Law firms hold some of the most sensitive information any business handles — privileged communications, financial records, litigation strategy — and Illinois attorneys carry specific ethical obligations, not just general best practices, to protect it.
Rule 1.6: The Baseline Obligation
Illinois Rule of Professional Conduct 1.6 requires a lawyer to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. That’s not limited to intentional disclosures — it covers the technical safeguards (encryption, access controls, secure communication channels) needed to prevent a breach from happening in the first place, not just how you respond after one occurs.
What “Reasonable Efforts” Actually Means
There’s no single checklist, but the standard scales with the sensitivity of the information and the resources reasonably available to the firm. A solo practitioner and a 200-attorney firm aren’t held to identical technical requirements, but both must take real, documented steps. In practice: encrypted email or a secure client portal for sensitive communications, MFA on email and case management systems, and a defined process for vetting any vendor — including cloud storage and IT providers — that touches client data.
After a Breach: ABA Formal Opinion 483
Formal Opinion 483 describes a lawyer’s ethical obligations following an electronic data breach or cyberattack that compromises client information. Illinois’ rules are based on the ABA Model Rules with state-specific modifications, so the same underlying obligations apply: Rule 1.1 (competence) requires acting reasonably and promptly to stop a breach and mitigate damage, and Rule 1.4 (communication) requires notifying affected clients with enough detail for them to make informed decisions about their representation. Illinois’ Personal Information Protection Act may separately require formal notification to individuals and, for breaches affecting more than 500 Illinois residents, to the Attorney General within 45 days.
Why Consumer Tools Are a Real Liability
Consumer-grade cloud storage and personal email generally lack the access controls, encryption standards, and audit trails needed to demonstrate “reasonable efforts” under Rule 1.6, and most don’t offer any confidentiality agreement covering the data they hold. A single compromised personal email account or unsecured shared drive can expose privileged communications across every matter stored there — a security incident and a professional responsibility problem at the same time.
Privilege Is Also at Stake
A breach that exposes privileged communications creates a real risk of privilege waiver arguments from opposing parties, entirely separate from the ethical notification obligations. Any unencrypted or poorly secured system holding privileged material is a liability on two fronts: professional responsibility and litigation risk. Encryption and access controls matter as much for preserving privilege as for basic data protection.
What Firms Are Actually Targeted With
Law firms are attractive, high-value targets precisely because of the confidential information they hold on behalf of clients across multiple industries at once — a single firm breach can expose sensitive data belonging to dozens of unrelated businesses. Business email compromise targeting trust account wire transfers, phishing impersonating opposing counsel or clients, and ransomware are the most commonly documented attack vectors against firms specifically.
How CelereTech Helps
CelereTech implements the technical safeguards that support Rule 1.6 compliance — encryption, MFA, secure client communication tools, endpoint protection, and monitored backups — and helps build the incident response plan and vendor due diligence process firms need to demonstrate reasonable efforts. We work alongside firm leadership and, where appropriate, malpractice counsel, rather than replacing the firm’s own professional responsibility judgment.
Get your firm’s security assessed against Rule 1.6’s reasonable efforts standard.