ABA Rule 1.6 in 2026
ABA Model Rule 1.6(c) requires lawyers to make "reasonable efforts" to prevent unauthorized disclosure of client information.
In short
Texas Rule 1.05 mirrors it. What counts as reasonable has changed dramatically since the rule was last meaningfully updated in 2012 — institutional clients now run SOC-2-grade security questionnaires before retaining outside counsel, ransomware groups actively target law firms, BEC-driven wire fraud against trust accounts is a daily occurrence, and Texas State Bar Disciplinary Counsel has begun pursuing data breach matters under Rule 1.05.
Guide explainer · ABA Rule 1.6 and Texas Rule 1.05
What reasonable efforts look like in a small firm
The rising bar, the Comment 18 factors, a data map, the 2026 baseline, PAM, a tested breach plan and the file you answer from. Tap a lens to dive in, use the arrows, or let it play.
Overview · The bar keeps rising
Reasonable is a moving bar, and it has moved
Rule 1.6(c) and Texas Rule 1.05 ask you to make reasonable efforts to keep client information from getting out. The rule hasn't been meaningfully updated since 2012. What counts as reasonable has. Step through the years and watch a gap open under a firm still running on passwords and a policy PDF.
What LayerLogix does
- Measure where your firm sits against the 2026 baseline
- Map Opinions 477, 483 and 498 to the IT controls behind them
- Close the gap in the order that protects clients first
Step 1 · Weigh it like Comment 18
Five factors decide what reasonable means for you
Comment 18 weighs how sensitive the information is, how likely exposure is without a safeguard, what the safeguard costs, how hard it is to run and whether it gets in the way of the work. A solo office and a larger firm land in different places. MFA's shape hardly moves.
What LayerLogix does
- Run a risk assessment built on the Comment 18 factors
- Size each safeguard to your firm, not to a big-firm template
- Tell you when a vCISO makes sense for you, and when it doesn't
Step 2 · Inventory client data
You can't protect a matter you haven't mapped
Ask where client information lives and most firms say the DMS. Then you check email, the file shares, the cloud apps, attorneys' phones, the paralegal's desktop and the eDiscovery platform. The map is the first page of the program, and the controls that follow point back to it.
What LayerLogix does
- Inventory each system and device that holds matter data
- Record who can reach each place, and how they get in
- Hand the map to the partner or COO who owns the program
Step 3 · The 2026 baseline
Raise the baseline column by column, gaps first
The guide's floor reads like a parts list: encryption at rest and in transit, MFA on attorney accounts and the DMS, documented access controls, phishing simulations, monthly awareness training, a tested incident plan, vendor reviews and PAM. Leave a column out and ransomware or BEC finds the gap.
What LayerLogix does
- Turn on MFA for attorney accounts, email and the DMS
- Encrypt client data at rest and in transit, then document it
- Run phishing simulations and monthly awareness training
Step 4 · Privileged Access Management
Only what's on the docket gets to run
PAM here means application allowlisting and ringfencing on each attorney and staff workstation. Approved apps run. An unknown executable doesn't, and Word isn't allowed to launch PowerShell. The guide singles it out for ransomware and BEC defense, and each block lands in an audit log you can show.
What LayerLogix does
- Deploy allowlisting on each attorney and staff workstation
- Ringfence Office apps so they can't launch scripting tools
- Keep the audit log that shows the controls doing their job
Step 5 · After a breach (Opinion 483)
A tested plan catches the chain after the first domino
Opinion 483 sets the order after a breach: contain and fix it, work out which clients were affected, tell them enough to make informed decisions, and consider whether the representation can continue. Without a tested plan, one problem tips over the next. With one, the questions already have answers.
What LayerLogix does
- Write your incident plan and run a tabletop at least yearly
- Put your carrier and outside counsel contacts in the plan
- Contain and clean up with you, and log each step as we go
Step 6 · Show your reasonable efforts
When someone asks, you answer from the file
An institutional client's panel review, bar counsel and your carrier's renewal all ask the same thing in different words: what reasonable efforts did you take? A program that actually runs, with its annual review written down, answers from records you already keep. Pick who's asking.
What LayerLogix does
- Answer client security questionnaires from your real records
- Run the annual program review with you and write it down
- Keep training, incident and vendor records in one place
Showing Overview · The bar keeps rising: Reasonable is a moving bar, and it has moved
What We Offer
Comprehensive solutions tailored for Houston-area businesses
What Rule 1.6(c) Actually Says
ABA Model Rule 1.6(c) requires lawyers to "make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." Texas Rule 1.05 is substantively similar. The word "reasonable" is doing all the work — and what counts as reasonable in 2026 is dramatically more than what counted as reasonable in 2012 when the ABA added the comment 18 factors.
The Comment 18 Factors
ABA Comment 18 lists the factors for determining 'reasonable efforts': sensitivity of information, likelihood of disclosure if safeguards not employed, cost of additional safeguards, difficulty of implementing safeguards, and the extent to which safeguards adversely affect the lawyer's ability to represent clients. The factors are deliberately flexible — they accommodate solo practitioners, mid-size firms, and BigLaw differently. But they are not infinitely flexible: ignoring widely-available safeguards like MFA is no longer defensible.
ABA Formal Opinions That Matter
Formal Opinion 477 (2017) addressed secure communications and mobile device use. Formal Opinion 483 (2018) addressed lawyers' obligations after a data breach. Formal Opinion 498 (2021) addressed virtual practice and remote work. Together they establish that lawyers must understand the technology they use, must implement reasonable safeguards, and must respond to breaches with both notification and remediation. Reading these opinions is not optional for managing partners or COOs.
What Institutional Clients Demand
Major institutional clients — banks, insurers, healthcare systems, large corporates — now run security questionnaires before retaining outside counsel and during annual relationship reviews. The questions read like SOC 2 due diligence: encryption, MFA, access controls, incident response plans, vendor management, audit logs. Firms that cannot answer fail outside counsel guideline reviews and get dropped from the panel.
The Modern 'Reasonable' Baseline
In 2026, the practical floor for what counts as 'reasonable' includes: encryption of client data at rest and in transit, MFA on all attorney accounts and document management, documented access controls, an incident response plan with regular testing, vendor management for cloud services, regular phishing simulations, monthly security awareness, and increasingly Privileged Access Management (PAM) on attorney workstations to defend against the ransomware that hits law firms more than any other professional services category.
BEC and Wire Fraud — A Specific Problem
Real estate transactions, settlements, and trust account distributions involve large wire transfers that adversaries actively target through Business Email Compromise (BEC). Loss of client funds through BEC is now a top driver of legal malpractice claims. ABA Formal Opinion 483 implies a duty to implement controls reasonable to prevent foreseeable BEC — which means email security with anti-impersonation, DMARC at p=reject, conditional access, and out-of-band wire verification protocols.
Why Choose LayerLogix?
Serving businesses throughout the Greater Houston area including Houston, The Woodlands, Sugar Land, Spring, Conroe, Dallas, Fort Worth, Austin, San Antonio.
Defensible Compliance Posture
When a client asks "show me your information security program' or when bar discipline counsel asks 'what reasonable efforts did you take?" you have a documented answer. The cost of producing that answer in advance is dramatically less than the cost of constructing it after an incident.
Win Institutional Client Engagements
Most mid-size and small Texas firms lose institutional client opportunities they never know about because they fail outside counsel guideline security reviews silently. A real information security program — not a PDF policy document, an actual operational program — wins business that competitors cannot.
Lower Malpractice and Cyber Insurance Premiums
Lawyer Professional Liability and cyber insurance carriers now bake cybersecurity into pricing. Documented MFA, PAM, immutable backup, and incident response routinely reduce premium quotes 10-25% on renewal — frequently more than the engagement cost.
Reduced Wire Fraud Risk
BEC-driven wire fraud against trust account distributions is now a daily occurrence. A real BEC defense program (email security + staff training + out-of-band verification + DMARC) dramatically reduces successful fraud and the malpractice exposure it creates.
Bar Discipline Defensibility
Texas State Bar Disciplinary Counsel has begun pursuing data breach matters under Rule 1.05. Documented compliance with the modern reasonable efforts standard is your defense.
Our Process
Frequently Asked Questions
What does 'reasonable efforts' actually require my firm to do in 2026?▼
Does my firm need a written information security program?▼
What happens if my firm has a data breach?▼
How does Privileged Access Management (PAM) help a law firm comply with Rule 1.6?▼
How much does a real information security program cost a Texas law firm?▼
Is bar discipline actually a real risk for IT security failures?▼
Ready to Get Started?
Contact LayerLogix today for a free consultation. We serve businesses throughout Houston, The Woodlands, Sugar Land, and the surrounding Greater Houston area.