Answer · Updated August 2026
What cybersecurity does the ABA require of lawyers?
Direct answer
The ABA doesn't certify specific tools, but three authorities define the duty: Model Rule 1.1 Comment 8 requires technology competence; Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to client information; and Formal Opinions 477R and 483 set expectations for secure communication and breach response. 'Reasonable' scales with data sensitivity and threat likelihood — and documented testing is the standard way to prove your efforts were reasonable.
The three pillars
Every state-bar analysis of a lawyer's security duty traces back to the same sources:
- Model Rule 1.1, Comment 8: competence includes understanding the benefits and risks of relevant technology — you cannot delegate that judgment entirely to an IT vendor.
- Model Rule 1.6(c): you must make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or access to, client information.
- Formal Opinion 477R: securing client communications, with a factors-based approach to what 'reasonable' means for your practice.
- Formal Opinion 483: after a breach, you have obligations to assess, to remediate, and to notify affected current clients.
What 'reasonable efforts' means in practice
Reasonableness is a sliding scale: the sensitivity of the information, the likelihood of disclosure, the cost and difficulty of safeguards, and whether safeguards would impair representation. A solo estate planner and a 200-attorney M&A practice are not held to identical stacks — but both are expected to know their exposure, to have basic controls (MFA, encryption, patching, training), and to be able to show their work.
The evidence bar
After an incident, the question is never just 'were you breached' — it is 'can you document reasonable efforts?' The firms that answer well keep a written security program, a testing cadence with dated reports, remediation records, and training logs. Continuous assessment produces this evidence as a byproduct instead of a scramble.
Related questions
Do state bars follow the ABA rules exactly?
Most states adopt versions of the Model Rules, often with local amendments, and several bars have issued their own cybersecurity opinions. The ABA framework is the floor nearly everywhere — check your jurisdiction's specifics.
Is using cloud practice-management software a Rule 1.6 violation?
No. Formal Opinion 477R and many state opinions accept cloud providers when lawyers exercise reasonable care in selecting and configuring them — which includes verifying the vendor's security posture and your own tenant settings.
What is the single most-cited gap in bar discipline and insurance disputes?
The absence of documentation. Firms often had reasonable tools in place but could not produce a written program, testing evidence, or training records when it mattered.
