What ABA Model Rule 1.1 Actually Requires from Your Law Firm's IT
In 2012, the ABA amended Comment 8 to Model Rule 1.1 — the competence rule — to add a single sentence: lawyers should keep abreast of “changes in the law and its practice, including the benefits and risks associated with relevant technology.”
That sentence didn’t get much attention at the time. It still doesn’t, in most firms. But it has been quietly redefining what competence looks like in the model rules, and regulators, ethics committees, and malpractice carriers are paying closer attention than they were a decade ago.
Nevada’s Rule of Professional Conduct 1.1 uses the same competence text as the ABA model rule: a lawyer must provide competent representation, which requires the legal knowledge, skill, thoroughness, and preparation reasonably necessary for the representation. Comment 8 is ABA model-rule language. Nevada has not adopted that comment, so it is not a standalone Nevada ethics obligation. What is a Nevada obligation is NRPC 1.1 itself — and, separately, the duty to protect client information.
So what does that actually require of your IT?
What “technological competence” means in practice
The model comment doesn’t mandate specific software or a particular security stack. What competence requires is that you understand the technology your practice depends on well enough to make informed decisions about it — and that you take reasonable steps to protect client information.
The confidentiality duty is more specific. ABA Model Rule 1.6(c) requires lawyers to make “reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.” Formal Opinion 477R (2017) applies that rule to electronic communications: what’s reasonable depends on the sensitivity of the information, the likelihood of disclosure without extra safeguards, the cost and difficulty of those safeguards, and whether they interfere with the representation.
For a Henderson or Las Vegas practice handling real estate closings, family law matters, or business litigation, the information in your systems is exactly what attackers target: wire instructions, settlement amounts, client financials, and personally identifiable information.
The “we’re not a target” problem
It’s a reasonable instinct. A practice built around closings, family matters, or local litigation doesn’t feel like a high-value target compared to a regional bank or a hospital system. The logic makes sense on the surface.
The problem is that attackers don’t think the way you do. They’re not choosing targets based on prestige — they’re choosing based on access and vulnerability. A practice with weak email security and no MFA is easier to compromise than one with enforced MFA, tested backups, and someone accountable for patching. And the information inside — client trust account details, pending real estate transactions, confidential settlement negotiations — is genuinely valuable.
In Nevada specifically, real estate and gaming generate a volume of high-stakes transactions that flow through local firms every day. That’s not a reason to panic. It’s a reason to be honest about what your systems actually protect.
Imagine a Henderson real-estate practice that handles a steady run of closings. Visibility in the community doesn’t stop phishing or credential-based attacks. What stops them is having controls in place before the attempt succeeds.
Security is a set of controls — not a reputation.
Where firms typically fall short
Most of the gaps aren’t exotic. They’re the same handful of issues that show up in almost every practice that hasn’t had a formal IT review.
Email is the front door
Business email compromise — where an attacker gains access to a legitimate email account and uses it to redirect wire transfers or harvest information — is the most common attack vector against law firms. It works because email is trusted. A message from your managing partner’s actual account, asking the bookkeeper to process an urgent wire, doesn’t trigger the same skepticism as an obvious phishing email.
The defenses are specific: MFA on every email account (not optional, not just for admins), SPF/DKIM/DMARC configured on your domain to prevent spoofing, and a written policy requiring verbal confirmation for any wire instruction received by email. These three things, implemented together, stop the majority of BEC attacks.
Client portal vs. email attachments
Sending a confidential settlement agreement as an email attachment is the digital equivalent of leaving a file folder on a park bench. The document is unencrypted in transit, stored in potentially multiple email servers, and accessible to anyone who compromises either party’s email account.
Practice management platforms like Clio, MyCase, and Filevine all include secure client portals for document exchange. Using them isn’t just good practice — it’s a defensible answer to the question of whether you took reasonable steps to protect client information.
Backups that would actually survive an attack
Ransomware encrypts your files and then demands payment to restore them. If your backup is a network drive connected to your server, ransomware encrypts that too. If your backup is a cloud sync like Dropbox or OneDrive without versioning configured, the encrypted files overwrite the good ones.
What survives a ransomware attack: backups that are isolated from your production network, retained with versioning for at least 30 days, and tested with an actual restore — not just assumed to be working. “We back up every night” and “we can recover from a ransomware attack” are not the same statement.
Patch management
The Colonial Pipeline ransomware incident in 2021 started with a leftover VPN account, a compromised password, and no MFA — not an unpatched VPN CVE. Unused accounts and missing MFA are still the more common pattern in professional-services environments.
For a law practice, patch management means having someone responsible for ensuring that Windows updates, application updates, and firmware updates are applied on a regular schedule — not when someone notices the popup. Critical security patches should be applied within 30 days of release. Actively exploited vulnerabilities should be patched faster. Unused remote-access accounts should be disabled, not left as a spare key.
Access controls and offboarding
When an associate leaves your firm, do their credentials get disabled the same day? Do they have access to client files from their personal device that they took with them? Is there a list of every system they had access to?
Many practices don’t have a formal offboarding checklist. This matters because former employees — even ones who left on good terms — represent a real access risk if their credentials remain active. It’s not about distrust. It’s about hygiene.
What a defensible posture looks like
The goal isn’t perfection. The standard is “reasonable efforts” under Rule 1.6(c) — which means you’ve assessed the risks, implemented controls proportionate to the sensitivity of the information you handle, and documented what you’ve done.
In practical terms, a Nevada firm with a defensible security posture has:
- MFA enforced on email and any remote access
- Email authentication (SPF, DKIM, DMARC) configured
- A written policy for verifying wire instructions
- Endpoint protection on every firm device, including laptops
- Isolated, tested backups retained with versioning
- A patch management process with someone accountable for it
- A documented offboarding checklist
- At least annual security awareness training for all staff
None of this requires a large IT department. It requires a managed IT provider who understands law firm requirements — matter confidentiality, e-filing uptime, trust account segregation — and treats security as a baseline, not an upsell.
The ethics opinions you should read
If you want to go deeper, Nevada State Bar Formal Opinion No. 33 addresses cloud computing and client confidentiality. The ABA’s Formal Opinion 477R covers securing communication of protected client information under Model Rule 1.6(c). Both are worth reading — not because they’ll tell you exactly which tools to use, but because they clarify the standard you’re being held to.
The short version: you don’t need to be an IT expert. You need to be informed enough to ask the right questions and make reasonable decisions. That’s the same standard you apply to every other area of practice.
Where to start
If you’re not sure where your firm stands, the right first step is an honest assessment — not a sales pitch, but an actual review of what you have in place and where the gaps are.
We work with firms in the Las Vegas and Henderson area and understand what law firm IT actually requires. If you’d like to know where your firm stands, start with our assessment — it takes about ten minutes and gives you a clear picture of what’s working and what needs attention.