ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Technology Competence for Lawyers: Rule 1.1 Comment 8 in Practice

What ABA Model Rule 1.1 Comment 8 says about technology competence, and how a law firm can show reasonable steps without becoming an IT shop.

3 min readBy Counsel Cyber Team

In 2012 the ABA amended the comment to Model Rule 1.1 to state that, to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. That is Comment 8, and a majority of states have adopted some version of it. Check your own state's rule and any related ethics opinions for the exact language that applies to you.

This does not mean lawyers must become network engineers. It does mean that "I don't do computers" is no longer a comfortable posture. This post looks at what technology competence can reasonably look like for a small or mid-size firm.

Competence Is About Judgment, Not Expertise

A competent lawyer does not need to configure a firewall. A competent lawyer should be able to ask whether the firm has one, understand the answer, and know when to bring in help. The ABA's opinions on technology, including Formal Opinions 477R and 498, repeatedly describe reasonable, risk-based efforts rather than a fixed checklist.

Five Areas to Understand

1. How client data moves

Know where client information lives: email, document management, cloud storage, laptops, phones, text messages, and third-party platforms. You cannot protect what you have not mapped.

2. How accounts are protected

Understand multi-factor authentication, password management and why shared logins are a problem. Partners who are exempt from the security rules everyone else follows create the weakest link.

3. How communications are secured

Formal Opinion 477R discusses securing communications of protected client information and calls for a fact-specific analysis. Consider when encrypted email or a client portal is the better choice, and talk with clients about the channels they prefer.

4. How vendors are chosen and supervised

Cloud platforms, e-discovery providers, IT contractors and AI tools all handle client information. Rule 5.3 addresses responsibilities regarding nonlawyer assistance, and the ABA has applied that thinking to outside vendors. Ask about security practices, encryption, data location, breach notification and what happens to data at the end of the relationship.

5. How the firm would respond to an incident

Formal Opinion 483 discusses lawyers' obligations after a data breach, including monitoring for breaches, stopping them, and notifying clients where required. Rule 1.4 on communication is part of that discussion. A written plan beats improvising during a crisis.

Practical Steps for a Firm

  1. Name a technology lead. A partner or administrator who owns the issue, even if day-to-day work goes to an outside provider.
  2. Document your safeguards. A short written security policy, an inventory of systems and a record of reviews demonstrates reasonable effort.
  3. Train everyone. Annual security training plus periodic phishing simulations, for lawyers and staff alike.
  4. Review vendors yearly. Keep a list of vendors with access to client data and revisit their terms.
  5. Take CLE seriously. Many states offer or require technology-related CLE credit. Use it.
  6. Ask your provider for a periodic risk review and keep the results.

Common Misunderstandings

  • "My IT person handles this." Delegating the work does not delegate the responsibility. Rules 5.1 and 5.3 speak to supervision.
  • "We're too small to be a target." Attackers choose targets based on opportunity, not size, and small firms often have fewer defenses.
  • "We've never had a problem." Many incidents go undetected for some time.
  • "Compliance equals security." Written policies matter only if the controls behind them work.

A Note on Interpretation

This post is general information, not legal advice. Whether specific conduct satisfies your obligations depends on your jurisdiction and facts, so confirm with your state bar's ethics resources.

How We Help

Counsel Cyber helps law firms put reasonable safeguards in place and document them, from MFA and email security to vendor reviews and incident response plans. If you would like a plain-English security review, get in touch and we will walk through it with you.