Sentry CTO

Law Firms

Your duty of confidentiality does not have an IT exception.

For most businesses, a data breach is expensive and embarrassing. For a law firm it is also a professional responsibility problem, a malpractice exposure, and a conversation with clients whose confidences you undertook to protect.

We work with a Prescott law firm that came to us the way many do. Their IT person left town, and nobody had thought about what that meant until he was gone.

What makes this different

The pressures specific to law firms.

Everything is privileged

A manufacturer worries about which files are sensitive. In a law firm, essentially every document relates to a client matter. There is no low-value data to relax about, which changes how access, retention, and backup all need to be handled.

Client security questionnaires

Corporate clients increasingly send outside counsel guidelines with real security requirements attached, encryption, MFA, incident notification windows, sometimes a right to audit. Firms that cannot answer lose the work, often without being told why.

Attorneys use their own devices

Personal laptops, home machines, phones with client email on them. Banning it does not work; nobody complies. It has to be managed, which is a different problem with a different answer.

Wire fraud at closing

Real estate and settlement work makes firms a standing target for payment-diversion fraud. The attack is not technical. It is a convincing email at exactly the right moment in a transaction, sent by someone who has been reading your mailbox.

Nobody has time for this

Partners bill hours. Every hour spent on technology governance is an hour not billed, which is why it gets deferred until something forces it.

What you are measured against

The obligations that actually apply.

ABA Model Rule 1.6(c)
Requires reasonable efforts to prevent unauthorized access to or disclosure of information relating to representation. "Reasonable" is judged against what a competent firm would do, and that standard moves as the threat landscape does.
Model Rule 1.1, Comment 8
Technology competence is part of general competence, lawyers are expected to understand the benefits and risks of the technology they use.
Arizona ER 1.6 and ER 1.1
Arizona has adopted the substance of both rules. TODO(niles): confirm current citation with counsel before publishing this line.
Client-imposed obligations
Outside counsel guidelines frequently impose stricter requirements than any bar rule, and they are contractual rather than aspirational.

A client

A ten-person firm whose IT person left town

They started with routine IT support after an introduction from an attorney in a networking group. As the security picture became clearer, they moved to full managed security. They have now renewed on a five-year agreement, by the end of it they will have been with us for more than a decade.

Details anonymized. Figures are real.

Renewal term
5 yr
Total relationship
10+ yr
“Niles and team are the best in Northern Arizona! We use [Sentry CTO] for our law office, and Niles is always prompt, responsive, professional, and knowledgeable.”
Annie Holdsworth · Holdsworth Law Firm

Questions we get

From law firms, specifically.

Can attorneys keep using their own laptops?

Usually yes, with conditions. The workable answer is separating firm data from personal devices rather than trying to control the device itself, so client information lives somewhere managed and can be removed remotely, while the attorney keeps their own machine. Outright bans tend to produce quiet non-compliance, which is worse than a managed compromise.

What do we tell clients who send us a security questionnaire?

The truth, evidenced. The problem is rarely that a firm has poor security. It is that nobody can produce documentation of the security they do have. An assessment produces exactly the artifacts these questionnaires ask for, which is why several firms treat it as a business development expense rather than an IT one.

Do we need to tell clients if we have a breach?

Often yes, and the analysis is genuinely complicated. It depends on what was accessed, which clients were affected, the state law involved, and any contractual notification terms. This is a question for your malpractice carrier and ethics counsel, not your IT provider. What we can do is make sure you can answer the factual question of what was actually reached, because you cannot make that call without it.

We are a four-person firm. Is this overkill?

The confidentiality duty does not scale with firm size, and neither does the attacker. What does scale is how much you can absorb, a four-person firm that loses its document management system for two weeks is in more trouble than a large firm with the same outage. Whether our specific service is proportionate is a fair question, and the fifteen-minute call is where to ask it.

The next step

Find out where your law firm actually stands.

Three minutes, nine areas, no email address. Or book fifteen minutes and we will tell you honestly whether an assessment makes sense for an organization your size.

No pitch on the first call. If we are not a fit, we will say so and point you somewhere better.