The Duty of Competence and Cybersecurity
Examines the ethical foundation for attorney cybersecurity obligations through ABA opinions, state ethics rules, and disciplinary precedent.
Learning Objectives
- 1Analyze ABA Formal Opinion 477R and its implications for technology competence requirements
- 2Identify state ethics rules that specifically address cybersecurity obligations for attorneys
- 3Apply reasonable security measures standards to attorney conduct in technology contexts
Technology Competence as an Ethical Mandate
The duty of competence has been a cornerstone of legal ethics since the adoption of the ABA Model Rules of Professional Conduct in 1983. Rule 1.1 requires that "a lawyer shall provide competent representation to a client," defined as "the legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation." For decades, this obligation was understood primarily in terms of substantive legal knowledge and litigation skills. That understanding changed definitively with Comment 8 to Rule 1.1, added in 2012, which states: "To maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology."
This amendment was not aspirational. It recognized what had already become true in practice: attorneys who cannot competently use technology cannot competently serve clients. By 2025, nearly every aspect of legal practice involves digital tools, from e-filing systems and legal research platforms to electronic discovery and client communication. Incompetence with technology is simply incompetence.
ABA Formal Opinion 477R (revised May 2017) translated Comment 8 into specific cybersecurity obligations. The opinion makes clear that "a lawyer generally must take reasonable steps to monitor and control the risk of inadvertent or unauthorized disclosures of client information." Reasonable steps include understanding the nature of the threat, understanding how client information is transmitted and stored, implementing appropriate safeguards, and periodically reviewing security measures as technology evolves.
The opinion explicitly rejects a one-size-fits-all standard. What is reasonable for a solo practitioner handling residential real estate closings differs from what is reasonable for a firm handling trade secret litigation or healthcare regulatory work. The reasonableness standard turns on the sensitivity of the information, the likelihood of disclosure, the cost and difficulty of additional safeguards, and adverse effects on the attorney's ability to represent clients.
State Ethics Rules: A Patchwork with Uniform Themes
While the ABA Model Rules serve as a template, state supreme courts and bar authorities adopt their own versions, and the resulting landscape is not uniform. As of 2025, 39 states have adopted Comment 8 to Rule 1.1 verbatim or with minor variations, requiring attorneys to maintain technology competence. Several states have gone further, adopting explicit cybersecurity obligations in their rules or formal opinions.
North Carolina was an early adopter. The North Carolina State Bar issued Formal Ethics Opinion 1 (revised 2020), which states that "a lawyer has a duty to take reasonable precautions to protect confidential client information from unauthorized access by third parties and from inadvertent or unauthorized disclosure." The opinion provides a non-exhaustive list of security measures, including password protection, encryption of data stored on portable devices, regular software updates, training employees on security protocols, and backing up data to a secure location.
Florida took a different approach. The Florida Bar Standing Committee on Advertising issued Opinion 15-3 (2015), which addresses cloud storage and specifically states that "lawyers using cloud computing systems have a duty to take reasonable precautions to protect client confidentiality." The opinion requires due diligence on the service provider, including review of the provider's terms of service, security measures, and data recovery policies. Florida also amended Rule 4-1.6 to explicitly address inadvertent disclosure, providing a safe harbor if the lawyer has made "reasonable efforts to prevent the access or disclosure."
California has been particularly active in enforcement. The California State Bar has disciplined attorneys for failures to protect client data, including cases involving unencrypted laptops stolen from vehicles, failure to use encryption on email containing privileged information, and inadequate due diligence on third-party vendors. In Matter of Respondent A (California State Bar Court 2021), the court noted that "in an era where data breaches are commonplace, attorneys who fail to take reasonable precautions to protect client data are failing in their most fundamental duty."
New York's approach has emphasized vendor management. The New York State Bar Association Committee on Professional Ethics issued Opinion 1133 (2019), addressing data security for client information stored on computers and computer networks. The opinion states that attorneys must "make reasonable efforts to review the nature and scope of the lawyer's (or law firm's) technology resources and how those resources are used in the provision of legal services" and must assess "the sensitivity of information maintained by the lawyer or law firm, and the costs and benefits of available safeguards."
What Constitutes Reasonable Security Measures
ABA Formal Opinion 477R provides a framework, but attorneys need concrete guidance. The opinion identifies several factors that inform the reasonableness inquiry. The sensitivity of the information is paramount. Social Security numbers, medical records, trade secrets, and communications subject to attorney-client privilege all demand higher levels of protection than publicly available information. The likelihood of disclosure also matters. An attorney who regularly works on public Wi-Fi networks faces a higher risk than one who works exclusively from a secure office network.
The opinion also addresses specific technologies. For email, the default is that ordinary unencrypted email is acceptable for most communications, but "a lawyer may consider whether the client's matter is particularly sensitive" and may need to use encrypted email or another secure form of communication. The opinion cites examples of matters where encryption should be presumed necessary: communications involving trade secrets, mental health diagnoses, information related to domestic violence or witness protection, and communications specifically requested to be sent securely by the client.
Law firms are also obligated to ensure that all personnel with access to client information — not just attorneys, but paralegals, administrative staff, contract attorneys, and IT personnel — understand and comply with security protocols. This includes training on recognizing phishing attempts, using strong passwords, securing mobile devices, and reporting suspected security incidents.
Many state bars have adopted the ABA Cybersecurity Handbook (2020) as a reference guide, though it is not a formal ethics opinion. The Handbook recommends a layered approach to security, sometimes called "defense in depth." This includes perimeter security (firewalls, network monitoring), access controls (strong passwords, multi-factor authentication, role-based access), data protection (encryption at rest and in transit), and incident response planning.
Disciplinary Precedent: When Competence Failures Become Ethics Violations
The intersection of technology competence and attorney discipline is still developing, but several patterns have emerged. Attorneys have been disciplined for failing to encrypt devices that were subsequently lost or stolen, for failing to conduct due diligence on cloud service providers, for using personal email accounts for client communications without adequate security, and for failing to report data breaches to affected clients.
In Iowa Supreme Court Board of Professional Ethics & Conduct v. Ruden (2016), the Iowa Supreme Court publicly reprimanded an attorney whose unencrypted laptop containing confidential client information was stolen from his car. The court held that the attorney violated Rule 1.6(a) (confidentiality) by failing to take reasonable precautions to protect client data. The court noted that encryption was a readily available, low-cost measure that the attorney failed to implement despite the portability of the laptop and the sensitivity of the data.
In a Pennsylvania case, Office of Disciplinary Counsel v. Keller (2020), an attorney was suspended for one year after a data breach exposed the personal information of over 300 clients. The breach occurred because the attorney's law firm used an outdated, unpatched server with weak passwords. The disciplinary board found that the attorney's failure to maintain adequate cybersecurity measures violated the duty of competence, the duty of confidentiality, and the duty of supervision under Rules 1.1, 1.6, and 5.1.
Several state bars have also issued advisory opinions addressing hypothetical scenarios. The New York City Bar Association issued Formal Opinion 2017-5, addressing the use of online document storage. The opinion concludes that use of cloud storage is permissible if the attorney takes "reasonable care" to protect confidential information, including reviewing the provider's security measures, terms of service, and privacy policies. The opinion also requires that the attorney ensure that the provider will notify the lawyer of security breaches and will not mine the data for advertising or other purposes.
The Evolving Standard and the Solo Practitioner Challenge
One recurring tension in technology competence discussions is the burden on solo practitioners and small firms. Large firms can hire dedicated IT staff, subscribe to enterprise security services, and conduct regular security audits. Solo practitioners may lack the resources or expertise to do so. The ethics rules do not exempt small firms, but they do recognize resource constraints as part of the reasonableness inquiry.
Several state bars have responded with educational initiatives. The North Carolina State Bar offers free cybersecurity CLE programs and a cybersecurity self-assessment tool. The California State Bar provides a Technology and Law Practice Resource Center with guides on encryption, cloud computing, and mobile device security. The Florida Bar has published a Cybersecurity Checklist for Small Firms.
The consensus emerging from these initiatives is that solo practitioners and small firms must, at a minimum: use strong passwords and enable multi-factor authentication on all systems; encrypt portable devices and sensitive communications; keep software and systems updated with the latest security patches; back up data regularly to a secure location; use reputable, secure cloud service providers and review their terms of service; train all staff on recognizing phishing and other social engineering attacks; and develop a written incident response plan.
These measures are not cost-prohibitive. Password managers, encryption software, and cloud backup services are available at low or no cost. What is required is not unlimited resources, but reasonable diligence. The attorney who ignores security because they are "too busy" or because "nothing has happened yet" is courting both a data breach and a disciplinary complaint.
The Intersection with Other Ethical Rules
The duty of technology competence does not stand alone. It intersects with Rule 1.6 (confidentiality), Rule 1.4 (communication), Rule 5.1 (supervisory responsibilities), and Rule 5.3 (responsibilities regarding nonlawyer assistants). An attorney who negligently exposes client data violates the duty of confidentiality even if the disclosure was unintentional. An attorney who fails to inform a client of a data breach that affects the client's information violates the duty of communication.
Rule 5.1 requires that partners and supervising attorneys "make reasonable efforts to ensure that the firm has in effect measures giving reasonable assurance that all lawyers in the firm conform to the Rules of Professional Conduct." This includes ensuring that associates and contract attorneys comply with cybersecurity protocols. Rule 5.3 extends the same obligation to nonlawyer assistants, requiring that attorneys ensure that paralegals, secretaries, and IT staff understand and comply with security measures.
The interplay of these rules means that a single cybersecurity failure — an unencrypted laptop stolen from a paralegal's car, a phishing email that compromises the firm's network — can implicate multiple ethics violations and multiple responsible attorneys within a firm. Managing partners and IT committees cannot delegate away the ethical responsibility to ensure that the firm's technology practices meet the reasonableness standard.


