No firm wants to imagine a data incident leading to a bar inquiry or a client complaint. But the quality of your records and your response in the first days can shape how the matter proceeds. Firms that can show what they did, when, and why tend to be in a stronger position than firms trying to reconstruct events from memory.
This post is a readiness guide for administrators and managing partners. It is general information, not legal advice. If you face an actual inquiry, retain ethics counsel promptly and let counsel direct communications. Requirements vary by state.
What the ethics guidance discusses
Several ABA sources are commonly cited when discussing incident response.
- Model Rule 1.1 and Comment 8 connect competence to understanding technology risks.
- Model Rule 1.4 addresses communication with clients, which ABA Formal Opinion 483 applies to data breaches, discussing duties to inform affected clients.
- Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure or access.
- Model Rules 5.1 and 5.3 address supervision of lawyers and nonlawyers, including vendors.
- ABA Formal Opinion 477R discusses securing communications of client information.
State bars may have their own rules and opinions. Confirm which apply to you.
Why preparation matters
Questions that might be asked after an incident include: What safeguards did the firm have in place? Did the firm follow its own policies? When did it detect the incident? How quickly did it respond? What did it tell clients, and when? What changed afterward?
You can answer these far better if you have already documented your program.
Build the file before you need it
A written security program
Keep current copies of your written information security policy, acceptable use policy, remote work policy, incident response plan, and AI use policy. Record the date of each version and the approval.
Evidence of operation
Policies on paper are not enough. Keep proof that controls actually run:
- MFA enforcement reports
- Endpoint protection coverage reports
- Backup and restore test logs
- Training completion records with dates
- Vendor review records
- Patching reports
- Results of any independent assessment and your remediation tracker
Governance records
Note who is responsible for security, how often partners review it, and decisions made about risk and budget. Minutes of a brief quarterly review can be enough.
When an incident occurs
Start a timeline immediately
Assign someone to maintain a running log, with date, time, who did what, and why. Record when the incident was detected, when it was contained, when counsel and the insurer were notified, and when clients were told. Keep it factual and avoid speculation.
Preserve evidence
Preserve logs, emails, device images, and vendor communications. Coordinate with forensic responders and counsel before wiping or rebuilding systems. Do not delete anything in an attempt to tidy up.
Route communications through counsel
Limit who speaks to clients, regulators, the press, and the bar. Use counsel-reviewed language. Avoid blaming, guessing at the cause, or promising outcomes.
Work through notification obligations
Counsel will assess what notices may be required to clients, individuals, regulators, and insurers based on the data and states involved. Contracts with clients may add their own deadlines. Track each deadline and each notice sent.
After the response
- Complete a root-cause analysis and document corrective actions with dates and owners
- Update policies and training based on what you learned
- Follow up with affected clients as appropriate
- Brief the partners and record decisions
- Review insurance coverage and update applications accurately
A firm that shows prompt, honest remediation generally looks more credible than one that cannot explain what happened.
Cultural readiness
People should know who to tell when they suspect an incident and should not fear punishment for reporting. Delays in reporting commonly cost more than the original mistake.
Practice it
Include a bar or client inquiry scenario in your annual tabletop exercise. Ask: if a client asked tomorrow for proof of our safeguards, what could we hand over in an hour?
How we help
Counsel Cyber helps firms gather and organize the technical evidence of their security program, maintain incident timelines, and run tabletop exercises. We work alongside your ethics and breach counsel, who guide the legal side. If you would like to assemble your documentation before you need it, we can help.