ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Model Rule 1.4 and Cyber Incidents: What Clients Should Hear

How the duty to communicate under Model Rule 1.4 applies when a cyber incident touches client data, and how to prepare clear, timely client notices.

3 min readBy Counsel Cyber Team

When a firm discovers that client information may have been exposed, the technical response gets most of the attention: contain the threat, restore systems, find the cause. The communication response can matter just as much to the client relationship, and to the firm's ethical position.

Model Rule 1.4 addresses a lawyer's duty to keep clients reasonably informed, to explain matters to the extent reasonably necessary for informed decisions and to consult about the means of achieving objectives. ABA Formal Opinion 483, on lawyers' obligations after a data breach, connects this duty to incidents affecting client information. This article is general information, not legal advice. Your state's rules, breach-notification statutes and client contracts may impose different or additional duties, so consult counsel.

Why Communication Is Hard in an Incident

Facts are incomplete, the investigation is ongoing and there is pressure to say nothing until everything is clear. At the same time, delay can harm clients who could take protective steps, and silence erodes trust. Preparing the communication framework before an incident makes it possible to be both careful and timely.

Who Needs to Hear What

Current clients whose information was involved

Opinion 483 discusses a duty to notify current clients when a breach involves material confidential client information. The notice should generally allow the client to understand what happened and make decisions to protect itself.

Clients not affected

Not every client needs the same message. Consider whether a general communication is appropriate for the rest, especially if news of the event may become public.

Former clients

The opinion treats former clients differently from current ones, with notice questions often governed by other law. Ask counsel how to handle them.

Others with their own deadlines

State attorneys general or other regulators, individuals whose personal data was exposed, insurers, banks and law enforcement may each have different timing. Many contracts and cyber-insurance policies set short notice windows.

What a Good Client Notice Includes

Think of the questions a client would ask in your place.

  1. What happened? A plain, factual description, without technical jargon or speculation.
  2. What information was involved? Be specific about categories, such as documents, email or personal identifiers, to the extent known.
  3. When did it happen, and when did we discover it?
  4. What are we doing about it? Containment, investigation, forensic help and improvements.
  5. What can the client do? Password changes, monitoring, notifying their own insurers or counterparties.
  6. Who can they call? A named contact and a way to reach them.
  7. What do we not yet know? Say so, and promise updates.

Tone

Be direct and respectful. Avoid minimizing language and avoid legal defensiveness that reads as evasion. Do not speculate about who was responsible or promise outcomes you cannot guarantee.

Process Before Publication

  • Have breach counsel review notices before they go out.
  • Coordinate with your insurer, which may have requirements for how notices are handled.
  • Verify facts with the forensic investigator, and avoid statements the investigation has not confirmed.
  • Make sure the person making calls to clients has a script and current facts.

Avoid New Risks While Communicating

If email may be compromised, do not use it to discuss the incident with clients. Use phone calls or a verified alternative channel. Attackers sometimes monitor mailboxes and exploit chaotic periods to send fake "update" messages with malicious links.

Prepare Now

Create a notice template library

Keep templates for initial notice, follow-up updates and closure, with placeholders and a record of counsel's review.

Maintain a current client contact list

Store it somewhere accessible when systems are down, including key contacts at each client and any contractual notification requirements.

Review engagement letters and outside counsel guidelines

Note commitments about security and incident notice. A client guideline might require notice within a stated period of discovery, and you need to know that in advance.

Assign communication roles

Decide who leads client communication, who handles press or public inquiries and who documents what was said and when.

Keep Records

Document what you knew, when you knew it and what you told whom. Contemporaneous notes are useful if questions arise later.

Learn From It

After an incident, hold a debrief. What did clients ask? What surprised them? Update your templates and your plan.

Counsel Cyber supports law firms in incident preparation and response, including building notice workflows and contact lists in advance. If you would like help drafting yours with your counsel, we can assist.