No firm plans to suffer a breach, but every firm should know what it will need to do if it does. ABA Formal Opinion 483, "Lawyers' Obligations After an Electronic Data Breach or Cyberattack," issued in 2018, addresses that question. It explains how existing Model Rules apply when a lawyer's systems are compromised.
This post summarizes the opinion in plain English. It describes what the ABA has said, not what your state requires, and it is not legal advice. State bar opinions, state breach notification statutes and client contracts may add obligations, so involve counsel early.
The rules the opinion draws on
Opinion 483 relies on several Model Rules:
- Rule 1.1 (competence), including Comment 8 on technology, which supports a duty to understand the risks of the tools a lawyer uses
- Rule 1.4 (communication), which addresses keeping clients reasonably informed
- Rule 1.6 (confidentiality), including 1.6(c) on reasonable efforts to prevent unauthorized access
- Rules 5.1 and 5.3 (supervision), which address responsibility for lawyers and nonlawyers, including vendors
Before a breach: preparation
The opinion discusses an obligation to make reasonable efforts to monitor for breaches, and notes that a lawyer must act reasonably to detect them. It also encourages preparation, including an incident response plan. In practice, that means:
- Logging and alerting that would reveal unauthorized access
- Endpoint and email protections
- A written incident response plan with named roles
- Relationships ready in advance with forensics, breach counsel and your insurance carrier
A firm that learns of a breach months late has a harder time showing reasonable efforts.
When a breach is suspected
Opinion 483 describes steps once a lawyer discovers or reasonably suspects an incident:
- Act promptly to stop the breach and mitigate damage. Contain systems, change credentials, and restore from backups where appropriate.
- Investigate. The lawyer should make reasonable efforts to determine what occurred, including what systems and information were affected. The ABA recognizes that the full picture may take time, and that firms often need forensic help.
- Preserve evidence. Do not wipe systems prematurely.
Notice to clients
The opinion explains that Rule 1.4 may require notifying a current client when a breach involves material client confidential information. It generally concerns disclosure of information to unauthorized parties, or the loss of access to information the client needs. The notice should give enough information for the client to make informed decisions, and should be made promptly. The opinion also discusses that former clients are treated differently under the Model Rules, and that other laws may apply to them. Because notification triggers differ and depend on facts, legal counsel should guide each decision.
What a notice often covers
- What happened, in plain language and as known so far
- What information may have been involved
- What the firm is doing in response
- What the client can do to protect itself
- A contact person for questions
Practical steps to take now
- Write the plan. Include contact lists, decision authority, communication templates and system priorities.
- Know your insurance requirements. Many policies require prompt notice and use of panel vendors.
- Identify state laws. Breach notification statutes vary across Texas, Arkansas, Louisiana, Oklahoma, Kansas and other states. Counsel can map them.
- Check client agreements. Outside counsel guidelines may set notification deadlines shorter than statutes.
- Rehearse. A tabletop exercise exposes gaps before they matter.
- Preserve logs. Make sure you retain logs long enough to investigate. A short retention window can hide the evidence you need.
Common mistakes
- Waiting to notify until every detail is known
- Notifying without legal review
- Letting different partners give clients different stories
- Neglecting vendors, whose breaches can become your breaches
- Treating an incident purely as an IT problem
The bigger picture
Opinion 483 reinforces the notion that security is part of competent representation. It does not mandate specific technology, but it expects reasonable preparation, prompt action and honest communication. Confirm how your state applies these ideas with your bar and counsel.
How we help
Counsel Cyber helps law firms write incident response plans, rehearse them and respond when something goes wrong. If your plan has not been reviewed recently, we can walk through it with you and your insurance and counsel contacts.