Model Rule 1.6 is best known for confidentiality: a lawyer generally may not reveal information relating to the representation of a client unless the client consents or an exception applies. Paragraph (c), added in 2012, addresses something different. It says a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.
That sentence is the ethical foundation for much of what law firms do in cybersecurity. This post looks at what "reasonable efforts" has been understood to mean and how a firm can show that it meets the standard. As always, this is general information. Your state's version of the rule and its ethics opinions control, so confirm with your state bar.
What the comments say about reasonableness
The comments to Rule 1.6 describe factors for determining whether efforts are reasonable. They include:
- The sensitivity of the information
- The likelihood of disclosure if additional safeguards are not employed
- The cost of employing additional safeguards
- The difficulty of implementing the safeguards
- The extent to which the safeguards adversely affect the lawyer's ability to represent clients
The comments also note that a client may require special security measures not required by the rule, or may give informed consent to the use of methods that would otherwise be prohibited.
The key point is that this is a balancing test, not a checklist. A firm handling sensitive trade secrets or health records faces a different risk than a firm handling routine uncontested matters, so safeguards can reasonably differ.
What ABA Opinion 477R adds
ABA Formal Opinion 477R, on securing communication of protected client information, builds on this framework. It describes a fact-based, risk-based approach and identifies steps lawyers may consider: understanding the nature of the threat, understanding how client confidential information is transmitted and where it is stored, understanding and using reasonable electronic security measures, determining how electronic communications about client matters should be protected, labeling client information as confidential, training lawyers and nonlawyers in technology and information security, and conducting due diligence on vendors.
You can read those as a roadmap for a firm's security program.
Translating it into practice
Consider each item as an operational question.
Know where client data lives
Maintain an inventory of systems: email, document management, practice-management software, file shares, laptops, phones, backups and any personal or shadow tools. You cannot protect what you have not listed.
Use baseline technical controls
Reasonable today commonly includes multi-factor authentication, encryption of laptops and mobile devices, up-to-date patching, endpoint protection, email filtering and tested backups. These are widely available and affordable relative to the risk, which matters under the cost factor.
Handle unusually sensitive matters differently
If a client or matter warrants it, use additional protections such as restricted matter permissions, encrypted file transfer or limits on devices used. Agree on this with the client where possible and record it.
Train people
Staff are the most frequent entry point for attackers. Regular training on phishing, payment verification and safe handling of files supports the supervision duties in Rules 5.1 and 5.3.
Vet vendors
Cloud providers, outsourced IT, e-discovery vendors and shredding services all handle client information. Collect security documentation, review contract terms about confidentiality and breach notification, and revisit them periodically.
Documenting reasonableness
If something goes wrong, the question will be whether the firm acted reasonably beforehand. Documentation helps. Keep:
- A written information security policy appropriate to your size
- An inventory of systems and vendors
- Records of training, including dates and attendance
- Results of backup restore tests and phishing simulations
- Notes of decisions about safeguards and why they were chosen
- An incident response plan with contacts
You do not need perfect documents. You need evidence that the firm thought about the risks and acted in proportion.
What reasonable efforts does not mean
It does not guarantee that nothing will ever happen. The comments indicate that a disclosure does not by itself violate the rule if the lawyer made reasonable efforts. Equally, doing nothing is hard to defend. After an incident, Rule 1.4 on client communication and ABA Formal Opinion 483 on lawyers' obligations after a data breach come into play.
A simple annual routine
- Review the system inventory and vendor list each year.
- Reassess which safeguards are standard in the industry and whether you have them.
- Update policies and retrain staff.
- Run a restore test and a tabletop exercise.
Counsel Cyber helps firms apply this framework in practical terms, including policy templates, vendor review checklists and a documented security baseline. If you want help showing that your safeguards are reasonable and current, we can start with a short review.