Model Rule 1.6(c) says a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. The word that matters most is "reasonable." The rule does not demand perfect security, and it does not list required tools.
The comments to the rule identify factors for judging reasonableness, including the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost of added safeguards, the difficulty of implementing them and the extent to which they impair the lawyer's ability to represent clients. ABA Formal Opinion 477R applies this analysis to electronic communications, describing a fact-specific approach rather than a fixed checklist.
That leaves administrators with a fair question: what does reasonable look like in practice?
Reasonableness Is a Process, Not a Product
A firm can buy excellent tools and still fall short if nobody maintains them, trains users or reviews risks. Conversely, a small firm with modest tools can show reasonable care if it assesses its risks, applies sensible controls and documents what it did. Think of reasonable efforts as a cycle:
- Identify what client information you hold and where.
- Assess the risks to that information.
- Apply safeguards proportionate to those risks.
- Train people and supervise.
- Review and adjust after changes or incidents.
A Practical Safeguards Checklist
Access controls
- Multi-factor authentication on email, remote access, document management and practice management.
- Unique accounts for every person, with no shared logins.
- Access limited by role and matter, and reviewed periodically.
- Prompt removal of access when staff depart.
Device and data protection
- Full-disk encryption on laptops and phones.
- Automatic updates and patching.
- Endpoint protection monitored by someone, not merely installed.
- Remote wipe capability for lost devices.
Communications
- A defined practice for when to use encryption or a secure portal for sensitive documents, aligned with the risks Opinion 477R discusses.
- Email security filtering against phishing and impersonation.
- Guidance on using personal email and messaging apps, ideally discouraging it for client matters.
Vendors
- Written confidentiality and security terms with cloud providers and IT vendors.
- Periodic review of vendor security practices.
- Knowledge of where data lives and how to retrieve it if the relationship ends.
Resilience
- Tested backups, including at least one copy protected from tampering.
- A written incident response plan with contact numbers.
- Awareness of obligations after a breach, discussed in ABA Formal Opinion 483.
People
- Regular security awareness training for lawyers and staff.
- A culture in which reporting a mistake quickly is rewarded.
- Clear supervision responsibilities under Rules 5.1 and 5.3.
Documenting Reasonableness
If a client, insurer or disciplinary authority ever asks what the firm did, a paper trail helps. Keep a short file with:
- A current technology inventory.
- Your written security policies.
- Training dates and attendance.
- Results of restore tests and access reviews.
- Records of incidents and the actions taken.
None of this must be elaborate. A few well-maintained pages are better than a binder nobody opens.
Scaling to Your Firm
A solo practitioner and a 100-lawyer firm will not look identical. What matters is proportionality: more sensitive matters, such as those involving health data, trade secrets or financial information, warrant stronger measures. Special client requirements, such as outside counsel guidelines, may add obligations beyond the baseline.
Questions to Confirm Locally
State bars adopt and interpret the rules differently, and some have issued their own opinions on cloud computing, metadata and cybersecurity. This post is general information, not legal advice. Check your jurisdiction's rules and opinions, and consult ethics counsel for specific situations.
How Counsel Cyber Helps
Counsel Cyber helps firms assemble the controls and the documentation behind the word "reasonable," with practical safeguards tailored to firm size and client expectations. If you would like a gap review against the checklist above, we can walk through it with you.