In 2012 the ABA amended the comments to Model Rule 1.1, the competence rule, to add language about technology. Comment 8 says that to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Many states have since adopted a version of that language, though the specifics vary. Confirm how your own state bar treats it.
For firm leaders, the practical question is not what the comment says but what it looks like when a firm takes it seriously.
What the Comment Does and Does Not Say
It does not require every lawyer to become a systems engineer. It does not prescribe particular tools. It does say that understanding the risks of technology, not only the benefits, is part of competent practice. That includes how client data is stored and transmitted, how email is secured, how cloud services are chosen, and what happens when something goes wrong.
Other rules interact with it:
- Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of, or access to, client information.
- Rule 1.4 concerns communication with clients, which can matter after an incident.
- Rules 5.1 and 5.3 address supervisory responsibility for lawyers and nonlawyer assistants, including outside technology vendors.
- ABA Formal Opinion 477R discusses securing communications with clients and the idea that reasonable precautions depend on the sensitivity of the information and the risk.
- ABA Formal Opinion 483 discusses a lawyer's obligations after a data breach.
The common thread is reasonableness. The ABA has not said that a particular product or checklist is required; it has said that lawyers should make reasonable, informed decisions.
What Reasonable Attention Can Look Like
Know what technology your firm uses
Keep a current inventory of the systems that hold client information: email, practice management, document management, billing, file sharing, phone and messaging tools, and any AI tools staff use. If the managing partner cannot name them, nobody is making informed decisions about them.
Understand the main risks
You do not need deep technical expertise, but someone in leadership should be able to explain in plain terms how phishing leads to account takeover, why wire instructions get spoofed, and what ransomware does to a firm that has no tested backup.
Make deliberate choices about vendors
Before adopting a cloud service, ask where data is stored, who can access it, how it is encrypted, and what happens to your data if you stop using the service. Put the answers in writing.
Train people
Competence is organizational as well as individual. Regular security awareness training for attorneys and staff, with short refreshers and realistic examples, is one of the most direct ways to show that the firm is managing technology risk.
Write policies and use them
A written information security policy, an acceptable use policy, and an incident response plan are baseline documents. Their value comes from being read, understood and occasionally tested.
Review periodically
Technology and threats change. Set a calendar reminder to review your tools, access rights and policies at least annually, and after any significant change.
Common Gaps
- Partners who exempt themselves from MFA or training
- Personal email or consumer file-sharing apps used for client matters
- No inventory of cloud accounts staff have signed up for
- Old laptops or servers no longer receiving security updates
- No plan for who speaks to clients and when after an incident
Documenting Your Efforts
If a client, insurer or disciplinary authority ever asks what your firm did to meet its obligations, evidence helps. Keep training logs, policy versions with dates, vendor review notes, backup test records, and the results of security assessments. This is not legal advice; ask your state bar or ethics counsel how your jurisdiction views these duties.
Making It Manageable
Start small: inventory, MFA everywhere, training, tested backups, and a written incident plan. Then add layers as the firm grows.
Counsel Cyber works with law firms to turn these obligations into specific, affordable steps, and can provide documentation you can point to when clients or carriers ask. If you want a starting point, we offer a security review written for firm leadership.