The first flag is human · Law firms

Privilege is a duty. It needs a process, not just a promise.

Model Rule 1.6 puts the burden on you to make reasonable efforts to prevent unauthorized access to client information. Most firms treat that as an IT question. The ABA's own data says otherwise — a third of firms have already been breached, and most never saw it start with a person.

The regulatory backdrop

The bar's own survey shows the exposure — and who's expected to catch it.

The ABA's annual Cybersecurity TechReport tracks how firms are actually doing against their ethical obligations. The trend line isn't reassuring, and it gets worse the smaller the firm.

~30%

of law firms report having experienced a security breach at some point, per recent ABA Cybersecurity TechReport surveys — a figure that has climbed in more recent survey years.

ABA Cybersecurity TechReport, multi-year survey data
80%

of solo practitioners report holding primary responsibility for their own firm's security — with no dedicated IT or security staff to share the load.

ABA Legal Technology Survey Report
Rule 1.6

of the ABA Model Rules of Professional Conduct requires reasonable efforts to prevent unauthorized access to or disclosure of client information.

ABA Model Rules of Professional Conduct
What actually goes wrong

The leak rarely comes from outside the firm.

Confidentiality failures at firms your size tend to follow a small set of patterns — all human, all visible before they become a bar complaint.

Curiosity outside the matter

An associate or paralegal looks into a file they're not staffed on — a high-profile client, a personal connection, a case that touches someone they know.

The departing associate's export

Someone leaving for a competitor — or to start their own practice — takes client contacts, work product, or matter files with them on the way out.

Shared logins into the DMS

Staff share document management system credentials for convenience. When something goes wrong, there's no way to say who actually touched the file.

Pressure that precedes a lapse

Financial strain, a grievance with the partnership, or burnout precedes a serious ethical shortcut — self-dealing, an unauthorized disclosure, or worse. The runway is visible if someone's watching.

Who this is for

Firms with real exposure and no one whose job this is.

Law firms

Firms of roughly 5–50 attorneys

Handling litigation, M&A, family law, or other matters where a single leak is a malpractice exposure or a bar complaint — without a Chief Security Officer, and often without a formal security policy at all. Security is whatever the office manager or an IT vendor happens to cover.

Services

Three ways to work together.

Same arc every time: find the gaps, train the eyes, build the program that holds.

Start here 01 · Workshop

Before the Breach

Train the eyes

A half-day session for partners, associates, and staff — the precursor framework adapted to matter access, DMS permissions, and Rule 1.6's confidentiality duty, plus a one-page escalation path everyone actually knows.

From $3,500Founding rate $2,500 for the first cohorts
02 · Assessment

Program Readiness & Gap Assessment

Find the gaps

2–3 weeks: access review across your DMS and case management systems, offboarding process, and policy review — benchmarked against ABA cybersecurity guidance, with a prioritized roadmap your managing partner can act on.

From $5,500Fixed fee · scope set before we start
03 · Retainer

Program Advisory

Build it for real

Ongoing advisory as headcount and matters change — access reviews, refresher training, and incident-response readiness before your malpractice carrier or a client asks.

From $3,000/mo6-month minimum
Let's talk

Curious where your firm actually stands?

A 20-minute call, no pitch. Tell me where you're exposed — I'll tell you honestly whether I can help and where I'd start.

Book a 20-minute call