ABA Model Rule 1.6: A Practical Cybersecurity Checklist for 2026
Rule 1.6(c) requires 'reasonable efforts' to protect client information. Here's what reasonable actually looks like in 2026 — and how to document it.

Why Rule 1.6 is now a technical standard
For years, "reasonable efforts" was treated as a posture, not a checklist. In 2026, state bars and malpractice carriers are reading it the way courts read HIPAA — as an enforceable security baseline.
The non-negotiables
Every firm, regardless of size, should be able to produce evidence of:
- MFA on every account that can read client data — including legacy IMAP and document management portals.
- Encrypted backups stored off-network, tested quarterly.
- A documented incident response plan with named decision-makers.
- A current attack-surface inventory: every domain, subdomain, and exposed service.
- Vendor security review for any third party that touches privileged data.
What "reasonable" looks like in a deposition
Bar counsel and plaintiff's experts will ask three questions: what did you know, what did you do about it, and can you prove it? The firms that survive those questions have continuous monitoring and a date-stamped report log — not a once-a-year pentest PDF in a shared drive.
Where to start this week
Run an external attack-surface scan today. Fix anything critical within 72 hours. Schedule a tabletop exercise for the next quarter. Document everything.
Free Assessment
See what an attacker sees.
Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.
Start the assessment


