In 2012 the ABA amended the comments to Model Rule 1.1, the competence rule, to add language that has shaped legal technology conversations ever since. Comment 8 says that to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Many states have adopted similar language, though each state's version and enforcement differ, so confirm what your own bar has said.
For a firm administrator, the practical question is what "keeping abreast" looks like in an office that also has deadlines, billing and clients to manage.
What the comment does and does not say
It does not require every attorney to become an IT expert. It does not name a specific product, control or standard. It asks lawyers to understand the benefits and the risks of the technology they use. That includes cloud storage, email, mobile devices, remote access, e-discovery tools and, increasingly, generative AI.
It also does not shift responsibility entirely to an outside provider. Lawyers can and do rely on qualified help, and Model Rules 5.1 and 5.3 address supervision of lawyers and nonlawyers. But reliance works best when someone at the firm understands enough to ask good questions and to notice when the answers are thin.
Turning the principle into firm practice
Name an owner
Assign one partner or administrator as the technology point person. Their job is not to fix computers. It is to make sure the firm has a plan, asks vendors the right questions and reports to the partners regularly.
Keep an inventory
You cannot assess risk in systems you have not listed. Maintain a simple record of the applications that hold client data, who administers each one, where the data is hosted and how access is controlled.
Build learning into the calendar
Short, regular training beats a single annual lecture. Consider:
- A brief security awareness session for all staff, with periodic phishing simulations.
- A yearly briefing for attorneys on the tools the firm uses and the risks that come with them.
- A quarterly review with your IT provider covering incidents, patches, backups and upcoming changes.
Document decisions
When the firm decides to adopt a cloud platform, allow personal devices or permit remote work, record who evaluated it and what safeguards were chosen. Documentation shows a thoughtful process, which tends to matter if anyone later asks questions.
Where competence shows up in daily work
- Email and file sharing: Do attorneys know when to use encryption or a client portal rather than ordinary email? ABA Formal Opinion 477R discusses reasonable efforts to secure communications and notes that some situations call for added precautions.
- Mobile and remote work: ABA Formal Opinion 498 addresses virtual practice, including securing home networks and devices.
- Third-party vendors: Do you know who has access to client data and under what terms?
- Generative AI: ABA Formal Opinion 512, issued in July 2024, discusses competence, confidentiality, communication, supervision and fees when lawyers use generative AI tools.
Common gaps
- Partners assuming "IT handles it" without asking what "it" covers.
- Unmanaged personal devices holding client email.
- Shadow software: tools adopted by individuals without review.
- No written incident response plan.
- Outdated systems that no longer receive security updates.
A word of caution
This article describes what the ABA has said and general practice. It is not legal advice, and it does not tell you what your own ethical obligations are. Your state bar and your own counsel are the right sources for that.
A simple annual routine
Many firms find it easier to remember a short routine than a principle. Once a year, put three items on a partner meeting agenda: review the application inventory, review any incidents or near misses, and review changes in the tools or guidance the firm relies on. Record the discussion in a few lines of minutes. It takes under an hour and builds the documented habit of staying current that Comment 8 points toward.
How we can help
Counsel Cyber works with law firms in Texas, Arkansas, Louisiana, Oklahoma and Kansas to translate these expectations into concrete controls and plain-English reporting. If you would like a short technology review you can show your partners, we are happy to prepare one.