When a law firm hires an outside IT provider, cloud service or consultant, it hands someone else access to client information. ABA Model Rule 5.3 speaks to this situation. It deals with a lawyer's responsibilities regarding nonlawyer assistance, and the ABA has applied it to technology vendors, including in Formal Opinion 477R on securing client communications and Formal Opinion 498 on virtual practice.
In general terms, the rule asks lawyers with managerial authority to make reasonable efforts to ensure the firm has measures giving reasonable assurance that nonlawyers' conduct is compatible with the lawyer's professional obligations. Check your own state's version of the rule, because wording varies.
Why It Matters for IT
An IT provider may have administrative access to email, document systems, backups and every workstation. That is a lot of trust. If the provider mishandles data, is compromised, or uses weak practices, the firm may still have to answer to clients. Reasonable supervision is how a firm manages that risk.
What Reasonable Supervision Can Look Like
Before hiring
- Ask about experience and practices. How do they protect client data? Do they have experience with law firms?
- Ask about their own security. Do they use MFA, protect their administrative tools, and monitor access? Providers are themselves targets because they hold keys to many clients.
- Check background and screening practices for technicians with access.
- Request references and, where available, independent assessment reports.
- Read the contract. Look for confidentiality terms, breach notification timing, data return and deletion at termination, and liability provisions.
In the contract
- A confidentiality clause covering client information
- A requirement to notify you promptly of any incident affecting your data
- Clarity on who owns data, documentation and credentials
- Defined access limits and a requirement to use named accounts, not shared logins
- Subcontractor disclosure
- Transition assistance if the relationship ends
During the relationship
- Review access regularly. Who at the provider has admin rights, and does each person still need them?
- Require reporting. Ask for patch status, backup test results, security alerts and open risks on a regular schedule.
- Hold periodic meetings with a named contact at the provider to review these items and plan ahead.
- Verify, do not just trust. Ask to see evidence, such as MFA reports or restore test logs.
- Insist on logging. You should be able to find out who accessed what.
When it ends
- Revoke all provider accounts and remote access tools immediately
- Change administrator passwords and any shared secrets
- Obtain documentation, configuration backups and an inventory
- Confirm in writing that your data has been returned or deleted
Other Vendors Count Too
The same thinking applies beyond IT: e-discovery vendors, cloud storage, document shredding, outside accountants, answering services, and AI tool providers. Keep a vendor list noting what data each holds, the contact person, contract dates, and the date of your last review. Tier vendors by risk so your effort goes where it matters most.
A Simple Vendor Review Checklist
- What client data does this vendor touch?
- Is there a written agreement with confidentiality terms?
- Does the vendor use MFA and encryption?
- How will we learn of an incident on their side?
- What happens to our data if we leave?
- When did we last review this vendor?
Documenting Supervision
Keep records of vendor reviews, contracts, meeting notes and evidence requested. If a client or regulator asks how you oversee vendors, you will have an answer. This is not legal advice; your state bar or ethics counsel can tell you how your jurisdiction applies the rule.
Counsel Cyber's Approach
As a provider serving only law firms, Counsel Cyber expects to be supervised. We provide regular reporting, named accounts, documented access, and a clear contractual commitment to confidentiality, and we are happy to answer your vendor due diligence questions.