ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Supervising Vendors and Staff: Rules 5.1 and 5.3 for IT Security

How Model Rules 5.1 and 5.3 relate to firm cybersecurity, including supervising staff, IT providers and cloud vendors who touch client information.

3 min readBy Counsel Cyber Team

When a paralegal clicks a phishing link or an outside IT provider misconfigures a server, who is responsible? From an ethics standpoint, the answer often leads back to the lawyers. ABA Model Rules 5.1 and 5.3 deal with supervision, and they apply to how a firm handles technology just as they apply to everything else.

This post gives a plain-English overview and a set of practical steps. It is general information, not legal advice. Rules differ by state, so check your own state's version and any relevant ethics opinions.

What the Rules Say, Briefly

Rule 5.1 covers responsibilities of partners, managers and supervisory lawyers. It calls for reasonable efforts to ensure the firm has measures giving reasonable assurance that all lawyers conform to the Rules of Professional Conduct, and it addresses supervision of subordinate lawyers.

Rule 5.3 covers responsibilities regarding nonlawyer assistance. It calls for similar measures for nonlawyers employed or retained by or associated with a lawyer. The ABA has discussed in Formal Opinions, including 477R and 498, that this thinking extends to outside vendors and technology providers who handle client information.

In practice, "reasonable efforts" is the standard, not perfection. The question is what a thoughtful firm would do.

Supervising Your Own People

Policies that people actually follow

Maintain a short written policy covering passwords, MFA, acceptable use, remote work, personal devices, email handling, wire verification and AI tools. Keep it readable.

Training

Provide security awareness training at hire and at least annually, with periodic phishing simulations. Document attendance. Training is how you demonstrate that you made reasonable efforts.

Oversight

Partners should set an example. Policies exempting senior lawyers send the wrong signal and create real risk. Review who has access to what, and revisit it when roles change.

Clear escalation

Make it easy and safe to report a mistake. Early reports reduce damage, and a blame culture delays them.

Supervising Your Vendors

Outside parties often hold or can reach client data: IT providers, cloud platforms, e-discovery vendors, copy services, transcription services and AI tool providers. A reasonable review process might include:

  1. Inventory. List every vendor with access to client information, and what they can access.
  2. Due diligence. Ask about their security practices, encryption, access controls, breach history and independent assessments.
  3. Contract terms. Look for confidentiality commitments, breach notification timelines, data location, subcontractor rules, return or deletion of data at termination, and insurance.
  4. Least privilege. Give vendors only the access they need, with individual accounts and MFA, not shared credentials.
  5. Ongoing review. Revisit key vendors annually, and when something changes, such as an acquisition or a reported incident.
  6. Exit plan. Know how you would retrieve your data and move to another provider.

Special attention for IT providers

Your IT provider often has the keys to everything. Ask how their technicians are vetted, how their remote tools are secured, whether access is logged, and whether they carry appropriate insurance. A provider that welcomes these questions is a good sign.

Document What You Do

Rules do not require paperwork for its own sake, but a record shows reasonable effort. Keep:

  • The current security policy and acknowledgments
  • Training records
  • A vendor list with review dates
  • Summaries of risk assessments and remediation
  • Incident logs and lessons learned

Common Pitfalls

  • Assuming the IT provider takes on the firm's professional obligations
  • Signing vendor terms without reading the data provisions
  • Letting departed vendors or staff retain access
  • Treating security as a one-time project

Quick Self-Check for Partners

Ask yourself five questions. Can I name every vendor that can reach client data? Do all staff, including partners, use MFA? When was our last security training? Who would I call first in an incident? Where is that plan written down? If any answer is "I'm not sure," that is the place to start.

Support

Counsel Cyber helps firms build vendor review checklists, security policies and training programs that fit these supervisory expectations. If it would help to have a second opinion on your current practices, we are happy to talk it through.