
Rules of professional conduct across the country require attorneys to make “reasonable efforts” to prevent the unauthorized disclosure of client information. The phrase shows up in ethics opinions and CLE materials constantly, and it is almost never defined with any precision. That ambiguity is not an accident — what counts as reasonable depends on the firm, the data, and the threat. It does mean, however, that a firm can't assume it's covered just because nothing has gone wrong yet.
“Reasonable” Is a Standard, Not a Checklist
Ethics rules deliberately avoid prescribing specific technical requirements, because a solo practitioner and a twenty-attorney firm face different risks and have different resources. What regulators and bar associations generally look at instead is whether a firm made a good-faith, documented effort proportional to the sensitivity of the data it holds — not whether it bought a particular product.
That's good news in one sense: there's no single tool that automatically satisfies the standard. It's also the reason many firms get this wrong. Without a specific checklist to point to, it's easy to assume that ordinary business practices are automatically “reasonable” for a law practice, when the professional responsibility bar is generally read as higher.
What Regulators and Courts Tend to Look For
- Whether the firm has a written information security policy at all
- How access to client files is restricted — not every staff member needs access to every matter
- Whether sensitive communications and documents are encrypted, in transit and at rest
- Whether backups exist, and whether they've ever actually been tested
- Whether the firm has a plan for what happens in the first hours after a suspected breach
None of these require exotic technology. They require the firm to have made deliberate decisions about its data, rather than inheriting whatever configuration came with the computers.
Where This Intersects With IT, Not Just Ethics
The ethical obligation belongs to the attorneys and the firm. Whether the underlying systems actually support that obligation is a technical question — and it's the one that gets overlooked. A firm can have a well-written policy on paper while its backups have never been restored, its access controls are set to “everyone,” or its email isn't encrypted. The gap between the policy and the configuration is where “reasonable efforts” claims tend to fall apart under scrutiny.
This is also where an outside review helps. A firm that has never had someone independently check the difference between its written policy and its actual technical setup usually has no way to know whether the two agree.
Frequently Asked Questions
Does “reasonable efforts” mean firms need the most advanced security available?
No. Reasonableness is judged relative to the sensitivity of the data and the resources of the firm, not against the most sophisticated option on the market. A small firm doesn't need enterprise-grade tooling built for a Fortune 500 company — it needs deliberate, documented practices suited to what it actually handles.
What's the single most common gap firms have in this area?
Untested backups and unrestricted internal access are the two we see most often. Both are usually invisible until something forces the issue — a ransomware event, a departing employee, or a bar complaint.
Can a firm be found to have violated its ethical duties even without a data breach?
Generally, the duty is about the effort made, not solely the outcome. A firm with no policy, no access controls, and no tested backups could still face scrutiny for its practices even in the absence of an incident, though enforcement in practice is often triggered by one.
Is a written policy enough on its own?
A written policy is necessary but not sufficient. It needs to be reflected in how systems are actually configured — access restrictions, encryption, and tested backups among them — not just filed away.
Next Step
If you'd like a plain, specific answer about where your firm actually stands — rather than an assumption — we offer a 15-minute call to see if we're a fit. No pitch, no obligation.
Managing partners and office administrators can reach us at 325-643-8184 or through the contact form at apollocomputers.com.


