In 2012 the ABA amended the comments to Model Rule 1.1, the duty of competence. Comment 8 now says that to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Many states have adopted similar language, though wording and numbering vary, so check your own jurisdiction.
That one phrase gets quoted often and explained rarely. What does it mean for a firm administrator trying to run an office on a real budget?
What the Comment Does and Does Not Say
It does not say every lawyer must become an IT expert. It does not require specific products. It does say that both the benefits and the risks of the technology you use are part of competence.
Put plainly, a lawyer who uses email, cloud storage, e-filing, video conferencing or AI tools should understand enough about each to use it responsibly, or should rely on someone who does. Model Rules 5.1 and 5.3 address supervising lawyers and nonlawyer assistance, which is where outside IT providers and vendors come into the picture.
Where Firms Commonly Fall Short
- Unmanaged tools. Staff adopt file-sharing or messaging apps that no one has reviewed.
- No security basics. Email without multi-factor authentication, laptops without encryption, shared passwords.
- No knowledge of where data lives. Partners cannot say which vendors hold client files.
- Outdated habits. Sending sensitive documents as plain email attachments when a secure portal is available.
- No plan for new tools. AI, e-signature and transcription tools show up before a policy does.
A Practical Competence Program
A firm does not need a large program. It needs a visible, repeatable one.
1. Know Your Technology Inventory
Keep a one-page list of systems that handle client information: email, practice management, document storage, billing, backup, remote access, communication tools. Next to each, note the owner and the vendor.
2. Understand the Risks of Each
For each system, be able to answer in a sentence: what could go wrong, and what do we do to reduce it? For email, the answer might include phishing and misdirected messages, with MFA and filtering as controls.
3. Train Regularly
Short, recurring sessions work better than annual marathons. Topics worth covering include phishing, secure file sharing, working remotely, mobile devices and AI tools. Keep a simple record of who attended and when.
4. Use Qualified Help
Competence can be met in part by involving people with the right expertise. If your firm relies on an outside provider, ask what they actually do for security, how they report to you and how you will learn of problems.
5. Review When Things Change
New software, new office, new remote policy, new practice area? Each is a moment to ask what changed in the risk picture.
Related Guidance Worth Knowing
The ABA has addressed technology in several opinions. Formal Opinion 477R discusses securing communications of protected client information. Formal Opinion 483 addresses lawyers' obligations after a data breach. Formal Opinion 498 covers virtual practice, and Formal Opinion 512 covers generative AI. Reading the summaries is a reasonable first step, and your state bar may have its own opinions that go further.
Documentation Helps
If a client, insurer or disciplinary body ever asks what you did to stay current, a simple file helps: your technology inventory, training records, policies and notes from vendor reviews. Competence you can show is easier to defend than competence you merely believe you have.
This article is general information, not legal advice. Your state bar and your own counsel are the right sources for what your obligations are.
Counsel Cyber works with law firms to turn these expectations into practical steps, from inventories and policies to training and security controls. If you would like help building a lightweight program, we are glad to talk it through.