ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Remote Work and ABA Opinion 498: A Security Checklist for Firms

ABA Formal Opinion 498 addresses virtual practice. Use this checklist to secure home offices, personal devices and remote conversations for lawyers and staff.

3 min readBy Counsel Cyber Team

Remote and hybrid work is now a normal part of legal practice. Lawyers draft at home, join hearings from hotel rooms and answer client calls from wherever they happen to be. ABA Formal Opinion 498, issued in 2021, addresses what the ABA calls virtual practice, and discusses how Model Rules on competence, confidentiality, communication and supervision apply when lawyers work outside a traditional office.

This checklist translates the opinion's themes into practical controls. It is general information, not legal advice, so confirm requirements with your state bar.

What the Opinion Addresses

In broad terms, Opinion 498 discusses:

  • Competence in using technology for remote work, tying back to Rule 1.1 and its Comment 8.
  • Confidentiality and reasonable safeguards under Rule 1.6(c), including securing home networks and devices.
  • Communication with clients about how the firm works remotely, under Rule 1.4.
  • Supervision of lawyers and nonlawyers working remotely, under Rules 5.1 and 5.3.

It does not mandate specific products. It encourages reasonable steps appropriate to the circumstances.

The Home Network

  • Change the default router administrator password and use a current encryption standard for Wi-Fi, such as WPA2 or WPA3.
  • Keep router firmware updated, and replace routers that are no longer supported.
  • Use a separate network or guest network for smart home gadgets where possible.
  • Provide guidance for staff who are not technical, ideally with a short setup guide or support session.

Devices

  • Firm-managed laptops with full-disk encryption, automatic updates and endpoint protection.
  • A clear policy for personal devices. If allowed, require management software or restrict access to browser-based sessions, and prohibit saving client files locally.
  • Screen locks with short timeouts.
  • Remote wipe capability for lost or stolen devices.
  • Separate user accounts so family members cannot use work devices.

Remote Access and Authentication

  • Multi-factor authentication for every remote login.
  • A secure remote access method, such as a managed virtual desktop or VPN, rather than exposing remote desktop services to the internet.
  • Conditional access rules that block sign-ins from unexpected countries or unmanaged devices.
  • A password manager for all staff.

Conversations and Meetings

Remote work creates privacy risks that are easy to overlook:

  1. Use headphones, and take calls in a room where others cannot overhear.
  2. Be aware of smart speakers and virtual assistants that may listen in the background.
  3. Use firm-approved conferencing tools with passcodes or waiting rooms.
  4. Verify who is on the call before discussing confidential matters.
  5. Be careful with screen sharing, so other windows or notifications do not appear.

Paper and Printing

Home printers and stray printouts are a forgotten weak spot. Decide whether staff may print client documents at home. If so, require secure storage and shredding, or prohibit it. Remember that cloud printing services may route data through third parties.

Public and Travel Settings

Avoid public Wi-Fi without a secure connection. Do not leave devices unattended in cars or hotel rooms. Use privacy screens in public spaces.

Communication With Clients

Opinion 498 touches on the value of telling clients about how the firm communicates. Consider adding a short statement to engagement letters about remote work and how you protect information, and offer secure alternatives for especially sensitive matters.

Supervision

Rules 5.1 and 5.3 address supervising lawyers and staff. For remote teams, that means documented policies, training, regular check-ins and clear expectations about devices and workspaces. Spot checks, such as verifying encryption status, are easy and informative.

A Short Policy Outline

  • Scope and definitions.
  • Approved devices and software.
  • Network and workspace requirements.
  • Handling paper and printing.
  • Incident reporting, including lost devices.
  • Acknowledgment signature.

Review Regularly

Remote practice settings change as staff move, devices age and tools update. Review the policy annually and after any incident.

How Counsel Cyber Helps

Counsel Cyber secures remote and hybrid firms with managed devices, remote access, conditional access and staff training. If you would like a quick assessment of how your remote setup stacks up against this checklist, we are glad to help.