California Attorneys' Duty of Confidentiality in the Age of Cyberattacks
Business & Professions Code § 6068(e), Rule 1.6, and the technology-competence comment to Rule 1.1 — and what they mean for your firm’s IT.
· 6 min read

California attorneys have long been bound by a strict duty to maintain inviolate the confidence of their clients under Business & Professions Code § 6068(e). In a world of cloud email, remote work, and targeted phishing, meeting that duty increasingly depends on your technology.
Competence includes technology
The comment to California Rule of Professional Conduct 1.1 notes that competence includes keeping abreast of the benefits and risks associated with relevant technology. You do not need to become an IT expert — but you are expected to understand the risks well enough to manage them, often with qualified help.
What reasonable safeguards look like
State Bar ethics opinions have addressed cloud storage, public Wi-Fi, and data breaches. Common themes translate into practical controls:
- Multi-factor authentication on email and practice management systems
- Full-disk encryption on every laptop and phone
- Vetting cloud vendors and understanding their terms
- Restricting access to client files on a need-to-know basis
- A plan for detecting and responding to a breach
Document your diligence
If a client, insurer, or regulator asks how you protect information, a documented security program is your best answer. We help firms build that documentation as part of normal IT support.
This article is general information about technology safeguards, not legal or ethics advice. Consult your ethics counsel or the State Bar for guidance on your specific obligations.
This article is general information about IT and security practices, not legal advice.

