Model Rule 1.6(c) reads like eleven words nobody at a two-partner firm has time to think about: a lawyer "shall make reasonable efforts to prevent the unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." Big firms answer it with a compliance department. Solo and small-firm lawyers answer it, in practice, with whatever email and cloud storage they already had before they ever read the rule.
That gap is exactly where bar complaints and malpractice claims come from — not from a sophisticated nation-state attacker, but from a paralegal's old laptop, a shared Dropbox link that was never revoked, or a "temporary" spreadsheet of client passwords that outlived the intern who made it.
01What "reasonable efforts" actually means
The rule doesn't define a technology standard, and that's the trap. Comment 18 to Rule 1.6 lists factors regulators weigh after the fact: the sensitivity of the information, the likelihood of disclosure if safeguards aren't used, the cost and difficulty of implementing safeguards, and how those safeguards affect the lawyer's ability to represent the client. In practice, that means the bar is asking whether a reasonable lawyer — not a reasonable IT department — would have seen the risk coming.
"Reasonable efforts" is not a technology purchase. It is a written policy, a paper trail, and someone who can prove both existed before the breach.
02The eight-item checklist
None of the following requires a security hire. Each item is something one partner or office manager can own directly. Check them off as you close them out — the state persists in this browser so you can pick the list back up later.
- Written policyA one-page data-handling policy every attorney and staff member can point to — not tribal knowledge held by whoever set up the email.
- MFA everywhere client data livesEmail, document management system, cloud storage, and remote access — not just the tools that make it easy to enable.
- Encryption confirmed, not assumedGet your DMS and email vendor to state plainly, in writing, that data is encrypted at rest and in transit — "enterprise-grade" is marketing language, not a control.
- Vendor review before signingGet the subprocessor list and breach-notification terms before a single client file goes into a new tool, not after.
- Same-day offboardingAccess to every system is revoked the day a paralegal or associate leaves — not at the next IT check-in.
- Written incident response planWho calls whom, in what order, within how many hours — decided before you need it, not improvised during it.
- Insurance renewal cross-checkRead what your malpractice or cyber carrier's renewal application actually asks, then make sure the honest answer is yes before they ask it.
- Annual technology competence reviewComment 8 to Model Rule 1.1 makes staying current on relevant technology part of competent representation, not an IT department's problem alone.
0 of 8 closed
03What this doesn't cover
This checklist is a floor, not a defense. It won't tell a state bar investigator your firm was breach-proof — nothing does. What it gives you is the paper trail Comment 18's factors actually ask for: evidence that the risk was considered, a safeguard was chosen on purpose, and someone can show their work. That paper trail is usually the difference between a bad week and a bar complaint that goes nowhere.