ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Rule 5.1 and Partner Responsibility for Firm Cybersecurity

Model Rule 5.1 addresses partner and supervisory duties. Here is how the principle applies to firm cybersecurity policies, culture and everyday oversight.

4 min readBy Counsel Cyber Team

Model Rule 5.1 deals with the responsibilities of partners, managers and supervisory lawyers. In broad terms, it says that lawyers with managerial authority should make reasonable efforts to ensure the firm has measures in place giving reasonable assurance that all lawyers conform to the Rules of Professional Conduct. Lawyers with direct supervisory authority over another lawyer have a related duty.

Rule 5.1 was not written with cybersecurity in mind. But a firm whose lawyers mishandle client data, fall for a phishing email or use an unapproved cloud tool may well raise questions about confidentiality and competence, and the rule on supervision is part of the picture. This post looks at what the principle means in practice for partners who would rather not spend their evenings reading about passwords. It is general information and not legal advice, and you should confirm your state's version of the rule with your bar.

Policies versus culture

Rule 5.1's framing is about measures and reasonable assurance. That points to systems and habits rather than good intentions. A firm that has a security policy but whose partners ignore it sends a clear signal about how seriously to take it.

The most effective security cultures in small firms share a feature: partners follow the rules visibly. When a senior attorney uses MFA without complaint, completes training on time and asks before installing a new tool, everyone else follows suit. When a partner demands an exception, the exception becomes the norm.

What "reasonable measures" often look like

There is no single list that defines reasonable. Courts, bars and clients assess it in context. But the following are the sorts of measures that firms often point to when describing their approach.

  • A written acceptable use policy that every person acknowledges.
  • Required security awareness training at hire and at regular intervals.
  • Enforced multi-factor authentication and device encryption.
  • A process for approving new software and cloud services.
  • A defined path for reporting suspicious emails or lost devices.
  • Periodic review of who has access to what.
  • A basic incident response plan with named roles.

The common failure points for partners

Exceptions for senior people

"I'll do the MFA thing later" is the most dangerous sentence in a law firm. Executive and partner accounts are the most valuable to attackers because they carry authority and access to the most sensitive matters.

Using personal tools for convenience

Personal email, home printers and consumer file sharing are tempting when the approved process feels slow. Partners who do this teach associates to do the same.

Delegating and never checking

Handing IT to an administrator or outside provider is reasonable. Never asking for a report is not. Partners should see, at least quarterly, a short summary of patch status, MFA coverage, backup results and open risks.

Skipping training

Attorneys with a heavy docket often consider training optional. Partners who skip it should expect staff to skip it as well.

Supervising the people who supervise IT

A parallel principle appears in Rule 5.3, which addresses responsibilities regarding nonlawyer assistance. In a modern firm, the people closest to your systems are often nonlawyers or outside vendors. Partners are not expected to administer the network, but they are expected to establish that someone competent is doing it and that the work is reviewed.

A one-page partner checklist

  1. Have we named a partner or administrator accountable for technology risk?
  2. Do all partners use MFA and encryption on every device?
  3. Did all lawyers and staff complete security training this year?
  4. Have we received an IT status report in the last quarter?
  5. Do we know who has access to our most sensitive matters?
  6. Have we discussed what we would do in a breach?
  7. Do clients' security requirements reach someone who tracks them?

Make the review routine

Put a fifteen-minute technology item on the agenda of every partner meeting. Cover one topic at a time: patching, access, training completion, incidents and near misses. Brief and consistent beats long and rare. Minutes of those discussions also create a record of attention.

Near misses are gifts

A staff member who reports a phishing email they almost clicked has given the firm a free lesson. Thank them publicly, share the example anonymously and adjust training. Firms that celebrate near-miss reporting find problems earlier.

Closing the loop

Supervision is not a one-time event. Revisit the questions above annually, track completion of action items and update policies as tools change. If a regulator, client or insurer ever asks how the firm approached cybersecurity, a record of regular, partner-level attention is the most persuasive answer available.

How Counsel Cyber can help

Counsel Cyber can prepare a short quarterly security summary for your partners and help you build the habits above without adding bureaucracy. If you would like an outside review of where your firm stands, we are glad to start there.