Skip to content
TECNICODESK

For law firms

Law Firm Cybersecurity and the Rules You Practice Under

How technology competence, confidentiality, and breach duties map to controls a Denver firm can actually put in place.

The short answer

The ABA Model Rules do not prescribe security products. They set a reasonableness standard: Comment 8 to Rule 1.1 makes technology competence part of competence, and Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of or access to client information. Formal Opinions 477R and 483 apply that standard to electronic communication and to what happens after a breach. Colorado has adopted Rules of Professional Conduct that follow the Model Rules on both points.

The four sources that come up most

Model Rule 1.1, Comment 8

Technology competence

Competence includes keeping abreast of the benefits and risks of relevant technology. In practice: knowing where client data lives and who can reach it.

Model Rule 1.6(c)

Reasonable efforts to protect

Make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation.

Formal Opinion 477R

Securing client communication

A fact-specific analysis rather than a blanket encryption rule. Sensitivity of the matter drives how much protection is reasonable.

Formal Opinion 483

After a breach

Monitor for breaches, act to stop and remediate them, and notify current clients whose material confidential information was compromised.

Tecnico Desk is an IT and security provider, not a law firm. Nothing on this page is legal advice or an interpretation of your professional obligations. Confirm how these rules apply to your practice with your own counsel or your state bar.

What a reasonableness standard looks like as controls

Because the rules describe an outcome rather than a product, the useful question is what a reviewing eye would expect a firm your size to have done. These are the controls that come up in client security reviews, insurer questionnaires, and post-incident conversations.

  • Multi-factor authentication on every account, including administrators and shared mailboxes
  • Access limited by matter and role, so a departing associate cannot reach everything
  • Email authentication with SPF, DKIM, and DMARC, to make your domain harder to impersonate
  • A secure way to send sensitive documents, and staff who know when to use it
  • Device encryption and a way to wipe a lost laptop or phone
  • Backups that have been restored at least once, not just configured
  • Logging that can answer what was accessed, when, and by whom
  • Onboarding and offboarding that actually closes accounts and mailbox delegation

Trust accounts and wire fraud

The single most expensive incident pattern for small firms is business email compromise around a funds transfer. An attacker watches a mailbox, waits for a closing or settlement, and sends altered wire instructions from a lookalike domain or a compromised account. Trust account balances make firms a deliberate target rather than a bystander.

The defenses are unglamorous and effective: mailbox monitoring for forwarding rules an attacker added, DMARC so your domain is harder to spoof, and a documented rule that wire instructions are confirmed by phone using a number you already had on file. See email and DMARC security.

Where to start

A Tecnico Ready security review maps what your firm has against what a reviewer would expect, in plain English. Tecnico Defend keeps the controls monitored and produces the monthly evidence. For the practice-wide view, see IT support for law firms in Denver, and for the notification clock see Colorado breach notification requirements.

FAQ

Frequently asked questions

Do the ABA rules require law firms to use specific security technology?

No. The Model Rules set a reasonableness standard rather than a technology checklist. Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of or access to client information, and what counts as reasonable depends on the sensitivity of the matter, the cost of safeguards, and how difficult they make the work.

What does technology competence mean in practice?

Comment 8 to Model Rule 1.1 says competence includes keeping abreast of the benefits and risks of relevant technology. For most firms that means understanding where client data actually lives, who can reach it, and what happens if an account is compromised, rather than becoming a security engineer.

Does a firm have to tell clients about a breach?

ABA Formal Opinion 483 addresses obligations after a data breach or cyberattack, including the duty to monitor for breaches, act to stop and remediate them, and notify current clients when material confidential information relating to their representation was compromised. Separately, Colorado's breach notification statute may require notice to affected residents. Your counsel should decide what a specific incident requires.

Is email encryption required?

ABA Formal Opinion 477R takes a fact-specific approach rather than a blanket rule. Ordinary email may be reasonable for routine matters, while particularly sensitive information may call for stronger protection. The practical work is making sure a secure option exists and that staff know when to use it.

What does Tecnico Desk actually do here?

We implement and evidence the technical controls: identity and access, email authentication, device and file protection, backups, logging, and clean onboarding and offboarding. We do not interpret your professional obligations, and we work alongside your counsel rather than replacing them.

Firms that also handle tax or bookkeeping work for clients should read IRS WISP requirements, and every Colorado firm should know the deadline in Colorado breach notification requirements.

Find out where your firm stands

Book a Security Fit Call and we will walk through what your firm has today and what a client or insurer would expect to see.