ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Competence in the Digital Age: Habits That Satisfy Comment 8

What ABA Model Rule 1.1, Comment 8 says about technology competence, and how law firms can turn it into practical habits for email, cloud and device use.

3 min readBy Counsel Cyber Team

In 2012 the ABA amended the comments to Model Rule 1.1 on competence. Comment 8 now says that, to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Many states have adopted some version of that language, though wording and the details differ. Confirm with your own state bar how your jurisdiction handles it.

The comment is short, but it affects daily operations. This post looks at how a firm can translate it into habits that are easy to explain and easy to show.

What the comment does and does not say

It does not require every lawyer to become a technician. It points to two ideas: understanding the benefits and risks of the tools you use, and keeping that understanding current. In practice, that means a lawyer using cloud storage, email, e-signature tools or generative AI should know in general terms how those tools handle client data, and should know when to ask for help.

Competence can also be met by associating with someone who has the expertise. The ABA has discussed reliance on qualified vendors, together with the supervision duties found in Rules 5.1 and 5.3. Delegation does not remove responsibility, so oversight matters.

Where it shows up day to day

Email

Email is where confidential information travels most often. Questions worth asking: Is email encrypted in transit? Do staff know when sensitive attachments warrant extra protection? ABA Formal Opinion 477R discusses securing communications and describes a risk-based approach, noting that some situations call for additional safeguards. It does not impose one rule for every message.

Cloud storage and practice-management software

Before putting client files in a cloud tool, a firm should understand where data is stored, who can access it, how it is backed up, and what happens if the account is closed. Ask the vendor for security documentation and read the terms covering data ownership and breach notification.

Devices and remote work

ABA Formal Opinion 498 addresses virtual practice, including securing home networks, devices and conversations. Attorneys who work from home or on the road should use managed devices, screen locks, and secure Wi-Fi or a VPN, and should avoid sharing devices with family members.

Generative AI

ABA Formal Opinion 512, issued in July 2024, discusses lawyers' use of generative AI tools, including competence, confidentiality, communication and supervision. At a minimum, a firm should decide which tools are approved and what information may be entered into them.

Turning competence into a program

A written policy is less useful than a repeatable routine. Consider these steps.

  1. Inventory your technology. List the systems that touch client data, who administers them, and who the vendor is.
  2. Assign an owner. Someone, whether a partner, administrator or outside provider, should be accountable for security decisions.
  3. Train on a schedule. Short, regular security awareness sessions beat an annual lecture. Include phishing, wire-fraud warning signs and safe use of AI tools.
  4. Review vendors. Gather security documentation and revisit it when contracts renew.
  5. Document decisions. A short memo showing that the firm considered risks and chose safeguards is valuable if a client, insurer or regulator asks.
  6. Test. Run phishing simulations and restore tests, and record the results.

Questions to ask this quarter

  • Can every attorney explain where client files are stored and who can access them?
  • Do we use multi-factor authentication on email and practice-management systems?
  • Have we verified that our backups can be restored?
  • Do we have a plan for notifying clients if their information is compromised? ABA Formal Opinion 483 discusses lawyers' obligations after a data breach, and Rule 1.4 covers communication with clients.
  • Does everyone know which AI tools are permitted?

A word on proportion

A solo practitioner and a 100-lawyer firm will not look the same, and the ABA's guidance emphasizes reasonable efforts rather than perfection. What matters is that the firm has thought about the risks and acted in proportion to them.

Counsel Cyber supports law firms by turning these questions into a practical checklist and by providing documentation firms can keep on file. If you would like help assessing where your firm stands, we can start with a short conversation and a review of your current safeguards.