Cybersecurity: Solo and Small Firm Perspective on Protecting Client Data - Conclusion

V. Conclusions

All lawyers, including solos and small firms, have ethical duties to maintain the confidentiality of client data used in their practices, to act competently in their practices, and to supervise staff and third parties with access to client data. These duties appear in the ABA Model Rules of Professional Conduct and state rules of professional conduct. These are non-delegable duties. Lawyers must provide leadership and manage the information security functions in their firms and not simply turn over all information security functions to their staffs.

With increasing information security threats from various state and non-state actors, coupled with rapid advances in technology and how it is used, law firms face ever-greater threats to client data. The rules call for attorneys to use reasonable care to protect client data. An effective security program of administrative, physical, and technical safeguards can help a law firm and its lawyers mitigate their information security risks and comply with ethical obligations. Solos and small firms can and must implement reasonable safeguards that are appropriate for the size of their practices. Over time, there will be breaches. Nonetheless, if small practices implement and maintain an effective information security program, they can effectively manage their risk of breaches and resulting liability.

For more information, contact:

Stephen Wu,, 408.573.5737

Drew Simshaw,, 202.662.9067

