ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

A Ten-Question Technology Competence Self-Audit for Firms

Use these ten plain-English questions to test whether your firm could show a thoughtful approach to technology competence if a client or regulator asked.

3 min readBy Counsel Cyber Team

Most discussions of technology competence stop at quoting Comment 8 to ABA Model Rule 1.1, the language noting that lawyers should understand the benefits and risks of relevant technology. That is a fair starting point, but it leaves a managing partner asking the obvious next question: so what do we actually do about it?

One practical answer is a short self-audit. Ten questions, answered honestly once a year, will tell you more about your firm's posture than a long policy manual. You are not looking for perfect scores. You are looking for the places where the honest answer is "I don't know," because that is where risk hides. This article is general information, not legal advice, and your state bar is the authority on what applies to your attorneys.

How to run the audit

Set aside an hour with the managing partner, the firm administrator, and whoever supports your IT. Answer each question as yes, no, or unsure. Write down who owns each "no" or "unsure" and a target date. That written list is the beginning of a defensible record.

The ten questions

1. Do we know where client data lives?

List every system: email, document management, practice management, accounting, shared drives, laptops, phones, scanners and personal cloud accounts someone may have quietly started using. If the list surprises you, that is the finding.

2. Is multi-factor authentication required everywhere it is available?

Email, remote access, practice management, document management and the admin consoles for each. Partners are not exempt.

3. Can we remove a departing employee's access in one day?

Think accounts, devices, shared passwords, mobile email profiles and vendor portals. Ask for the last three departures and check how long it really took.

4. Are our devices encrypted and manageable?

If a laptop is left in a rental car, can you prove the data was encrypted and wipe it remotely?

5. Do we have a backup we have actually restored?

The ABA's discussion of security in Formal Opinion 477R speaks of reasonable efforts. A backup nobody has tested is a hope rather than an effort.

6. Does everyone receive security awareness training?

Short, regular and recorded, including partners and part-time staff.

7. Do we supervise our vendors?

Model Rule 5.3 addresses nonlawyer assistance, and the ABA has discussed outside service providers in that context. Do you know what your IT provider, e-discovery vendor and cloud tools do with your data?

8. Do we have a written incident plan?

ABA Formal Opinion 483 discusses lawyers' obligations after a data breach. A plan naming who decides, who calls the insurer and who contacts clients is far easier to follow at midnight than to invent.

9. Do we know what our clients expect of us?

Many clients now send security questionnaires or include data security terms in outside counsel guidelines. Does someone track those commitments and confirm the firm actually meets them?

10. Who owns technology risk?

One named person, accountable to the partners. If the honest answer is "everyone," it is usually no one.

Scoring yourself

Count your yes answers, but pay more attention to the unsure ones. Unsure means a gap in knowledge, and gaps in knowledge are the cheapest to fix. Convert each into a small task: "Ask IT for a list of accounts without MFA," "Request the last restore test report," "Pull the three most recent offboarding tickets."

Turning findings into a plan

Rank findings by two factors: how likely the problem is to hurt the firm, and how easy it is to fix. Start with the high-impact, easy items. MFA gaps, orphaned accounts and untested backups are usually in that group. Larger projects, such as moving off an aging server, belong on a calendar with a budget.

Keep the record

File the completed audit with the date and attendees. Next year, repeat it and compare. A firm that can show it asked the right questions annually, fixed what it found and documented the work is in a much stronger position than one with a polished policy and no evidence of follow-through.

When to bring in help

Some questions, such as whether a backup is truly recoverable or whether MFA is enforced consistently, require someone to check the systems rather than rely on memory. An outside party can verify what the firm believes to be true.

How Counsel Cyber can help

Counsel Cyber can walk through this audit with your partners and verify the technical answers against your actual systems. We will leave you with a short written list of priorities you can act on.