ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Reasonable Efforts Under Rule 1.6(c): What a Careful Firm Does

Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information. Here is what that can look like in practice.

3 min readBy Counsel Cyber Team

ABA Model Rule 1.6 is best known for confidentiality, the duty not to reveal information relating to the representation of a client. Paragraph (c) adds something that matters directly to IT: a lawyer should make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.

The text does not demand perfection and does not list specific technologies. It uses the word "reasonable," which turns the question into: what would a careful firm of your size, handling your kind of information, be expected to do? This post offers a practical way to approach that question. It is not legal advice, and state rules vary, so confirm how your state has adopted the rule with your state bar.

What the ABA has said about "reasonable"

The comments to Rule 1.6 list factors for judging reasonableness, in general terms: the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost of employing additional safeguards, the difficulty of implementing them and the extent to which safeguards would adversely affect the lawyer's ability to represent clients.

ABA Formal Opinion 477R, on securing communication of protected client information, builds on this. It describes a fact-based, risk-based approach rather than a fixed checklist, and discusses considerations such as understanding the nature of the threat, understanding how client information is transmitted and stored, using reasonable electronic security measures and labeling confidential communications. Opinion 483 later addressed obligations after a breach.

The takeaway is not a magic list. It is a process: assess risk, put sensible safeguards in place, and revisit regularly.

Turning "reasonable" into a working process

1. Know what you have and where it lives

You cannot protect information you cannot locate. Make a simple inventory of where client information sits: file servers, document management, practice management, email, laptops, phones, personal cloud accounts, paper files and backups.

2. Rank sensitivity

Not every matter is equal. A firm that handles medical records, trade secrets, family law matters or high-profile cases should reflect on whether standard safeguards are enough. Identify categories that warrant extra protection.

3. Apply baseline safeguards

Commonly cited baseline measures include:

  • Multi-factor authentication on email and key systems.
  • Encryption of laptops, phones and removable media.
  • Endpoint protection and monitoring.
  • Prompt patching.
  • Secure, tested backups.
  • Email filtering and phishing defenses.
  • Access limited to those who need it.
  • Secure methods for sharing files with clients rather than unprotected attachments.
  • Written policies and regular staff training.

For clients with elevated risk or special instructions, consider additional steps and ask clients what they expect.

4. Document your decisions

Write down what you decided and why, including what you chose not to do because of cost or impracticality. A short risk assessment memo, updated annually, shows that your approach was considered rather than accidental.

5. Review after changes

New software, a new office, a merger, a staff departure or an incident should trigger a reassessment.

Where firms often fall short

  • Staff using personal email or consumer file-sharing for client documents.
  • Shared passwords and no MFA.
  • Lost or stolen laptops without encryption.
  • Old accounts for former employees that stay active.
  • No tested backups.
  • No incident plan, so the first response is improvised.
  • Vendors with access to client data that no one has reviewed.

Communication with clients

Rule 1.4 on communication is often discussed alongside 1.6. Clients may ask how you protect their information, and some outside counsel guidelines impose specific requirements. Consider including a short description of your communication and security practices in engagement letters, and agree on how to exchange sensitive information.

Don't forget people and vendors

Rules 5.1 and 5.3 on supervision connect to safeguards. Partners generally need measures that give reasonable assurance that lawyers and nonlawyer assistants follow the rules, which includes training staff and overseeing vendors.

A simple annual routine

  1. Update the data inventory.
  2. Review the risk assessment and baseline controls.
  3. Test backups and the incident plan.
  4. Train all staff.
  5. Review vendors with access to client data.
  6. Record the results and decisions.

How Counsel Cyber helps

We help law firms translate "reasonable efforts" into specific, documented safeguards that match the firm's size and practice. If you would like a plain-English risk assessment, we can conduct one and give you a written summary.