, not a badge on a website, and read the exceptions.
2. How quickly will you tell me, and what will you tell me? Your notification clock under Opinion 483 starts when you learn of a breach. If your provider’s contract lets them take weeks to inform you, they have quietly transferred their delay onto your ethical obligation.
Obligations Mapped to Controls
The rules are deliberately technology-neutral, which is why they have aged well — and why they offer no shopping list. The mapping below is ours, not the ABA’s. It reflects what we see satisfy client security questionnaires and insurer applications for firms in the 10 to 250 seat range.
| Obligation | Source | Controls that evidence it |
|---|---|---|
| Prevent unauthorized access | Rule 1.6(c) | Multi-factor authentication on every account without exception; conditional access; least-privilege permissions reviewed on a schedule; prompt offboarding |
| Protect information at rest and in transit | Rule 1.6(c); Op. 477R | Full-disk encryption on all endpoints; encryption in the document platform; TLS enforcement; a defined secure-transport tier for sensitive matters |
| Match method to sensitivity | Op. 477R; Rule 1.4 | Written sensitivity tiers; client portal for high-sensitivity exchange; engagement-letter language recording the agreed method |
| Detect intrusions | Op. 483 | Managed detection and response; centralized log collection with defined retention; alerting routed to a monitored queue; identity-based anomaly detection |
| Stop and mitigate promptly | Op. 483; Rule 1.1 | Written incident response plan naming decision-makers; isolation capability; tested backups with a proven restore, not merely a green backup report |
| Notify with sufficient detail | Op. 483; Rule 1.4 | Forensic readiness — the ability to determine which matters and which clients were affected; a pre-drafted notification workflow; counsel and carrier contacts on file |
| Supervise providers | Rules 5.1, 5.3 | Vendor inventory; current SOC 2 Type II or equivalent on file; contractual breach-notification timelines; documented diligence at selection and on renewal |
| Maintain competence | Rule 1.1, Cmt. 8 | Recurring staff security awareness training with completion records; a written technology and acceptable-use policy that is actually reviewed |
One theme runs through the right-hand column: nearly every entry produces an artifact. A policy document, a training completion record, a restore test result, a vendor’s SOC 2 report, a log retention setting. That is not accidental. “Reasonable efforts” is a standard you have to be able to demonstrate after the fact, frequently to someone who is skeptical and working from hindsight. Controls that leave no evidence are worth less than controls that do.
Where DP3 Fits
We work exclusively with law firms and professional services organizations in Chicago and New York, which means these obligations are the frame we design environments around rather than a compliance exercise bolted on afterward. Our broader treatment of the subject lives on our IT compliance for law firms page, and the specific controls we run are described under security.
If your firm is responding to a client security questionnaire, renewing cyber liability coverage, or simply trying to establish whether “reasonable efforts” describes your current environment, that is a conversation worth having before an incident rather than during one.
The firms that handle this well are rarely the ones that spent the most. They are the ones that decided what they owed their clients, wrote it down, and can show their work.
Contact us to review your firm’s security posture
References
- [1] American Bar Association, "Rule 1.1: Competence — Comment," Model Rules of Professional Conduct. Accessed August 6, 2026. Link
- [2] American Bar Association, "Rule 1.6: Confidentiality of Information," Model Rules of Professional Conduct. Accessed August 6, 2026. Link
- [3] ABA Standing Committee on Ethics and Professional Responsibility, "Formal Opinion 477R: Securing Communication of Protected Client Information," May 22, 2017. Link
- [4] ABA Standing Committee on Ethics and Professional Responsibility, "Formal Opinion 483: Lawyers' Obligations After an Electronic Data Breach or Cyberattack," October 17, 2018. Link
- [5] American Bar Association, "Rule 5.3: Responsibilities Regarding Nonlawyer Assistance — Comment," Model Rules of Professional Conduct. Accessed August 6, 2026. Link
- [6] American Bar Association, "Rule 1.4: Communications," Model Rules of Professional Conduct. Accessed August 6, 2026. Link
- [7] Robert Ambrogi, "Tech Competence," LawSites — tracker of jurisdictions adopting the duty of technology competence. Accessed August 6, 2026. Link
This article is provided for informational purposes by DP3. It is not legal advice, and DP3 does not practice law. The ABA Model Rules are not binding of their own force — each jurisdiction adopts, modifies, or declines to adopt them, and the rules and opinions of your licensing jurisdiction govern. Firms should consult ethics counsel regarding their specific obligations. The control mapping in this article represents DP3’s professional judgment, not ABA guidance.