ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

ABA Formal Opinion 483 in Plain English: After a Data Breach

ABA Formal Opinion 483 discusses lawyers' obligations when they learn of a data breach. Here is a plain-language summary and a firm response checklist.

3 min readBy Counsel Cyber Team

When a law firm discovers or suspects a data breach, panic often competes with procedure. Who needs to know? What do we tell clients? Do we have to? ABA Formal Opinion 483, issued in 2018, addresses lawyers' obligations after an electronic data breach or cyberattack. It is worth understanding in advance, because the middle of an incident is no time to read an ethics opinion for the first time.

This post summarizes the opinion in general terms and translates it into a response checklist. It is not legal advice, and it does not describe your state's rules. Opinions of the ABA are persuasive, not binding, and many states have their own ethics opinions and breach notification statutes. Confirm with your state bar and counsel.

The core ideas in the opinion

In general terms, Opinion 483 discusses several themes.

  • Monitoring. Lawyers should make reasonable efforts to monitor for breaches of client data. The opinion ties this to the duty of competence and to the duty to safeguard confidential information.
  • Stopping and restoring. When a breach is detected, the lawyer should act reasonably and promptly to stop it, mitigate damage and restore systems.
  • Investigating. The lawyer should make reasonable efforts to determine what happened and what information was affected.
  • Informing current clients. Where client confidential information has been compromised, the opinion discusses a duty to notify affected current clients, grounded in Model Rule 1.4 on communication and in the duties of confidentiality.
  • Former clients. The opinion treats former clients differently and notes that notice obligations may arise from other law, such as state breach notification statutes.

The opinion also emphasizes that lawyers should consider preparing an incident response plan in advance.

What "reasonable efforts to monitor" means in practice

The opinion does not specify tools. Practically, the question is whether anyone would notice an intrusion. Firms commonly address this with:

  • Endpoint detection and response with 24/7 monitoring.
  • Alerts on unusual Microsoft 365 sign-ins and forwarding rules.
  • Log retention long enough to investigate.
  • A way for staff to report suspicious activity quickly.

A response checklist

First hours

  1. Contain: isolate affected devices and disable compromised accounts. Do not power off machines unless advised, as volatile evidence may be lost.
  2. Activate the incident plan and name an incident lead.
  3. Notify your cyber insurance carrier according to policy terms.
  4. Engage counsel with breach experience, and consider whether a forensic firm should be retained through counsel.
  5. Preserve logs, emails and images of affected systems.

First days

  1. Determine scope: which systems, which clients, what categories of information.
  2. Identify whether data was accessed, copied or merely exposed.
  3. Evaluate notification obligations under the ethics rules, state statutes and contracts, including client outside counsel guidelines that set deadlines.
  4. Prepare a client communication that is accurate, plain and avoids speculation.
  5. Coordinate with law enforcement as appropriate. The FBI encourages reporting through IC3.

Afterward

  1. Fix the root cause: patching, password resets, MFA, vendor changes.
  2. Document timeline, decisions and communications.
  3. Update training and the incident plan with lessons learned.

What to tell clients

Rule 1.4 emphasizes keeping clients reasonably informed. Clients generally want to know what happened, what information was involved, what the firm is doing and what they should do. Your ethics counsel can help decide timing and wording. Avoid delay driven by embarrassment; clients tend to react more harshly to concealment than to a clear, prompt disclosure.

Prepare before it happens

An incident plan does not have to be long. A usable one fits on a few pages and includes:

  • Names and 24/7 phone numbers for the incident lead, managing partner, IT provider, breach counsel and insurance carrier.
  • A list of critical systems and where data resides.
  • Decision rights on shutting down systems.
  • A template client notice, reviewed by counsel in advance.
  • A reminder to use out-of-band communication if email is compromised.

Run a tabletop exercise once a year. A two-hour discussion exposes more gaps than any document review.

How Counsel Cyber can help

Counsel Cyber provides monitoring and incident response support for law firms and can help you draft and exercise a response plan before you need it. If you would like to start with a review of your current readiness, we are glad to help.