Your duty of confidentiality does not have an IT exception
A practice holds settlement figures, medical records, custody details and client funds — and is expected to protect all of it under the same professional rules as a firm with a security department. Meanwhile billable hours are the only thing that pays for any of it.
What you are carrying
- Client confidentiality and privilege apply to every file, backup and phone
- Court deadlines make downtime expensive in a way most businesses never experience
- Wire fraud targets trust and escrow accounts specifically
- Corporate clients increasingly send security questionnaires before engaging counsel
- Practice-management and document systems are old, fragile and non-negotiable
What we do about it
- Encryption, access control and retention that map to your confidentiality duties
- Recovery targets set against filing deadlines, and timed restores behind them
- Payment-redirection controls: verified change procedures and email impersonation defence
- Ready-made answers to client security questionnaires, kept current
- We support your practice-management vendor so you are not the middleman
- Secure remote access for court, deposition and home working
Most firms we meet are not careless. They are stretched. The gap is usually documentation and testing, not intent.
How it usually works
What we find in law firms
None of this is about your practice. It is what a firm of your size looks like from the inside when technology has been bought as it was needed, which is how almost all of them got here.
Your duty of confidentiality has no size exemption. A twelve-person firm owes a client the same protection as one with a security department.
ABA Model Rules 1.1 and 1.6 (opens in a new tab)How it got that way
The professional rules were written about the obligation, not about the budget available to meet it. No bar association has ever published a smaller standard for a smaller firm.
What we do
We build to the obligation and tell you plainly which parts we have covered and which parts remain yours.
Technology competence is a stated part of the duty of competence in most states, and it extends to the technology your firm chose.
ABA Model Rule 1.1, Comment 8 (opens in a new tab)How it got that way
Comment 8 to Model Rule 1.1 was amended in 2012 and adopted by the large majority of states since. It arrived quietly, during years when most firms were not watching bar guidance for IT news.
What we do
We keep a written record of what is configured and why, so the reasoning exists in a form other than somebody's memory.
Outside counsel guidelines arrive with a deadline and a security questionnaire, and it is often the first time anyone asks the firm what it actually runs.
How it got that way
Corporate clients started pushing their own vendor-security programmes down to their law firms. The requirement is real and contractual, but it lands on whoever opens the email.
What we do
Send it to us. The technical answers take minutes when somebody already knows the environment, rather than a weekend of guessing.
Every rule above links to the rule itself rather than to our summary of it. If something here does not apply to your firm, that is worth knowing before you budget for it.
Compared honestly
What a generalist provider brings to law firms
A capable generalist provider can secure a law firm. The difference is how much of your professional context you have to explain first.
A generalist
Treats your practice-management system as an application to keep running.
CY6
Treats it as the system your confidentiality duty runs through, and deals with the vendor directly so you are not the middleman.
A generalist
Sets recovery targets against a general service standard.
CY6
Sets them against filing deadlines, and times real restores so the target is a measurement rather than a promise.
A generalist
Hands you the client security questionnaire to fill in.
CY6
Answers the technical sections when you send it over — minutes, because somebody already knows the environment, rather than a weekend of guessing.
Plenty of generalist providers are good at their job. The distinction here is context, not competence.
Rules in play
What you are likely to be measured against
We are not your compliance counsel, and we will say so. What we do is make sure the technical controls and the evidence behind them stand up when someone asks.
- ABA Model Rules 1.1 and 1.6 (competence and confidentiality)
- State bar technology-competence guidance
- Client-imposed outside counsel guidelines
- State breach-notification law
Not sure where you stand?
Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.
Or call 1-855-966-2967