Privilege is a duty. It needs a process, not just a promise.
Model Rule 1.6 puts the burden on you to make reasonable efforts to prevent unauthorized access to client information. Most firms treat that as an IT question. The ABA's own data says otherwise — a third of firms have already been breached, and most never saw it start with a person.
The bar's own survey shows the exposure — and who's expected to catch it.
The ABA's annual Cybersecurity TechReport tracks how firms are actually doing against their ethical obligations. The trend line isn't reassuring, and it gets worse the smaller the firm.
of law firms report having experienced a security breach at some point, per recent ABA Cybersecurity TechReport surveys — a figure that has climbed in more recent survey years.
of solo practitioners report holding primary responsibility for their own firm's security — with no dedicated IT or security staff to share the load.
of the ABA Model Rules of Professional Conduct requires reasonable efforts to prevent unauthorized access to or disclosure of client information.
The leak rarely comes from outside the firm.
Confidentiality failures at firms your size tend to follow a small set of patterns — all human, all visible before they become a bar complaint.
Curiosity outside the matter
An associate or paralegal looks into a file they're not staffed on — a high-profile client, a personal connection, a case that touches someone they know.
The departing associate's export
Someone leaving for a competitor — or to start their own practice — takes client contacts, work product, or matter files with them on the way out.
Shared logins into the DMS
Staff share document management system credentials for convenience. When something goes wrong, there's no way to say who actually touched the file.
Pressure that precedes a lapse
Financial strain, a grievance with the partnership, or burnout precedes a serious ethical shortcut — self-dealing, an unauthorized disclosure, or worse. The runway is visible if someone's watching.
Firms with real exposure and no one whose job this is.
Firms of roughly 5–50 attorneys
Handling litigation, M&A, family law, or other matters where a single leak is a malpractice exposure or a bar complaint — without a Chief Security Officer, and often without a formal security policy at all. Security is whatever the office manager or an IT vendor happens to cover.
Three ways to work together.
Same arc every time: find the gaps, train the eyes, build the program that holds.
Before the Breach
A half-day session for partners, associates, and staff — the precursor framework adapted to matter access, DMS permissions, and Rule 1.6's confidentiality duty, plus a one-page escalation path everyone actually knows.
Program Readiness & Gap Assessment
2–3 weeks: access review across your DMS and case management systems, offboarding process, and policy review — benchmarked against ABA cybersecurity guidance, with a prioritized roadmap your managing partner can act on.
Program Advisory
Ongoing advisory as headcount and matters change — access reviews, refresher training, and incident-response readiness before your malpractice carrier or a client asks.
Curious where your firm actually stands?
A 20-minute call, no pitch. Tell me where you're exposed — I'll tell you honestly whether I can help and where I'd start.
Book a 20-minute call