
Every attorney knows the duty of confidentiality. It is one of the most fundamental obligations in the practice of law. But what many law firms are only now coming to grips with is this: confidentiality is no longer just a matter of closing your office door or shredding old files. It is a cybersecurity problem.
And the American Bar Association agrees.
What ABA Model Rule 1.6 Actually Says
Model Rule 1.6 governs the confidentiality of client information. Most attorneys are familiar with the basic principle — you don’t share client information without consent. But in 2012, the ABA amended Rule 1.6 to add a critical paragraph that many firms still haven’t fully acted on.
Rule 1.6(c) states:
“A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.”
The operative phrase is “reasonable efforts.” That language puts the responsibility squarely on the firm to proactively protect client data — not just to avoid intentional disclosure, but to prevent breaches caused by negligence, poor IT practices, or cyberattacks.
The ABA Has Made This Explicit
In Formal Opinion 477R (2017), the ABA Standing Committee on Ethics and Professional Responsibility went further, addressing the specific cybersecurity obligations of lawyers. The opinion acknowledges that:
- Cybersecurity threats to law firms are real and growing
- Lawyers must understand the technology they use well enough to assess the risks
- “Reasonable efforts” depends on factors like the sensitivity of the data, the cost of security measures, and the likelihood of a breach
- Using unencrypted email to transmit highly sensitive client information may not meet the standard
In plain terms: the ABA is saying that bad IT security can be an ethics violation
Why Law Firms Are a Prime Target
Law firms are uniquely attractive to cybercriminals. Here’s why:
You hold the most sensitive data imaginable. M&A details before they go public. Litigation strategy. Criminal defense information. Immigration status. Financial disclosures. This data is extraordinarily valuable — to competitors, foreign governments, and ransomware gangs alike.
You are often less protected than your corporate clients. A Fortune 500 company may have an entire security operations center. The law firm handling their biggest deal might have one overworked IT generalist or a consumer-grade router.
You are a gateway to your clients. Attackers who can’t breach a corporation directly will sometimes target its outside counsel instead. Your inbox is a treasure map.
The FBI, CISA, and major cybersecurity firms have all identified law firms as high-priority targets. The 2016 “Panama Papers” leak — 11.5 million documents from a single law firm — is one of the most dramatic examples of what a breach can look like.
What “Reasonable Efforts” Looks Like in Practice
The ABA has not issued a specific technical checklist, but Formal Opinion 477R and subsequent guidance make clear that the following are baseline expectations for most firms:
1. Encrypted Communications
Unencrypted email may be acceptable for routine correspondence, but sensitive client data — financial records, settlement terms, protected health information, immigration documents — should be transmitted using encrypted channels. This means using encrypted email services, secure client portals, or other protected methods.
2. Multi-Factor Authentication (MFA)
Password theft is the most common way attackers access law firm systems. Enabling MFA on email, document management systems, and remote access tools is now considered a baseline security measure, not an advanced one.
3. Secure Remote Access
The shift to remote work has created enormous risk for firms that allow attorneys to connect to firm systems using personal devices or unsecured home networks. A proper VPN, endpoint security policies, and mobile device management are all components of a reasonable remote access program.
4. Vendor and Cloud Due Diligence
Rule 5.3 requires that lawyers supervise non-attorney staff and service providers. This extends to cloud vendors and technology providers. Before storing client data in a cloud platform, firms should review the vendor’s security practices, data residency, breach notification policies, and contractual protections.
5. Incident Response Planning
The ABA has noted that firms need a plan for what to do when a breach occurs. Lawyers may also have notification obligations — to clients, to state bars, and under applicable data privacy laws — if client data is compromised.
6. Training and Awareness
Phishing attacks are the number one entry point for breaches. A single attorney clicking a malicious link can give attackers access to the entire firm’s network. Regular security awareness training is now considered part of a reasonable security posture.
The Professional Liability Stakes
Non-compliance with Rule 1.6(c) doesn’t just expose your firm to a bar complaint. The downstream consequences can be severe:
- Bar discipline, up to and including suspension or disbarment in egregious cases
- Malpractice liability if a client suffers harm from a breach you failed to prevent
- Loss of client trust — clients are increasingly asking firms to complete cybersecurity questionnaires before retaining them
- Regulatory exposure — firms handling healthcare, financial, or government data face additional federal and state obligations on top of ethics rules
- Ransom and remediation costs — the average cost of a law firm data breach runs into the hundreds of thousands of dollars
State Bars Are Paying Attention
Many state bars have adopted their own cybersecurity guidance, and some have gone further than the ABA model rules. The New York State Bar Association, Florida Bar, and California Bar have all issued formal guidance or ethics opinions requiring attorneys to take specific steps to protect client data in the cloud and via electronic communications. If your firm operates across multiple states, you may be subject to multiple and overlapping obligations.
A Practical Path Forward
If you’re not sure whether your firm’s current IT practices meet the “reasonable efforts” standard, here are five questions to start with:
- Do we have multi-factor authentication on all firm email and remote access?
- When did we last conduct a security risk assessment?
- Do our attorneys use personal devices to access client files, and if so, how are those devices secured?
- Has our cloud storage provider been reviewed for security and compliance?
- Do we have a written incident response plan — and does anyone know where it is?
If the answers to any of these give you pause, your firm may have a gap between your ethics obligations and your current IT posture.
How Data Troop Can Help
We can help your firm close that gap. This includes:
- Conducting a security risk assessment tailored to legal practice
- Implementing and managing MFA, endpoint protection, and secure remote access
- Establishing encrypted communication and secure client portal options
- Providing security awareness training for attorneys and staff
- Developing an incident response plan that addresses both technical recovery and professional notification obligations
- Monitoring your environment around the clock for signs of compromise
The goal isn’t to turn your firm into a technology company. It’s to ensure that your IT environment supports your ethical obligations — so you can focus on practicing law.
The Bottom Line
Cybersecurity is no longer a back-office IT concern for law firms. It is an ethics obligation, a professional liability issue, and increasingly, a competitive differentiator. Clients want to know their most sensitive information is safe. The ABA has made clear that attorneys bear responsibility for making that happen.
The question isn’t whether your firm needs to take cybersecurity seriously. It’s whether you’re doing enough — right now — to meet the standard.
