ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

What ABA Comment 8 Means for Your Firm's Technology Habits

ABA Model Rule 1.1, Comment 8 ties competence to technology. Here is how firm administrators can turn that language into everyday, documented practices.

3 min readBy Counsel Cyber Team

Most lawyers can recite Model Rule 1.1: a lawyer shall provide competent representation. Fewer have read Comment 8 closely. It says that to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Many states have adopted some version of that language, and your state bar may phrase it differently, so confirm the exact wording where you practice.

For a firm administrator, the practical question is not whether the comment is real. It is what a firm can show if a client, a carrier or a disciplinary counsel asks how the firm stays current on the risks of the tools it uses. This post breaks the comment into habits you can actually run.

Read the comment as a two-sided duty

Notice the phrase "benefits and risks." The comment does not tell lawyers to adopt every new tool, and it does not tell them to avoid technology. It asks them to understand both what a tool can do and how it can go wrong. That framing is useful when you evaluate anything from a new document-sharing portal to an AI drafting assistant.

What this does not require

Comment 8 does not turn every attorney into an IT engineer. Lawyers can and routinely do rely on qualified people for technical work. Model Rules 5.1 and 5.3 address supervising lawyers and nonlawyer assistance, and the ABA has discussed outside vendors in its formal opinions. The point is that a lawyer who delegates still needs a reasonable basis for trusting the person or provider doing the work.

Turn the comment into five habits

  1. Keep a simple technology inventory. List the systems that touch client information: email, document management, practice management, billing, phone and text tools, file sharing, backup and any AI tools. You cannot assess risks in systems nobody has written down.
  2. Assign an owner. Someone, whether the managing partner, an administrator or your managed IT provider, should be responsible for knowing what is in the inventory and what has changed.
  3. Review vendors before adopting them. Ask where client data is stored, who can access it, how it is encrypted, what happens when the contract ends and how the vendor reports a security incident.
  4. Train on a schedule. Short, regular security awareness sessions beat one long annual lecture. Cover phishing, wire instructions, password practices and what to do when something looks wrong.
  5. Write down what you decided. A one-page record of why the firm chose a tool, or chose not to, is far more useful than good intentions nobody can document.

Build a lightweight annual review

Competence is a continuing obligation, so a one-time project will not satisfy the spirit of the comment. A yearly review does not need to be elaborate. Set a standing meeting with your partners and your IT provider and walk through a short agenda.

  • What new tools did attorneys or staff start using this year, officially or not?
  • Which tools did we retire, and was client data removed from them?
  • Did we have any security incidents or near misses, and what did we change afterward?
  • Are our backups tested, and when did we last restore something?
  • Who still has access that they no longer need?
  • What do our carriers and clients now ask about that we could not answer easily?

Keep the notes. If someone later asks how the firm approaches technology competence, a dated set of meeting notes is a straightforward answer.

Watch for shadow technology

The biggest gap between policy and reality is usually tools nobody approved. Staff who use free file converters or paste client text into public chatbots are solving a problem. Ask periodically which tools people use, make it safe to answer, then approve the tool with proper settings or replace it.

Connect competence to confidentiality

Comment 8 sits alongside Rule 1.6(c), which asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. The ABA's Formal Opinion 477R discusses securing communications and says the reasonable efforts standard depends on factors such as the sensitivity of the information and the cost of safeguards. Nothing here is legal advice, so check your own state bar's opinions.

Where Counsel Cyber fits

Counsel Cyber works only with law firms, so we are used to translating ethics language into concrete IT controls. If you would like help building a technology inventory, an annual review agenda or a vendor checklist, we are glad to run a security review with your team and leave you with documents you can keep.