ABA Formal Opinion 483, issued in 2018, addresses a question every firm hopes never to face: what must a lawyer do after learning of a data breach or cyberattack? The opinion applies the Model Rules to that situation and has become a common reference point for firms building incident response plans. This post summarizes its main themes in plain English.
This is not legal advice. Opinions of the ABA are persuasive and not binding, state rules differ, and state breach-notification statutes may apply in addition. Confirm the requirements for your jurisdiction with your state bar and counsel.
The core ideas
Duty to monitor
The opinion discusses that lawyers have an obligation to make reasonable efforts to monitor for breaches of client data, consistent with competence under Rule 1.1 and the duty of confidentiality under Rule 1.6. In practice, that means having some way to detect incidents, such as endpoint monitoring and log review, rather than relying on chance.
Duty to stop and restore
After a breach is detected, the opinion points to the need to act promptly to stop the breach and mitigate damage. It also discusses restoring computer operations, and conducting a reasonable investigation, sometimes with the help of forensic experts, to determine what happened.
Duty to notify current clients
The opinion concludes that when a breach involves material client confidential information, Rule 1.4 requires the lawyer to notify affected current clients. It describes the notice as needing to give clients enough information to make informed decisions, including what happened and what information was involved, in a timely way. It also discusses that lawyers need not disclose information they have not yet confirmed, but should provide reasonable, accurate information as the investigation develops.
Former clients
The opinion notes that the Model Rules do not themselves require notice to former clients, though other law, such as state breach statutes or contractual obligations, may.
Why this changes how firms prepare
If notification is required, a firm must be able to answer basic questions quickly: whose data was involved, which systems, and when. That depends on preparation.
- Know where client data lives. Maintain a system inventory and a way to tie data to matters.
- Keep logs. Without logs, you may be unable to say what was accessed.
- Use encryption. Some state statutes treat encrypted data differently, and encryption can reduce the likelihood that information is usable.
- Have contacts ready. Keep incident response and breach counsel details at hand.
- Know your insurance requirements. Policies commonly require early notice.
A practical post-breach checklist
- Contain. Isolate affected systems and accounts without destroying evidence.
- Activate your plan. Notify your IT provider, counsel and insurance carrier.
- Investigate. Determine what was accessed, for how long and how. Use forensic help for anything serious.
- Assess the data. Identify the clients and categories of information involved.
- Evaluate notification duties. Consider Rule 1.4, state breach notification statutes, client contracts and outside counsel guidelines, any of which may impose deadlines.
- Notify clients. Communicate promptly, honestly and in plain language, explaining what happened, what was involved, what the firm is doing and what the client can do.
- Remediate. Fix the root cause, strengthen controls and document changes.
- Review. Hold a post-incident review and update the plan.
Communicating with clients
Clients react best to candor. A good notice avoids technical jargon, avoids speculation, states what is known and not yet known, explains protective steps, and offers a point of contact. Consider whether a call from a partner should precede or accompany a written notice for key clients. Have the notice reviewed by counsel, because statements can affect liability and privilege.
Privilege and the investigation
Ask counsel how to structure the forensic investigation so that findings are protected as far as possible, for example by engaging the forensic firm through counsel. Practices vary, so get advice early.
Common mistakes
- Waiting for certainty before telling anyone
- Deleting logs or wiping systems before preserving evidence
- Failing to check client contracts that set shorter notice deadlines
- Sending a vague or misleading notice
- Skipping the lessons-learned review
Build the plan before you need it
A written plan shortens response time, and rehearsing it through a tabletop exercise reveals weak spots. Include a notification decision tree and draft templates for client communications.
Counsel Cyber helps law firms prepare incident response plans consistent with these themes, including logging, contacts and notification templates reviewed by your counsel. If you would like to rehearse a breach scenario, we can run a tabletop exercise with your partners.