How Can a Law Firm Protect Client Confidentiality and Comply With ABA Cybersecurity Obligations?

Direct Answer

A law firm can protect client confidentiality and comply with ABA cybersecurity obligations by making reasonable efforts to prevent unauthorized access to or disclosure of client information.

ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to a client representation. Comment 18 to Rule 1.6 explains that reasonable efforts depend on factors including the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost and difficulty of implementing safeguards, and their effect on the lawyer's ability to represent clients.

For most law firms, protecting client confidentiality requires a combination of technology, written procedures, employee training, and ongoing cybersecurity management.

Why This Matters

Client confidentiality has always been a fundamental responsibility of a law firm. Technology has changed how that responsibility must be carried out.

Client information now resides in email, document management systems, cloud applications, laptops, mobile devices, and other electronic systems. Cybersecurity is therefore part of protecting client confidentiality.

Comment 8 to Rule 1.1 requires lawyers to keep abreast of the benefits and risks associated with relevant technology.

Editor's Insight

The ABA does not require perfect cybersecurity. It requires reasonable efforts to protect client information.

A successful cyberattack does not automatically mean a lawyer failed to satisfy that obligation. Comment 18 to Rule 1.6 recognizes that unauthorized access or disclosure does not violate Rule 1.6(c) when the lawyer made reasonable efforts to prevent it.

The question for a law firm is not whether every cyberattack can be prevented. The question is whether the firm has implemented reasonable safeguards for the information and risks it has.

How Can a Law Firm Protect Client Confidentiality?

A law firm should approach client confidentiality as an ongoing cybersecurity responsibility.

1. Identify the Client Information That Needs Protection

The firm first needs to understand where confidential client information resides and how employees access it.

This may include:

  • Email
  • Client files
  • Document management systems
  • Practice management applications
  • Cloud storage
  • Laptops and desktop computers
  • Mobile devices
  • Backups

The sensitivity of the information is one of the factors used to determine what safeguards are reasonable under Comment 18 to Rule 1.6.

A firm cannot adequately protect information if it does not know where that information is stored and who can access it.

2. Implement Reasonable Technical Safeguards

Technology should provide multiple layers of protection around client information.

Depending on the firm's environment, reasonable safeguards may include:

  • Multi-Factor Authentication (MFA)
  • Endpoint Detection and Response (EDR)
  • Firewalls
  • Email security
  • Secure backups
  • Password managers
  • Access controls
  • Encryption where appropriate
  • Security monitoring

ABA Formal Opinion 477R, Securing Communication of Protected Client Information explains that lawyers using electronic communications must make reasonable efforts to prevent inadvertent or unauthorized access, and that some circumstances may require additional security precautions.

The appropriate safeguards depend on the information being protected and the risks the firm faces.

3. Train Employees to Protect Client Information

Technology cannot protect client confidentiality by itself.

Attorneys and employees need to recognize phishing attacks, fraudulent requests, suspicious links and attachments, Business Email Compromise, and other methods attackers use to obtain access to information.

They also need to understand the firm's procedures for handling confidential information.

ABA Formal Opinion 498, Virtual Practice emphasizes confidentiality and supervision when lawyers use technology for virtual practice, including reasonable efforts to ensure that lawyers and non-lawyer assistants comply with professional obligations.

Cybersecurity awareness training makes employees part of the firm's protection rather than leaving the responsibility entirely to technology.

4. Maintain Written Cybersecurity Procedures

A law firm should document how it protects information and how employees are expected to respond when something goes wrong.

Written procedures may address:

  • Password and MFA requirements
  • Acceptable use of technology
  • Handling confidential information
  • Remote access
  • Employee onboarding and termination
  • Security awareness training
  • Incident reporting
  • Incident response

Written procedures establish consistent expectations throughout the firm.

They also help employees know what to do before an incident occurs.

5. Prepare to Respond to a Cybersecurity Incident

Reasonable safeguards reduce risk, but they cannot guarantee that an incident will never occur.

The firm should have a written Incident Response Plan that identifies what happens when a suspected breach or cyberattack is discovered.

ABA Formal Opinion 483, Lawyers' Obligations After an Electronic Data Breach or Cyberattack explains that when a data breach involving material client information occurs, lawyers have duties to take reasonable steps consistent with their obligations under the Model Rules. The opinion also discusses monitoring for a breach, stopping a breach, restoring systems, and determining what happened.

The time to decide how to respond to a cyberattack is not after the attack begins.

Two Questions We Hear

Does the ABA require specific cybersecurity technologies?

The ABA Model Rules generally establish a standard of reasonable efforts rather than prescribing a universal list of security products.

What is reasonable depends on factors including the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost and difficulty of implementing safeguards, and their effect on the representation. Clients may also require additional security measures. (American Bar Association)

That does not mean technology is optional. It means the safeguards should be appropriate to the risks.

Can a law firm violate its ethical obligations if it suffers a cyberattack?

A cyberattack by itself does not establish that the firm failed to make reasonable efforts.

Comment 18 to ABA Model Rule 1.6 states that unauthorized access or disclosure does not constitute a violation of Rule 1.6(c) if the lawyer made reasonable efforts to prevent it.

The important question is what the firm did before the incident to protect client information and how it responded when the incident occurred.

How Avenue M Helps

Avenue M helps law firms throughout New York and New Jersey implement and maintain cybersecurity safeguards designed to protect confidential information.

We help clients:

  • Conduct cybersecurity risk assessments.
  • Implement Multi-Factor Authentication.
  • Deploy Endpoint Detection and Response.
  • Secure email and business systems.
  • Implement password managers.
  • Provide cybersecurity awareness training.
  • Develop written cybersecurity policies and Incident Response Plans.
  • Monitor and respond to cybersecurity threats.

The objective is not to promise that a cyberattack can never happen. It is to help the firm make reasonable efforts to prevent unauthorized access, identify threats, and respond when an incident occurs.

Three Key Takeaways

  1. Protecting client confidentiality includes protecting the systems where client information is stored and accessed.
  2. The ABA requires reasonable efforts to protect client information, not a universal checklist of cybersecurity products.
  3. A cyberattack does not automatically mean a law firm failed its cybersecurity obligations. The question is whether the firm made reasonable efforts to protect client information and responded appropriately to the incident.

Related Articles

Technology should help your law firm practice law more securely, efficiently, and confidently, not become another distraction.