Model Rule 1.6(c) is short. It says that a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. The accompanying commentary explains that unauthorized access or disclosure does not necessarily violate the rule if the lawyer made reasonable efforts, and it lists factors relevant to what is reasonable, such as the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost and difficulty of safeguards and the extent to which they impair the lawyer's ability to represent clients.
The word doing the work is "reasonable." It means no one can hand you a definitive checklist. It also means that the quality of your process matters at least as much as the outcome. Firms that can show a thoughtful, documented, regularly reviewed program are in a better position than those relying on good intentions. This post suggests how to build one. It is general information, not legal advice, and your state's version of the rule and commentary may differ.
Reasonable is risk-based
The commentary's factors point to a risk-based approach. A firm handling sealed family court records, medical files or merger documents faces different risks from one doing routine uncontested matters. The program should scale accordingly, but some baseline controls are widely expected now.
A baseline program in six parts
1. Governance
Name an owner for technology risk, hold a regular partner-level review and keep a short written security policy. Governance is what turns scattered fixes into a program.
2. Know your data and systems
Maintain an inventory of applications, devices and vendors that touch client information, and classify what is most sensitive.
3. Protect
Core technical safeguards include:
- Multi-factor authentication on email, remote access and key applications.
- Encryption of laptops, phones and removable media.
- Patching and supported software.
- Email security and filtering.
- Least-privilege access, with periodic review.
- Secure sharing options for clients.
4. Detect
Add monitoring: endpoint detection and response, sign-in alerts and log retention long enough to investigate. A breach you cannot see is a breach you cannot respond to; ABA Formal Opinion 483 discusses monitoring in that vein.
5. Respond and recover
Maintain a written incident response plan, tested backups with at least one immutable or offline copy and a list of contacts for counsel, insurer and forensic help.
6. People and vendors
Train all staff at hire and regularly afterward. Supervise nonlawyer staff and vendors consistent with Model Rules 5.1 and 5.3, including reviewing vendor security and contract terms.
Documentation: the quiet power
If a client, insurer or regulator asks what you did, the answer should be on paper, with dates. Keep these in one folder:
- The current security policy and acceptable use policy.
- The software and vendor inventory.
- Training completion records.
- MFA, encryption and patch coverage reports.
- Backup test results.
- Incident response plan and tabletop exercise notes.
- Notes from partner reviews showing decisions.
- Vendor assessments.
None of this has to be long. It has to be current.
Tie the program to client expectations
Client guidelines and questionnaires often set security expectations. Track them, meet the baseline and document exceptions. The ABA's discussion of securing communications in Formal Opinion 477R also notes that clients may request particular safeguards, and a lawyer should consider those requests.
Balance security and usability
The commentary recognizes that safeguards should not unreasonably impair the lawyer's ability to represent clients. Controls that attorneys find so burdensome that they work around them create worse outcomes than moderate controls everyone follows. Test processes with real users.
Review and improve
Reasonableness is judged against current circumstances. Controls considered adequate several years ago may not be today. Schedule an annual review that covers new threats, new tools, incident lessons and changes in the firm. Update documentation and training afterward.
A five-step starter plan for the next 90 days
- Assign an owner and schedule a quarterly review.
- Build the inventory and identify systems without MFA.
- Verify encryption, patching and backup coverage, then test a restore.
- Run training and set up a way to report suspicious emails.
- Write or refresh the incident response plan and hold a short tabletop exercise.
When something still goes wrong
Even strong programs experience incidents. A documented program, prompt response and honest client communication are the best foundation for the aftermath. Consult ethics counsel promptly about obligations specific to your state and the facts.
How Counsel Cyber can help
Counsel Cyber helps law firms build, operate and document security programs aligned with these expectations. If you would like a review of your current program and a prioritized list of next steps, we are glad to help.