By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 26, 2026
Quick Answer
Every lawyer in the US and Canada carries a professional duty to protect client confidential information, and that duty now reaches technology directly. In the US, ABA Model Rules 1.1 and 1.6 establish competence and confidentiality obligations that explicitly extend to the technology a lawyer uses. In Canada, provincial Law Society rules impose parallel duties. Both frameworks have evolved to treat cybersecurity controls as a component of the professional duty, not an optional IT investment, which is one reason why law firms are targeted has become a governance question rather than a technical one. These lawyer cybersecurity obligations are the baseline every firm is measured against.
Key Takeaways
- ABA Model Rule 1.1 requires lawyers to maintain competence, which the ABA has explicitly extended to understanding the risks of technology used in practice.
- ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized disclosure of client information, which bar opinions have applied to cybersecurity controls.
- State bars across the US have issued formal opinions applying ABA rules to cloud storage, email encryption, and breach notification.
- Canadian Law Society rules in all provinces require reasonable steps to safeguard client information, with increasing technical interpretation of what those steps must include.
- PIPEDA in Canada and state data breach notification laws in the US add statutory privacy obligations on top of professional conduct requirements.
The US Framework: ABA Model Rules and State Bar Guidance
Rule 1.1: Competence Includes Technology
ABA Model Rule 1.1 requires lawyers to provide competent representation, which includes the legal knowledge, skill, thoroughness, and preparation reasonably necessary for the representation. Comment 8 to Rule 1.1 was amended in 2012 to add that competence includes keeping abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.
This amendment has been interpreted broadly. A lawyer who uses cloud-based practice management software, sends client documents over unencrypted email, or accesses privileged materials on an unsecured public network is using technology. The duty of competence requires understanding the risks of that technology and taking appropriate steps to mitigate them. Ignorance of cybersecurity risks is not a defence to a competence finding.
Most US states have adopted Rule 1.1 with the technology competence comment. California, New York, Florida, Texas, and other major jurisdictions all incorporate the technology competence standard. State-specific variations exist, but the principle that lawyers must understand and manage the technology risks of their practice is consistent across jurisdictions.
Rule 1.6(c): Reasonable Efforts to Prevent Unauthorized Disclosure
ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. The comment to Rule 1.6 identifies factors relevant to what constitutes reasonable efforts: the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, the cost of employing additional safeguards, the difficulty of implementing the safeguards, and the extent to which the safeguards adversely affect the lawyer’s ability to represent clients effectively.
The practical consequence of Rule 1.6(c) is that lawyers must actively assess the security of their technology environment against the sensitivity of the client information it holds. A solo practitioner handling residential real estate transactions faces different reasonable-effort expectations than a partner at an Am Law 100 firm handling cross-border M&A for public companies. The standard scales with risk, but it applies to both.
State Bar Formal Opinions on Technology
State bars across the US have issued formal opinions applying ABA rules to specific technology scenarios. ABA Formal Opinion 477R, issued in 2017, addresses the duty to protect confidential information when using internet-based or cloud-based communication and storage technology. It concludes that lawyers must assess the risks of transmitting and storing client information electronically, consider the sensitivity of the information, and take reasonable precautions, which for highly sensitive matters may include encrypted communication.
New York State Bar Association Opinion 1019 and California Formal Opinion 2010-179 address the use of technology and the electronic storage of client files, establishing that lawyers using cloud and remote-access tools must take reasonable precautions. New York’s SHIELD Act imposes additional data security requirements on any business holding private information of New York residents, which applies to law firms with New York clients regardless of where the firm is based.
Breach Notification Obligations
When a law firm experiences a breach that results in unauthorized access to client information, professional responsibility obligations require prompt notification to affected clients. ABA Formal Opinion 483 addresses this specifically, concluding that lawyers have a duty to notify clients when a data breach compromises information relating to their representation, and to take reasonable steps to stop an ongoing breach and mitigate its effects.
State data breach notification laws impose additional statutory notification requirements that operate alongside professional conduct obligations. Most states require notification to affected individuals within defined timelines, often 30 to 90 days of discovery depending on the state. New York’s SHIELD Act applies to firms holding private information of New York residents, and California’s privacy law, the CCPA as amended by the CPRA, applies to firms that meet its business thresholds, in both cases regardless of where the firm is located.
The Canadian Framework: Law Society Rules and Privacy Law
Provincial Law Society Rules
Each Canadian province has a Law Society that governs the professional conduct of lawyers. All provincial Law Society rules include a duty of confidentiality that requires lawyers to protect client information from unauthorized disclosure. The rules do not specify technical standards, but they impose a duty of competence alongside the duty of confidentiality that has increasingly been interpreted to include understanding the risks of technology used in practice.
The Law Society of Ontario’s Rules of Professional Conduct require that lawyers take reasonable steps to maintain information received in confidence. LSO guidance on cybersecurity has referenced the need for lawyers to understand how their technology stores and transmits client information and to take steps appropriate to the sensitivity of that information. Practice management reviews by the LSO have begun to include questions about cybersecurity practices, signalling that technical controls are within the scope of professional compliance.
Similar guidance has been issued by the Law Society of British Columbia, the Barreau du Quebec, and other provincial bodies. The Barreau du Quebec’s approach is shaped additionally by Quebec Law 25, which imposes specific privacy officer requirements and confidentiality incident reporting obligations that directly affect law firms with Quebec clients or operations.
PIPEDA and Law 25
The Personal Information Protection and Electronic Documents Act applies to law firms collecting personal information about clients, opposing parties, and witnesses in the course of legal practice. PIPEDA requires protection of personal information with safeguards appropriate to the sensitivity of the data, and reporting of breaches that pose a real risk of significant harm to the Privacy Commissioner of Canada and affected individuals.
Quebec Law 25 applies to firms with Quebec clients or operations and imposes requirements that go beyond PIPEDA in several respects: a mandatory designated privacy officer, privacy impact assessments for new technology deployments, and confidentiality incident reporting with defined timelines. The Barreau du Quebec has engaged with Law 25 obligations specifically in the context of legal practice, and firms with Quebec operations face a layered compliance environment that combines professional conduct rules with statutory privacy law.
What Do These Obligations Mean in Practical Terms?
The professional and statutory obligations facing law firms in the US and Canada converge on a common set of practical requirements. Lawyers must understand the technology they use well enough to assess its risks. They must implement safeguards appropriate to the sensitivity of the client information held in that technology. They must have a plan for responding to breaches and notifying affected clients. And they must be able to document that they took these steps.
The documentation requirement is particularly important because professional discipline proceedings and civil litigation following a breach will ask what safeguards were in place and why. A firm that can produce a written information security programme, evidence of MFA deployment, a tested incident response plan, and a record of annual security testing is in a fundamentally different position than one that relied on a trusted IT provider without documented standards. Building documented controls and compliance evidence is what turns a professional obligation into something a firm can actually demonstrate.
Armour Cybersecurity helps law firms build the law firm cybersecurity services and compliance evidence that satisfy professional responsibility obligations across both US and Canadian jurisdictions. The programme covers the technical controls, the policy documentation, and the incident response capability that professional rules require, structured to be defensible to a Law Society, a state bar, or a court.
Frequently Asked Questions
Does Rule 1.6 require us to encrypt every client email?
ABA Formal Opinion 477R concludes that lawyers generally may transmit client information via unencrypted email, but must consider whether the sensitivity of the information and the circumstances of transmission require stronger protection. For highly sensitive matters, confidential settlement negotiations, privileged strategy discussions, or personal financial information, Opinion 477R suggests that encryption and additional precautions may be required. The standard is risk-based, not categorical, but it requires the lawyer to make an active assessment rather than defaulting to unencrypted email for all matters.
Are we required to notify a Law Society after a breach?
Professional conduct rules in most Canadian provinces do not impose a specific breach notification obligation to the Law Society itself, though some may require disclosure if the breach results in a practice management issue or client harm that the lawyer is obligated to report. The obligation to notify affected clients is clearer and more immediate. In the US, some state bars have issued guidance requiring prompt notification to affected clients. PIPEDA breach reporting to the Privacy Commissioner is a statutory obligation that applies regardless of professional conduct rules. Legal counsel familiar with both professional conduct and privacy law should be involved in breach notification decisions.
What is the duty of competence requirement for technology in practice?
The duty requires that lawyers understand the technology they use well enough to assess its risks to client confidentiality and take reasonable steps to mitigate those risks. It does not require lawyers to be cybersecurity experts. It does require that someone with appropriate expertise assess the firm’s technology environment against the risks it faces, implement controls appropriate to those risks, and maintain those controls over time. Armour’s vCISO service provides that expertise in a structure that is appropriate and affordable for law firms of all sizes.
How do we handle privilege when working with an external cybersecurity firm?
Engaging a cybersecurity firm through outside counsel, or under an engagement letter specifically designed to support work product protection, helps preserve privilege over investigation findings. For incident response specifically, engaging outside counsel to retain the cybersecurity firm as a vendor provides the strongest basis for privilege protection over investigation work product. Armour works with law firms under NDAs and engagement structures designed with this consideration in mind, and coordinates with firms and their counsel to structure engagements appropriately.
The Bottom Line
Cybersecurity stopped being optional for lawyers the moment competence and confidentiality were read to include the technology they practise on. In the US that reading runs through ABA Model Rules 1.1 and 1.6 and a line of state bar opinions from 477R to 483; in Canada it runs through provincial Law Society duties, PIPEDA, and Quebec Law 25. The rules do not hand a firm a checklist, they hand it a standard: understand your technology, protect client information in proportion to its sensitivity, be ready to respond to a breach, and be able to prove you did all three. The firms that treat that as a documentation and controls problem, rather than a hope-nothing-happens problem, are the ones who can answer a regulator or a court with evidence. Armour Cybersecurity helps law firms build law firm cybersecurity services that satisfy professional conduct obligations under ABA rules, Canadian Law Society requirements, PIPEDA, and Law 25, so professional responsibility becomes a programme the firm can stand behind.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



