ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Model Rule 1.1 and Technology Competence: What It Means in Practice

ABA Model Rule 1.1, Comment 8, links competence to technology. See what that has meant for law firms and how to turn it into everyday habits and documentation.

3 min readBy Counsel Cyber Team

In 2012, the ABA amended the comments to Model Rule 1.1 on competence. Comment 8 now says that to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Many states have adopted similar language, though the wording and the date differ, so check your own jurisdiction's rules.

It is a single sentence, but it turned technology from a convenience into part of the professional duty. Here is how firms can think about it in practical terms.

What the comment does and does not say

It does not require every lawyer to become an engineer. It does say that lawyers should understand, at a reasonable level, the benefits and risks of the technology they use in practice, including email, cloud storage, remote work, e-discovery tools, and, increasingly, generative AI. ABA Formal Opinion 512 on generative AI discusses competence directly, including the need to understand a tool's capabilities and limits before relying on it.

Lawyers may also meet the duty by associating with or consulting someone with the needed knowledge. That is where IT providers and security advisors fit, though the lawyer's responsibility stays with the lawyer.

This post is general information and not legal advice. Confirm your state's specific rule and any bar opinions.

Turning "keep abreast" into a routine

A duty that exists only in the abstract tends to be ignored. Concrete habits make it real.

Know your technology map

Keep a one-page inventory of the systems that hold client information: email, document management, practice management, cloud storage, mobile devices, messaging apps, and any AI tools. For each, note who owns it, where data lives, and who has access.

Build a regular learning cadence

  • Schedule a short technology briefing at partner meetings, quarterly or twice a year
  • Use CLE offerings on technology and cybersecurity, which many states encourage or require in some form
  • Assign one person, such as a technology partner or administrator, to track relevant bar opinions and report back

Ask the benefit-and-risk question for every new tool

Before adopting any product, ask:

  1. What problem does this solve?
  2. What client information will it touch?
  3. Where is that information stored and who can access it?
  4. What happens if the vendor is breached or goes out of business?
  5. Can we get our data out?

This quick filter reflects the comment's language about benefits and risks.

Technology competence and security

Competence connects to other rules:

  • Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure or access to client information.
  • ABA Formal Opinion 477R discusses securing communications and says reasonable efforts depend on factors such as the sensitivity of the information and the cost of safeguards.
  • ABA Formal Opinion 498 addresses virtual practice, including secure home networks and devices.
  • Rules 5.1 and 5.3 address supervision of lawyers and nonlawyer assistants.

A firm that cannot say whether its email uses multifactor authentication, or who reviews its vendors, may struggle to show it has taken reasonable steps.

Document what you do

If a client, insurer, or disciplinary authority ever asks, a record helps. Keep:

  • Dates and attendance for technology briefings and trainings
  • Vendor review notes and contract copies
  • Your written security and AI-use policies
  • Records of MFA enforcement, backup tests, and incident drills

You are not trying to create a paper trail for its own sake. You are showing a thoughtful, repeated effort.

Common gaps

  • Attorneys who use personal email or consumer file-sharing for client work because it is faster
  • Partners exempt from MFA or training
  • No one who knows what is in the cloud
  • Staff using AI tools the firm has never reviewed
  • Dependence on a single IT person with no documentation

Small firms are not exempt

A solo or five-attorney firm owes the same duty, though proportionality matters. Opinion 477R recognizes that reasonable efforts vary with circumstances. For a small firm, the practical answer is often a managed provider, a short written policy, and a few well-chosen controls.

How we help

Counsel Cyber works with managing partners and administrators to translate these duties into plain-language checklists, training, and documentation. If you would like a technology competence review that gives you a clear picture of where your firm stands, we are glad to help.