
Law Firms · 6 min read
California Attorneys' Duty of Confidentiality in the Age of Cyberattacks
Business & Professions Code § 6068(e), Rule 1.6, and the technology-competence comment to Rule 1.1 — and what they mean for your firm’s IT.
IT for California law firms
Secure, dependable IT for North Bay law firms — protecting privileged communications, client files, and trust-account workflows with the safeguards California attorneys are expected to take.

Safeguard check
MonitoredProblems we solve
The problem: Criminals impersonate attorneys and clients to redirect settlement funds and retainer payments. One spoofed email can cost a fortune — and a client relationship.
How we fix it: We lock down Microsoft 365 or Google Workspace with multi-factor authentication, impersonation protection, external-sender warnings, and alerts for suspicious mailbox rules.
The problem: Client documents end up in personal Dropbox accounts, email attachments, and laptops that never get encrypted.
How we fix it: We consolidate files into a secure, permissioned document system, encrypt every device, and set up client portals for sharing sensitive documents instead of email.
The problem: Attorneys work from courthouses, coffee shops, and home offices — often on public Wi-Fi.
How we fix it: Managed devices, secure remote access, and the ability to remotely lock or wipe a lost laptop or phone.
The problem: When a paralegal or associate leaves, their access to email, case files, and practice software often stays active.
How we fix it: Documented onboarding and offboarding checklists so access is granted on day one and revoked the same day someone leaves.
Free AI site scan for law firms
Contact and case-evaluation forms collect privileged details. Enter your firm website to see which trackers load on those forms, whether your security headers meet State Bar expectations, and where ADA issues could expose the firm.
We only read publicly available pages, the same way a browser does. The scan sends public page data to an AI model to write your report. Results are not stored. See our Privacy Policy.
Security & compliance
Federal requirements and California law shape what "reasonable security" means for law firms. We design safeguards around them and document what we do.
M&R Systems provides IT and security services, not legal advice. Consult your attorney or compliance advisor for guidance on your specific obligations.
Run a free scan of your website now, or talk to a local technician about your whole environment.

Why M&R Systems
Attorneys do not have time to fight with technology. You need your documents, calendar, and email available the moment a client calls — at the office, at home, or outside a courtroom. Our job is to make that happen quietly and securely.
California attorneys carry a special responsibility. The duty of confidentiality, the expectation of technological competence, and State Bar ethics guidance on cloud services and data breaches all mean that "good enough" IT is not good enough for a law firm.
We translate those expectations into concrete, documented safeguards — so if a client, an insurer, or opposing counsel ever asks how you protect information, you have a clear answer. We are an IT firm, not a law firm, and we work alongside your own ethics counsel when questions go beyond technology.
MFA, impersonation protection, retention, and mailbox monitoring.
Support for the servers, workstations, and integrations behind Clio, PracticePanther, and similar tools.
Permissioned file storage, client portals, and encrypted sharing.
Encrypted laptops and phones with remote lock and wipe.
Retention and recoverable backups so you can find and preserve what matters.
Short, practical training on phishing and wire-fraud red flags.
FAQ
Yes, indirectly. Attorneys are responsible for taking reasonable steps to protect client confidential information, and California's Rule 1.1 comment expects lawyers to understand the risks of the technology they use. We help you put reasonable, documented safeguards in place. For specific ethics questions, consult your ethics counsel or the State Bar.
Cloud storage can be used responsibly when the provider is reputable, data is encrypted, access is restricted, and the firm understands the terms of service. We configure cloud platforms so those conditions are met and documented.
We enforce multi-factor authentication, block lookalike domains and impersonation, flag external senders, alert on suspicious inbox rules, and train staff to verify any payment change by phone using a known number.
We support the environment those tools run in — devices, sign-in security, integrations with Microsoft 365 or Google Workspace, scanners, and document storage — and coordinate with the software vendor when needed.
Call us immediately. If the device is managed and encrypted, we can lock or wipe it remotely, and encryption greatly reduces the chance that the loss becomes a reportable breach under California law.
Yes. Insurers increasingly ask about MFA, backups, endpoint protection, and training. We help you answer accurately — and close gaps before renewal.
We help firms choose and configure AI tools so client information is not used to train public models and access is controlled — consistent with State Bar guidance urging lawyers to protect confidentiality when using generative AI.
See your security, ADA, HIPAA, and California privacy results in about a minute. No sign-up required.
Insights
Practical, plain-English reading on the security and technology issues you deal with every day.

Law Firms · 6 min read
Business & Professions Code § 6068(e), Rule 1.6, and the technology-competence comment to Rule 1.1 — and what they mean for your firm’s IT.

Law Firms · 5 min read
Settlement funds and retainers make law firms a favorite target. These controls stop most attacks cold.

Law Firms · 4 min read
Practicing law from anywhere is now normal. Here is how to keep privileged information safe on the go.
Free assessment · No pressure
We will review your email, devices, and document storage against common attorney risk areas and send you a plain-English action plan.
Rather call?(415) 497-4137