In 2012 the ABA amended the comments to Model Rule 1.1, which addresses competent representation. Comment 8 now says that, to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Many states have adopted similar language in their own rules, though the wording and details vary, so confirm what your state bar has said.
The comment is short, and it generates a lot of questions. Does it mean every lawyer must become an IT expert? No. But it does mean that ignoring technology risk is hard to defend.
What the Comment Does and Does Not Say
It does not require lawyers to personally configure firewalls or read security logs. It does ask lawyers to understand the technology they use well enough to recognize its benefits and its risks, and to get appropriate help when their own expertise falls short. ABA Formal Opinion 477R, on securing communications, takes a similar reasonableness approach: it asks lawyers to make reasonable efforts based on the sensitivity of the information and the risks involved, rather than demanding a fixed set of controls.
The practical reading is that competence includes asking the right questions, documenting decisions and relying on qualified experts where needed.
Where Technology Competence Shows Up Day to Day
Email and communication
Do you know when email is a reasonable channel for client information and when something stronger, like a secure portal or encryption, is warranted? Opinion 477R discusses this judgment.
Cloud services
Using a cloud document or practice-management platform is common. Competence includes understanding where data is stored, who can access it, how it is protected and what happens if you end the relationship.
Remote work
ABA Formal Opinion 498 addresses virtual practice, including securing home networks, devices and conversations. Staff working at kitchen tables are part of your risk surface.
Generative AI
ABA Formal Opinion 512, issued in July 2024, discusses lawyers' obligations when using generative AI tools, including competence, confidentiality and supervision. Understanding the tools your lawyers actually use, sanctioned or not, is now part of the picture.
Turning the Comment Into a Practice
Here is a manageable approach for a firm without a full-time IT department.
- Inventory your technology. List the systems that touch client information, including cloud tools lawyers signed up for themselves.
- Assign responsibility. Someone, whether a partner, administrator or outside provider, should own technology risk and report to firm leadership periodically.
- Set baseline controls. Multi-factor authentication, encryption of laptops, patching, backups and email protection are widely considered a reasonable foundation.
- Train everyone. Security awareness training for lawyers and staff, with attention to phishing and wire-fraud attempts.
- Document decisions. A short written policy and a record of periodic reviews show that the firm took a thoughtful approach.
- Review vendors. Ask your providers about their security practices, and get confidentiality commitments in writing.
- Plan for incidents. Know who to call and what you would do first, a theme in ABA Formal Opinion 483 on lawyers' obligations after a data breach.
Common Misreadings
- "I am not technical, so this does not apply to me." The comment contemplates getting help, not avoiding the subject.
- "Our IT person handles it." Delegation is fine, but Rules 5.1 and 5.3 address supervisory responsibilities for lawyers and nonlawyers, which can include vendors.
- "We have never had an incident." Absence of a known incident is not evidence of adequate safeguards.
A Note on Certainty
Ethics rules are interpreted by state bars and courts, and they differ by jurisdiction. This post is general information and not legal advice. Check your state's rules and ethics opinions, and consult ethics counsel on specific questions.
How Counsel Cyber Can Help
Counsel Cyber works with firms in Texas, Arkansas, Louisiana, Oklahoma and Kansas to translate ethics guidance into practical safeguards. If you would like a technology inventory and risk review you can present to your partners, we can help.