Skip to content
Interdisciplinary CurriculumCurriculum

Your learning stays with you.

Purchase Terms

© 2026 Commensurate Ventures. All rights reserved.

Interdisciplinary CurriculumCurriculum
All Courses

Cybersecurity & Client Data Protection for Attorneys

ABA ethics obligations meet cybersecurity practice. Covers technology competence duties, threat landscape for law firms, client data classification, email security, cloud vendor risk, incident response, and building a security culture.

8 Units
20 minutes per unit
Curriculum Map

What You Will Learn

Ethics & Cybersecurity

ABA Formal Opinion 477R established the duty to use reasonable security measures. Learn what "reasonable" means in practice.

Law Firm Threats

Law firms hold privileged communications, trade secrets, and M&A intelligence. Understand why you are a high-value target.

Incident Response

Forensic investigation privilege, breach notification, client communication, and when you must report to the bar.

All Units

1
20 minutes
The Duty of Competence and Cybersecurity
Examines the ethical foundation for attorney cybersecurity obligations through ABA opinions, state ethics rules, and disciplinary precedent.
  • •Analyze ABA Formal Opinion 477R and its implications for technology competence requirements
  • •Identify state ethics rules that specifically address cybersecurity obligations for attorneys
  • •Apply reasonable security measures standards to attorney conduct in technology contexts
Start learning
2
20 minutes
The Threat Landscape for Law Firms
Surveys the cyber threat environment for legal practices, including ransomware, business email compromise, nation-state espionage, and insider threats.
  • •Identify the primary cyber threats facing law firms and assess their relative risk profiles
  • •Analyze why law firms are high-value targets for sophisticated threat actors
  • •Distinguish between external attacks and insider threats in the legal context
Start learning
3
20 minutes
Client Data Classification and Protection
Analyzes the classification of client data including PII, PHI, trade secrets, and privileged communications, with corresponding encryption and handling requirements.
  • •Classify client data according to sensitivity and regulatory requirements
  • •Apply differential protection standards based on data classification levels
  • •Identify when specific data types trigger heightened encryption or handling obligations
Start learning
4
20 minutes
Email Security and Confidentiality
Addresses email security protocols for attorneys, including encryption standards, metadata management, inadvertent disclosure, and privilege waiver risks.
  • •Evaluate when unencrypted email is ethically permissible versus when encryption is required
  • •Identify metadata risks in email communications and apply strategies to mitigate disclosure
  • •Analyze inadvertent disclosure scenarios and apply privilege preservation protocols
Start learning
5
20 minutes
Cloud Services and Vendor Risk Management
Examines vendor risk management for cloud services, including SaaS agreements, BAAs, data sovereignty, vendor due diligence, and exit strategies.
  • •Evaluate cloud service agreements for compliance with attorney confidentiality obligations
  • •Identify when Business Associate Agreements are required for legal technology vendors
  • •Develop vendor due diligence procedures appropriate to the sensitivity of client data
Start learning
6
20 minutes
Incident Response Planning for Law Firms
Provides a framework for incident response in law firms, covering breach detection, forensic investigation, notification obligations, privilege protection, and bar reporting requirements.
  • •Develop an incident response plan that addresses breach notification, client communication, and regulatory reporting
  • •Analyze privilege considerations in engaging forensic investigators and breach counsel
  • •Apply state breach notification laws to determine when and how to notify affected individuals
Start learning
7
20 minutes
Mobile Device Security and Remote Access
Covers mobile device security for legal practice, including BYOD policies, mobile device management, remote wipe capabilities, VPN requirements, and public Wi-Fi risks.
  • •Develop BYOD policies that balance attorney autonomy with firm security requirements
  • •Implement technical controls for remote wipe, containerization, and VPN access
  • •Identify and mitigate risks associated with public Wi-Fi and unmanaged networks
Start learning
8
20 minutes
Building a Security Culture: Training, Policies, and Compliance
Examines the human and organizational dimensions of law firm cybersecurity, including phishing simulations, security policies, access controls, and building sustained compliance.
  • •Design security awareness training programs that address attorney-specific threat scenarios
  • •Implement access controls based on least privilege and role-based access principles
  • •Develop ongoing compliance monitoring and policy enforcement mechanisms
Start learning

Continuing legal education. 3 credit hours (Technology). Accepted for attorneys in jurisdictions recognizing CLE.