Very few firms handle all their technology internally. Email is hosted by a cloud provider, files live in a document-management platform, an outside company manages the network, and an e-discovery vendor handles large productions. Each of these parties can see or affect client information. The ABA Model Rules speak to this in two places: Rule 5.1, on responsibilities of partners, managers and supervisory lawyers, and Rule 5.3, on responsibilities regarding nonlawyer assistance.
This post explains how the rules have been understood and how a firm can apply them to its technology vendors. It is general information, not legal advice, so confirm with your state bar how your jurisdiction applies them.
What the rules say, in outline
Rule 5.1 requires lawyers with managerial authority to make reasonable efforts to ensure the firm has measures in place giving reasonable assurance that all lawyers conform to the Rules of Professional Conduct. Rule 5.3 applies similar reasoning to nonlawyers employed or retained by or associated with a lawyer, including outside vendors. The point of both is that delegation does not erase responsibility.
The ABA has also addressed outsourcing and cloud computing in its opinions, including Formal Opinion 477R on securing communications, which recommends due diligence on vendors, and Formal Opinion 498 on virtual practice. A common thread is that a lawyer may use qualified vendors but should exercise reasonable oversight.
What reasonable oversight can look like
Reasonable depends on the sensitivity of the data and the vendor's role. A vendor with administrator access to every system warrants more scrutiny than a vendor that prints brochures.
Before engaging a vendor
- Know what the vendor will access. Email, files, backups, client lists, or only de-identified data?
- Collect security documentation. Ask for independent reports where available, a description of security controls and policies, and answers to a standard questionnaire.
- Check reputation and experience with law firms or similarly regulated clients.
- Ask about subcontractors and where data and staff are located.
- Review financial and operational stability, including what happens if the vendor shuts down.
In the contract
- Confidentiality obligations that cover client information
- Security requirements, such as MFA, encryption and access controls
- Breach notification with a defined timeframe
- Rights to data return and deletion at the end of the relationship
- Cooperation with audits or questionnaires from the firm's clients
- Insurance coverage and liability terms
- Restrictions on using firm data for the vendor's own purposes, including training AI models
Have counsel review the contract, since terms vary widely and cloud contracts are often presented as non-negotiable.
During the relationship
- Keep a vendor inventory with the owner, the data accessed and the renewal date.
- Review security documentation annually or when contracts renew.
- Ask for periodic reports of what the vendor did, particularly for IT providers.
- Limit vendor access to what is necessary, and require MFA and individual accounts, not shared logins.
- Monitor vendor access logs where feasible.
- Verify that former vendor staff lose access.
At the end
Revoke credentials, retrieve or confirm deletion of data, collect documentation and confirm in writing that data has been returned or destroyed.
Applying this to your IT provider
An IT provider typically holds the most powerful credentials in the firm. Ask:
- Do they enforce MFA on their own administrative tools?
- Do technicians use unique accounts, and can their actions be reviewed?
- How do they handle client data they encounter during support work?
- Who owns the documentation and administrator credentials?
- How would they notify you of an incident affecting their own systems?
If the answers are vague, treat that as information.
Supervising your own nonlawyer staff
Rule 5.3 also covers paralegals, assistants and other staff. Supervision includes training on confidentiality, security awareness, clear policies and consequences, and access limited to what the job requires. Documented training sessions help show that the firm has taken reasonable steps.
Keep records
If a vendor incident occurs, you will want to show how the firm selected and oversaw the vendor. Maintain a simple file for each significant vendor: due diligence materials, the contract, review notes and incident correspondence.
Where this fits in a program
Treat vendor management as a recurring calendar item, not a one-time event. A list of the ten vendors with the most access, reviewed annually, covers the greatest risk with manageable effort.
Counsel Cyber, as a managed IT provider to law firms, expects to be held to these standards. We provide security documentation and are happy to help you build a vendor review checklist for your other providers.