For most businesses, a data breach is a commercial and regulatory problem. For a law firm it is also an ethics problem, and that changes both the obligation and the consequences.
Confidentiality is not a policy a firm adopts. It is a professional duty, and the rules governing it now explicitly reach the technology the firm uses.
What the ethics rules actually say
Three provisions matter, and together they establish that competence in technology is not optional.
ABA Model Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent unauthorised disclosure of, or access to, client information. Note the standard: reasonable efforts, not a guarantee. A firm that suffers a breach despite sound controls is in a very different position from one that never implemented any.
Comment 8 to Model Rule 1.1 provides that competence includes keeping abreast of the benefits and risks associated with relevant technology. The great majority of states have adopted some version of this duty of technology competence.
ABA Formal Opinion 483 addresses obligations after a breach — the duty to monitor for intrusion, to act reasonably to stop it, and to notify affected clients where their material was compromised.
The practical implication is that "we did not know" is not a defence, and that the reasonableness of your controls is assessed against what a competent firm would have done.
| Provision | What it establishes |
|---|---|
| ABA Model Rule 1.6(c) | Reasonable efforts to prevent unauthorised disclosure of, or access to, client information |
| Comment 8 to Model Rule 1.1 | Competence includes keeping abreast of the benefits and risks of relevant technology |
| ABA Formal Opinion 483 | After a breach: monitor for intrusion, act reasonably to stop it, notify affected clients |
Why firms are targeted specifically
Law firms are attractive targets for reasons that have nothing to do with the firm's own size:
- Concentration of value. A firm holds the sensitive material of many clients in one place — transaction details, litigation strategy, intellectual property, personal information.
- Transaction timing. Real estate and corporate work involves large scheduled transfers on known dates, which is precisely what payment fraud targets.
- Reputational leverage. A firm whose confidential client material is threatened with publication faces pressure that goes beyond the direct loss.
- Relative security maturity. Attackers reasonably assume a 15-attorney firm has weaker controls than the corporate clients it serves — and frequently they are right.
Real estate practices deserve particular mention. Wire fraud around closings is one of the most persistent and costly attacks in the sector, and it usually begins with a compromised or spoofed email account rather than anything technically sophisticated.
The controls that matter most
Email security, first
Email is where most firm compromises begin and where most client communication lives. Requirements: MFA on every mailbox with no exceptions for partners, properly configured SPF, DKIM and DMARC so the firm's domain cannot be trivially spoofed, and filtering that catches impersonation as well as malware.
Add a rule that no payment instruction is ever accepted or acted on by email alone. Verification by voice to a previously known number, every time, without exception for urgency. This one procedural control prevents the most expensive incidents in the sector.
Access limited by matter
Not everyone in the firm needs access to every matter. Ethical walls are a professional requirement in conflict situations, and they need to exist technically rather than only on paper. Document management systems support this; general file shares usually do not.
Encryption everywhere
Full disk encryption on every device, including personal machines used for firm work. Encryption for material sent externally — a secure portal is better practice than email attachments for anything sensitive, and clients increasingly expect it.
Backups that survive an attack
Immutable or offline backups, tested by restoring. A firm that loses its document management system and cannot restore it has a practice-ending problem, not an IT problem.
Mobile devices
Attorneys read client material on phones constantly. Those devices need encryption, screen lock, remote wipe capability, and separation between firm and personal data. Personal devices holding client material without management is a common and serious gap.
Vendors and the duty that follows the data
Firms use cloud practice management, e-discovery platforms, transcription services, expert witnesses, contract attorneys and outsourced administrative support. Client confidential material reaches all of them.
The confidentiality duty does not stop at the firm's boundary. Reasonable due diligence on vendors handling client information is part of the obligation, and it should be documented — what you assessed, what the vendor committed to, and what is in the contract.
This is also increasingly a client expectation rather than only an ethics matter. Corporate clients ask which subprocessors touch their material.
Breach obligations
If client confidential information is compromised, obligations arrive from several directions at once: the ethical duty to notify affected clients under Opinion 483, state breach notification statutes — New York's SHIELD Act and Connecticut's own requirements both apply on their own terms — and any contractual notification commitments in client engagement or outside counsel guidelines.
Outside counsel guidelines are worth reading carefully in advance. Corporate clients frequently impose notification windows considerably shorter than any statute, along with specific security requirements the firm has already contractually agreed to meet.
| Obligation | Who to notify | Timing |
|---|---|---|
| ABA Formal Opinion 483 | Affected clients | When their material was compromised |
| New York SHIELD Act | Affected NY residents; Attorney General, Department of State and State Police | Within 30 days of discovery |
| Connecticut | Affected residents and the Attorney General | No later than 60 days from discovery |
| Outside counsel guidelines | The client, per the contract | Often considerably shorter than any statute |
A proportionate baseline for a small firm
- MFA on email and every system holding client material, partners included
- SPF, DKIM and DMARC configured correctly
- A written, exception-free payment verification procedure
- Full disk encryption on all devices, personal ones included
- Managed mobile devices where client material is accessed
- Matter-level access control in the document management system
- Immutable backups with tested restores
- Security awareness training, documented, covering the whole firm
- A written incident response plan that identifies who makes the notification decisions
- Documented vendor due diligence for anyone handling client data
None of this is exotic, and all of it is defensible as reasonable effort if something goes wrong anyway — which is the standard the rules actually set.
Sources
- FBI Internet Crime Complaint Center (IC3) — Business Email Compromise: The $50 Billion Scam (Alert I-060923-PSA)
- Cybersecurity and Infrastructure Security Agency (CISA) — BOD 18-01: Enhance Email and Web Security
- New York State Senate — New York General Business Law § 899-AA: Notification; person without valid authorization has acquired private information
- Connecticut Office of the Attorney General — Reporting a Data Breach
- Cybersecurity and Infrastructure Security Agency (CISA) — #StopRansomware Guide


