Model Rule 1.6(c) says that a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. The word that matters is reasonable. It does not promise perfection, and it does not name specific products. For small firms without a security department, that flexibility is both a relief and a source of uncertainty: how do you know when you have done enough?
This post explains how the ABA has described the standard and offers a practical way for a small firm to think about it. It is not legal advice. Your state's version of the rule and your bar's opinions control, so confirm them.
What the comments and opinions say
The comments to Rule 1.6 list factors for judging reasonableness, including the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, the cost of employing additional safeguards, the difficulty of implementing them and the extent to which the safeguards adversely affect the lawyer's ability to represent clients. The comments also note that a client may require extra measures or give informed consent to fewer.
ABA Formal Opinion 477R, on securing communication of protected client information, builds on these factors. It describes a fact-specific approach instead of fixed rules, and it suggests steps such as understanding the nature of the threat, understanding how client information is transmitted and stored, using reasonable electronic security measures, determining how to communicate electronically about client matters, labeling client information as privileged and confidential, training lawyers and nonlawyers, and conducting due diligence on vendors.
Turning factors into a practical review
Sensitivity
A firm handling trade secrets, family law matters, criminal defense, immigration or health information has more reason to protect it carefully than one handling routine, low-sensitivity work. Classify your practice areas by sensitivity and apply stronger controls where the stakes are higher.
Likelihood of disclosure
Ask where information is most exposed: email, shared links, personal devices, unlocked screens, misdirected emails and vendors. Threats against law firms, such as phishing and business email compromise, are well known. A control that blocks a common attack is easier to defend as reasonable than one aimed at a remote risk.
Cost and difficulty
Some measures are inexpensive and widely adopted, and their absence is harder to justify. Multi-factor authentication, encryption of laptops, regular updates, backups and staff training fall in that category. More expensive measures, such as around-the-clock monitoring, may be reasonable depending on firm size and client data.
A reasonable-efforts baseline for a small firm
- Strong authentication with MFA on email, document systems and remote access.
- Encrypted devices and a way to remotely wipe lost ones.
- Patching and endpoint protection that is actually monitored.
- Secure sharing through portals or encrypted tools for sensitive documents.
- Backups that are tested and protected against ransomware.
- Vendor review documented for key providers.
- Written policies that people have read, covering passwords, devices, acceptable use and incident reporting.
- Training on a regular schedule.
- An incident response plan with contacts and roles.
- Annual review by partners of risks, incidents and changes.
Consider client-specific requirements
Some clients, particularly corporate and financial ones, impose security requirements through outside counsel guidelines. Under the comments, a client can ask for additional safeguards. Keep a list of such requirements and make sure the controls follow the data of those clients.
Informed consent and email
Opinion 477R indicates that routine email is often acceptable for many matters, while highly sensitive information may call for additional precautions such as encryption or avoiding email. Ask clients about their preferences at intake and record them.
Documentation is your friend
Because reasonableness is judged by the circumstances, being able to show your reasoning helps. Keep a short file with your risk assessment, policies, training logs, vendor reviews, incident summaries and meeting notes. You do not need to be perfect, but you should be able to show you thought about it and acted.
Common misconceptions
- "We are too small to be a target." Attackers use automation and do not choose by size.
- "Our vendor handles it." Vendors help, but supervision duties remain.
- "We have never had a breach." That may mean you have not detected one.
- "Security is an IT issue." The rule applies to the lawyer, so partners must be involved.
Support from Counsel Cyber
Counsel Cyber helps small firms document a reasonable-efforts program that fits their size and practice. If you want a gap review against the ten items above, we can do one with you.