What IT Security Does a Washington Law Firm Need Beyond Its Practice Management System?

A Washington law firm needs IT security that protects everywhere client data actually lives — not just the practice management application. That means hardened email and Microsoft 365 with MFA, managed endpoint detection and response on every device, encrypted laptops and phones, segmented Wi-Fi, a documented incident response plan, and vendor due diligence on every cloud tool that touches client information. The practice management vendor’s marketing brochure does not get you to compliance with RPC 1.6 — your whole environment does.

What Does RPC 1.6 Actually Require of a Washington Attorney?

Washington’s Rule of Professional Conduct 1.6 is the binding rule. Subsection (c) requires a lawyer to “make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.” The comments to RPC 1.6 — and the general body of guidance attorneys rely on — make clear that “reasonable efforts” is measured against the sensitivity of the information, the cost of additional safeguards, and the difficulty of implementing them.

It is critical to separate what is binding from what is guidance:

  • RPC 1.6 is binding. Violations are a disciplinary matter.
  • WSBA Advisory Opinion 202505 is specifically about generative AI in legal practice — it addresses confidentiality obligations when attorneys use AI tools, not a general technology baseline. Useful, but narrow.
  • ABA Formal Opinions (such as 477R on electronic communications and 483 on cyber incident response) are guidance. They are persuasive and frequently cited, but they are not Washington law.

When a vendor tells you their tool is “ABA-compliant” or “RPC 1.6-compliant,” remember that no software is compliant on its own. Compliance is something a firm does, not something a SaaS product is.

Why the Practice Management System Is Only Part of the Story

Practice management platforms like Clio, MyCase, PracticePanther, and Smokeball encrypt their hosted data and offer MFA. That is good. It is also nowhere near sufficient, because client confidential information leaves the practice management system constantly:

  • Email. Drafts, attachments, settlement figures, opposing counsel discussions, and client communications live in Microsoft 365 or Google Workspace — not in your matter management software.
  • Document drafting. Attorneys draft in Word, save to OneDrive or a local drive, mark up PDFs in Adobe, and exchange redlines over email.
  • Endpoints. A laptop in a coffee shop on the Mukilteo ferry contains cached email, downloaded discovery, draft pleadings, and saved passwords.
  • Mobile devices. Phones receive client texts, calendar invites with matter names, and emails with attachments.
  • Cloud storage and collaboration. Dropbox, Box, SharePoint, Teams, and Zoom recordings hold meaningful client information.
  • Discovery tools and e-discovery vendors. Third-party platforms hold massive volumes of client and opposing-party data.

A breach at any one of those points is just as much an RPC 1.6 problem as a breach at the practice management vendor. The April 2026 Silent Ransom Group leak tied to Orrick illustrates the same lesson: most law firm exposure comes through phishing, downstream vendors, and email — not the case management system. (Note: the Orrick April 2026 references in trade press tie back to the 2026 SRG breach, not Orrick’s earlier 2023 incident — two separate events.)

What Should the IT Security Baseline Actually Be?

Here is the floor a Western Washington law firm should not operate below. None of this is gold-plating — this is what auditors, cyber insurance carriers, and clients expect.

Identity and Access

  • MFA on every account that can reach client data — email, practice management, file storage, VPN, remote access. Phishing-resistant MFA (passkeys, FIDO2, or app-based number matching) wherever supported. See MFA for business 2026 for the practical why.
  • Unique accounts only. Shared logins for paralegals or contract attorneys defeat audit logging.
  • Conditional Access policies in Microsoft 365 that block legacy authentication, enforce compliant devices, and limit risky sign-ins.

Endpoint Security

  • Full-disk encryption (BitLocker on Windows, FileVault on Mac) on every device that touches client data. This is the single most effective control against laptop theft, and it is non-negotiable.
  • Managed EDR on every endpoint — not consumer antivirus. See EDR for small business for the gap between traditional AV and EDR.
  • A managed update program that patches OS and third-party software (Adobe, Zoom, browsers) on a known cadence.

Email

  • Microsoft 365 Business Premium or E3/E5 with Defender for Office 365 turned on.
  • Anti-phishing, anti-spoofing, and impersonation protection enabled and tuned.
  • DKIM, SPF, and DMARC published and enforced on your sending domain. Most firms we audit have SPF but no DMARC enforcement.
  • Encrypted email for sensitive outbound communications (Microsoft Purview Message Encryption or a peer-to-peer secure messaging tool).

Network

  • Segmented Wi-Fi. Staff network, guest network, and any IoT (printers, smart speakers, cameras) on different VLANs.
  • A real firewall with documented rules — not a consumer router from the previous decade.
  • VPN or Zero Trust Network Access for remote attorneys, not split-tunnel chaos.

Backup and Incident Readiness

  • Immutable, off-site backups of the practice management database, the file server, and Microsoft 365 (yes, Microsoft 365 — Microsoft does not back up your tenant on your behalf).
  • A documented incident response plan with cyber insurance, outside counsel, and law enforcement contacts pre-populated. ABA Opinion 483 expects you to notify affected clients of a breach affecting their matter information.
  • Tabletop exercises at least annually, even if just an hour around a conference table.

What About AI Tools in a Law Practice?

This is where WSBA Advisory Opinion 202505 matters specifically. The opinion addresses how confidentiality obligations under RPC 1.6 apply to generative AI tools. The practical translation:

  • Do not paste client information into a free public LLM where the prompts may be used to train models.
  • Use enterprise AI tools (Microsoft Copilot for Microsoft 365 with the right tenant settings, vendor tools with signed agreements that prohibit training on your data).
  • Document your AI use in your engagement letters and your firm’s written information security policy.
  • Apply the same vendor-due-diligence rigor to AI tools that you would apply to a discovery vendor.

The opinion is narrow but useful — and Washington’s enforcement posture will likely lean on it as AI use spreads through practice.


ROI Technology Inc. provides security-first IT management to law firms across Western Washington — endpoint hardening, Microsoft 365 lockdown, immutable backups, and incident response readiness aligned to RPC 1.6 expectations. Contact us or call (888) 707-3652 for a no-cost gap assessment focused on the parts of your environment your practice management vendor never sees.