In 2012 the ABA amended the comments to Model Rule 1.1 on competence. Comment 8 now says that to maintain competence, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Many states have adopted similar language, although the exact wording and the number of states vary, so confirm what applies in yours.
The comment is short, which leaves firms asking a fair question: what does keeping abreast look like in practice? This post offers a practical, non-exhaustive answer. It is not legal advice, and the standard is ultimately set by your jurisdiction.
What the comment does and does not say
Comment 8 does not require lawyers to become engineers. It also does not prescribe specific tools. What it signals is that ignorance of the technology used in your practice is not a safe position. Competence can be achieved by learning, by associating with someone who has the knowledge, or by hiring qualified help, which echoes the broader guidance in the Model Rules on supervision of nonlawyers.
Turning the comment into firm practice
1. Know what technology you use
You cannot assess risk for tools you have not inventoried. Create a list of systems that touch client information: email, document management, practice management, cloud storage, e-signature, video conferencing, messaging, and AI tools. Include shadow tools staff adopted informally.
2. Understand the risks of each
For each system, ask a few basic questions: Where is the data stored? Who can access it? Is it encrypted? What happens if the vendor has an incident? How do we get our data out?
3. Put reasonable safeguards in place
The ABA's Formal Opinion 477R recognizes that reasonable efforts to protect electronic communications depend on factors such as the sensitivity of the information and the cost of safeguards. In practice, a baseline for most firms includes:
- Multi-factor authentication
- Encrypted devices
- Email security and phishing defenses
- Regular patching
- Tested backups
- Access limited to those who need it
4. Train everyone
Lawyers and staff all handle client data. Annual training is a minimum; short monthly reminders and phishing simulations work better. Keep attendance records.
5. Supervise vendors
Rule 5.3 on nonlawyer assistance has been applied by the ABA to outside service providers. Maintain contracts that address confidentiality and breach notification.
6. Prepare for incidents
ABA Formal Opinion 483 discusses lawyers' obligations when a data breach occurs, including monitoring for breaches and responding. A written incident response plan that names who does what is part of being ready.
7. Keep learning
Assign someone to follow developments, whether a partner, a firm administrator or your IT provider. Attend CLE sessions on technology, and include technology updates on partner meeting agendas.
Document what you do
If a client, a carrier or a disciplinary authority ever asks what the firm did to meet its obligations, records matter. Keep:
- Your technology inventory with review dates
- Training schedules and attendance logs
- Policies and acknowledgments
- Vendor assessments
- Test results for backups and incident drills
- Minutes showing that partners reviewed security periodically
Common misconceptions
- "My IT person handles it, so I don't need to know." Lawyers retain responsibility for supervision, even when delegating.
- "We are too small to be a target." Attackers frequently target small organizations because defenses are often thinner.
- "We bought security software, so we are covered." Tools need configuration, monitoring and people who respond to alerts.
A measured approach
Few firms can do everything at once. Start with the most likely and most damaging risks: email compromise, ransomware and lost devices. Build from there.
Where Counsel Cyber fits
We help firms translate competence expectations into concrete controls and documentation. If you would like a technology inventory and risk review as a starting point, we can arrange one.