The conversation around cybersecurity in legal practice has shifted dramatically in the last decade. Where firms once viewed IT as a back-office expense, today's regulators, judges, and clients view it as a professional responsibility, and frankly, a competence issue.
The American Bar Association's Model Rule 1.6(c) makes this explicit: a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. Most state bars have adopted parallel rules. Some have gone further with specific data breach notification requirements.
Below are the realities that drive every architectural decision we make. We've put them in plain language because the consequences are plain. We invite you to share these with your managing partner. These should be conversations your firm has had, on the record.