Law firms handle some of the most sensitive documents in existence. Contracts, discovery materials, settlement agreements, expert witness reports, M&A due diligence packages. These files move between partners, associates, clients, opposing counsel, courts, co-counsel, and expert witnesses every day.
Most firms rely on two layers of protection: encrypted email and secure client portals. Both are reasonable starting points. Neither solves the core problem.
The moment a client downloads a file to their personal laptop, or an opposing counsel saves it to their Gmail account, the file leaves the firm’s security perimeter. The duty of confidentiality remains. The technical protection does not.
This post examines where that gap originates, what ABA Model Rule 1.6 actually demands, and the architectural change that closes it.
Why Are Law Firms High-Value Targets for Data Breaches?
Law firms hold concentrated repositories of information that attackers price accordingly. A single matter file might contain M&A strategy that could move markets, litigation positions worth millions in settlement leverage, or intellectual property a client has spent decades developing.
The Legal Services Information Sharing and Analysis Organization (LS-ISAC) consistently tracks this pattern: law firms remain high-value targets precisely because of what they hold, not because of the size of the firm.
The numbers reflect the exposure. The 2023 ABA Legal Technology Survey found that 29% of law firms reported a security breach at some point. Yet only 43% had a formal incident response plan in place. That gap between exposure and readiness is where attackers operate.
The financial consequences are significant. According to the IBM Cost of a Data Breach Report, data breaches in professional services and legal sectors average over $5 million per incident, with unmanaged cloud assets and credential compromise adding significantly to containment time and overall cost.
Most breaches in the legal sector follow a consistent pattern: stolen credentials plus access to unencrypted files. The credential theft vector is covered in depth in our post on how file-layer encryption limits the blast radius of credential theft. The point here is that file protection cannot depend solely on keeping attackers out of the network. It has to assume they will eventually get in.
🔒 Stop Confidential File Exposure at the Moment of Download
Portals and encrypted email protect data until the client clicks save. Learn how per-file FIPS 140-3 encryption keeps privileged files unreadable on any unmanaged device.
What Does ABA Model Rule 1.6 Actually Require for File Security?
ABA Model Rule 1.6(c) states that lawyers must make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.
The rule does not define “reasonable efforts” in technical terms. That interpretation has been developed through ethics opinions and, increasingly, through disciplinary actions.
ABA Formal Opinion 477R (2017) updated the guidance on electronic communications. It recommended that lawyers evaluate the sensitivity of the information and the potential harm of disclosure when deciding whether to use encryption. For highly sensitive matters, unencrypted email is not sufficient regardless of firm size or practice area.
State bar activity has moved from guidance to enforcement. New York, California, and Texas have each seen disciplinary actions tied to data breaches that exposed client information. The standard is becoming clearer: if a firm had the technical means to prevent unauthorized access and did not deploy them, the bar expects an explanation.
For firms with international clients, GDPR adds another dimension. Any firm handling data related to EU or UK individuals is subject to its requirements around data protection and breach notification. The specific compliance posture depends on the firm’s structure and client base, but the regulatory exposure is real and increasing.
Where Does Encrypted Email and Secure Portal Protection End?
Encrypted email protects data in transit. A secure portal protects files while they sit on the firm’s infrastructure. Both controls have clearly defined technical boundaries.
The boundary is the download event.
When a client opens a document inside a secure portal, the portal’s access controls are active. When that same client clicks download and saves the file to their personal laptop, the protection ends. The file is now a standard document on an unmanaged device, with no access controls, no audit trail, and no ability for the firm to revoke access if the matter status changes or the client relationship ends.
Encrypted email has the same limitation. Transit encryption protects the message in motion. Once the recipient’s email client decrypts the attachment and saves it locally, the firm has no further visibility or control.
The practical result is that two of the most commonly deployed security controls in law firms protect data only up to the point where it becomes most exposed.
What Happens to Privileged Documents After They’re Downloaded by a Client or Co-Counsel?
Consider a typical discovery production. The producing firm delivers documents to opposing counsel via a portal or encrypted transfer. Opposing counsel downloads the production to a local server for review. An associate emails several documents to an expert witness. The expert forwards one to a colleague at another institution.
At each step, the producing firm’s confidentiality obligation still applies to that information. The technical protection has been absent since step one.
The same dynamic applies to co-counsel arrangements, expert witnesses, and direct client communications. Firms carefully manage who receives privileged materials. They have much less visibility into what happens to those materials once received.
For international matters, files may be stored in jurisdictions with different legal standards for government data access. A subpoena to a foreign email provider is outside the firm’s control entirely. The file is still the firm’s legal responsibility.
This is the blast radius problem at the file level. Sensitive content travels beyond the perimeter, and the security does not travel with it. The architectural response is to change that relationship between the file and its protection.
How Does File-Level Encryption Protect Attorney-Client Privilege Beyond the Firm’s Perimeter?
The answer is to make the protection part of the file itself, not part of the infrastructure that holds it.
File-level encryption means each document carries its own encryption and access policy. When that file is downloaded, forwarded, or saved to an unmanaged device, the encryption travels with it. The file cannot be opened without satisfying the conditions the firm established, regardless of where the file physically resides.
Theodosian applies per-file FIPS 140-3 AES-256 encryption, with a unique cryptographic key for each document. The key architecture is patent-pending and zero-knowledge: Theodosian does not hold a master key that could decrypt client files if the vendor were breached or served with a subpoena. The architectural implications of that design choice are examined in detail in zero-knowledge encryption vs. standard enterprise file encryption.
Access conditions are enforced at the time of opening, not at the time of sharing. A firm can specify that a document is accessible only from a verified device, within a particular geography, during defined hours, or only while the access grant remains active. If a client relationship ends or a matter closes, access to all shared files can be revoked immediately, including files already downloaded to external devices. This is the practical application of dynamic access control to the legal file-sharing problem.
Recipients open files in a browser. No client-side software installation is required. For external parties who receive files infrequently, this removes a significant friction point without compromising the access controls.
The encryption standard itself is worth understanding precisely. Firms evaluating compliance claims should ask vendors what “FIPS 140-3 compliant” actually means in practice and how to verify it. That question is answered in what does FIPS 140-3 compliant actually mean, and how do you verify it.
What Does a Compliant File Security Architecture Look Like for a Law Firm?
A firm that takes Rule 1.6(c) seriously needs four things from its file security architecture.
Encryption that travels with the file: Portal-only protection addresses at-rest and in-transit risk but leaves the downloaded file unprotected. The solution is encryption that remains active regardless of where the file is stored, on whose device, or which network they use.
Revocable access: Matters close. Client relationships end. Personnel turn over on both sides of a transaction. The ability to revoke access to shared files after the fact is not an advanced feature; it is a basic requirement for maintaining control of confidential information across the full matter lifecycle.
A complete audit trail: Knowing which files were accessed, by whom, on what device, and from where is essential for breach response and bar inquiries. Firms without this visibility are answering disciplinary questions without evidence.
Infrastructure that meets established government standards: Theodosian runs on FedRAMP Moderate infrastructure, the same certification tier required for federal government data. For firms handling government contractor clients or federal matters, that alignment with established standards matters. Firms that already manage contractor file sharing will find the approach directly parallel to how Theodosian handles sensitive files shared with contractors.
A fourth capability that is specifically relevant to legal practice: a firm can disable access to a file at any point after sharing, including files that have already been downloaded. If a settlement agreement becomes disputed, a document needs to be corrected, or a recipient’s access should never have been granted, the firm can act immediately rather than relying on the recipient to delete the file.
💼 Ready to See This in Your Environment?
Theodosian offers a two-week proof of concept that runs against your actual documents and sharing workflows, with no procurement commitment required.
FAQ’s: Law Firm File Security & ABA Rule 1.6
If a client’s device is compromised after they’ve downloaded a file, can the firm revoke access?
Yes. Because encryption and access policy are enforced at the time of opening rather than at the time of sharing, Theodosian can revoke access to any file at any point after it was shared. If the firm learns of a client device compromise, a partner departure, or a change in matter status, access revocation takes effect immediately regardless of where the file currently sits or how many times it has been copied.
Does file-level encryption create friction for clients or co-counsel who need to open documents quickly?
No client-side software installation is required. Recipients open files directly in a browser using their existing identity credentials. The experience is comparable to opening a document in any standard web viewer. The encryption verification and access check happen in the background without requiring action from the recipient. For external parties who receive files occasionally, this is a significant practical advantage over solutions that require software installation or account registration before a file can be opened.