Model Rule 1.1 requires competent representation. In 2012, the ABA amended Comment 8 to say that, to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. A large majority of states have since adopted some version of that language, though you should confirm your own state's rule.
The comment does not demand that every lawyer become a technologist. It does say that technology is part of competence, and that both the benefits and the risks count. This self-audit helps a firm look honestly at how it is doing. It is not legal advice, and it is not a compliance certification. It is a practical way to find gaps.
How to use this audit
Gather a partner, the firm administrator and whoever manages IT. Go through each section and rate yourselves: in place, partial or missing. Write down actions for anything partial or missing. Revisit annually.
Section 1: Know your technology
- Do we have a current inventory of systems, applications and vendors that hold or process client information?
- Do lawyers understand the tools they use daily, such as email encryption options, document management and e-filing?
- Is someone responsible for tracking technology changes that affect our practice?
- Do we know which AI features are active in our software?
Section 2: Protect client information
Rule 1.6(c) addresses reasonable efforts to prevent unauthorized access to client information, and Opinion 477R describes a risk-based approach.
- Is multi-factor authentication required on email and key systems, without exceptions for senior staff?
- Are laptops and phones encrypted and protected with endpoint security?
- Are patches applied promptly, and unsupported software retired?
- Are backups tested and protected from tampering?
- Do we have secure ways to share files with clients?
- Is access limited to people who need it, and reviewed regularly?
Section 3: Communicate with clients
- Do we know how clients prefer to communicate, and do we discuss risks when relevant?
- Do engagement letters or client communications explain our practices?
- Do we have a procedure for warning clients about wire fraud before closings and settlements?
- Do we know client-specific security requirements, such as outside counsel guidelines?
Section 4: Supervise people and vendors
Rules 5.1 and 5.3 address supervision.
- Are staff trained on security at hire and regularly afterward?
- Are policies written, acknowledged and enforced?
- Do we vet vendors with access to client data and have confidentiality terms in writing?
- Do we oversee our IT provider, with regular reviews and a list of administrative access?
Section 5: Prepare for incidents
Opinion 483 discusses obligations after a breach.
- Do we have a written incident response plan with named roles and contacts?
- Have we practiced it in a tabletop exercise?
- Do we have cyber insurance, and do we know its notice requirements?
- Do we know who would decide on client notification?
- Is logging enabled and retained long enough to investigate?
Section 6: Use AI thoughtfully
Opinion 512 discusses generative AI.
- Do we have a written AI policy and a list of approved tools?
- Do lawyers verify AI output, including citations?
- Do we know client restrictions on AI?
- Have we reviewed the data handling of tools we allow?
Section 7: Remote and mobile practice
Opinion 498 discusses virtual practice.
- Do remote workers use managed devices, secure connections and MFA?
- Do we have guidance on home network security and physical privacy?
- Are video meetings configured securely?
Section 8: Learning
- Do lawyers receive technology and security training, beyond a once-a-year video?
- Do we encourage questions and reporting of mistakes?
- Do we draw on outside resources, such as bar association materials and trusted advisors?
Scoring and acting
Count the items that are missing or partial. There is no passing grade, but patterns are informative. If most gaps cluster in one section, such as incident planning or vendor oversight, begin there. Choose three improvements to complete in the next ninety days, assign owners and dates, and record them.
Document the process
Keep a short record of the audit date, participants, findings and actions. If a client, insurer or disciplinary authority ever asks what you did to keep up with technology, a dated record of regular reviews is useful evidence of reasonable effort.
Humility helps
Competence does not mean having every answer. It can mean knowing when to ask for help. Lawyers have long associated with experts in other fields, and technology is no different. Engaging qualified advisors, while maintaining supervision, is a reasonable approach, but remember that the responsibility remains with the lawyer.
How we help
Counsel Cyber can facilitate this audit with your partners and produce a plain-English report with prioritized actions. If you would like an outside perspective on where your firm stands, we are glad to help.