After a law firm suffers a data breach or ransomware attack, when must a New York lawyer tell clients, and can the lawyer pay or lie to the extortionist?
Apply this to your situation
This page answers the general question as of 2024. Ezel answers yours: whether it's allowed on your facts, under the current New York Rules of Professional Conduct, with citations.
Plain-English summary
The opinion addresses what the New York Rules of Professional Conduct require of a lawyer or law firm that experiences a cybersecurity incident, defined to include confidentiality, integrity, and availability incidents (data theft, data alteration, and lockout/denial-of-service). It adopts the analysis of ABA Formal Opinion 483 (2018) on the duties of competence and confidentiality.
On protection, the opinion concludes that Rules 1.1, 1.3, and 1.6(c) require lawyers to understand the technologies they use, safeguard client data, monitor for incidents, investigate promptly, and mitigate harm. Rules 5.1 and 5.3 extend those reasonable-efforts duties to firm personnel and outside vendors, with the level of diligence scaled to firm size and the sensitivity of the information.
On notice, the opinion separates ethical duties from statutory, regulatory, and contractual breach-notification law, which it does not displace. Under Rule 1.4, a lawyer must promptly notify a current client when a cyber incident is a "material development" in the matter, meaning the incident compromises (or substantially threatens) the client's confidential information obtained in a current matter, or an availability incident materially impairs the lawyer's ability to represent the client. There is no Rule 1.4 duty to notify former or prospective clients in most circumstances, though Rule 1.15 fiduciary duties may apply to retained property, and a lawyer may choose to notify where reasonable.
On the extortionist, the opinion concludes there is no rule barring or requiring payment of a ransom, and that paying to recover systems or data does not violate Rule 8.4 because the firm is the victim of a crime. Drawing on Comment [2] to Rule 4.1 and the public-interest rationale of prior opinions, it concludes that a lawyer may bluff and be not candid about the attack's impact, the victim's finances, and mitigation steps when negotiating with a cyber-extortionist, a departure from the candor expected in ordinary settlement negotiations.
In practice
Under this opinion, a New York lawyer who learns of a cyber incident must investigate and, where the incident is a material development, give Rule 1.4 notice to current clients "at the earliest time" after the lawyer has enough information to determine whether and how the client's confidential information or representation is affected. The opinion ties the meaning of "promptly" to its earlier Opinions 2012-1 and 2016-3, equating it with "as soon as practical." Disclosure to law enforcement or a government investigation is permitted only as Rules 1.6, 1.9, and 1.18 allow, and the lawyer should weigh whether to withhold client identities, obtain consent, or rely on the implied-authorization exception, disclosing only what is reasonably necessary.
The opinion also identifies a Rule 1.7(a)(2) conflict that can arise when the lawyer's interest in avoiding reputational harm or a malpractice claim diverges from the client's interest in notification or further reporting. In that situation the lawyer may advise the client only with informed consent confirmed in writing, and may have to decline to advise on the incident or withdraw entirely.
Common questions
Q: After a ransomware attack on my firm, do I have to tell my clients?
A: Under Rule 1.4, you must promptly notify a current client when the incident is a material development, which the opinion says always applies where confidential information obtained in a current matter is breached, and applies to an availability/lockout incident only where it materially impairs your ability to represent the client. There is no Rule 1.4 duty to notify former or prospective clients in most circumstances.
Q: Can I pay the ransom, or am I required to?
A: The opinion concludes there is no rule prohibiting payment and none requiring it. Paying to recover systems or client data does not violate Rule 8.4 because the firm is the victim, though the opinion notes OFAC sanctions risk if the payee is a sanctioned entity.
Q: Can I lie to the cyber-extortionist during negotiations?
A: The opinion concludes that, unlike ordinary settlement negotiation, the accepted conventions of negotiating with a cyber-extortionist permit a lawyer to bluff and be not candid about the attack's impact, the firm's financial situation, and mitigation steps, grounded in Comment [2] to Rule 4.1 and the public interest in thwarting cyber criminals.
Q: Does my ethical breach-notice duty satisfy data-breach statutes?
A: No. The opinion stresses that Rule 1.4 obligations are separate from statutory, regulatory, and contractual breach-notification requirements; satisfying one does not satisfy the other, and each must be analyzed independently.
Q: Can I still advise my client about the incident if my firm caused it?
A: Possibly not. The opinion finds a Rule 1.7(a)(2) conflict can arise when the lawyer's interest in avoiding disclosure or a malpractice claim differs from the client's interest. The lawyer may continue only with informed written consent and a reasonable belief that competent representation is still possible, and may have to withdraw.
Background and rules framework
The opinion interprets the New York Rules of Professional Conduct, which track the ABA Model Rules. The core provisions are Rule 1.1 (competence, including technological competence under Comment [8]), Rule 1.3 (diligence), Rule 1.4 (communication), Rule 1.6(c) (reasonable efforts to prevent unauthorized access to confidential information), Rules 1.9 and 1.18 (confidentiality to former and prospective clients), Rule 1.15 (safekeeping property), Rules 5.1 and 5.3 (supervision of lawyers, nonlawyers, and vendors), Rule 4.1 (truthfulness to third persons), and Rule 8.4(b), (c), and (h) (misconduct). The opinion expressly adopts ABA Formal Opinion 483 (2018) and cites parallel opinions from California, Colorado, Kentucky, Michigan, and others on the duty to notify clients of a breach.
Citations and references
Rules of Professional Conduct:
- MR / NY RPC 1.1 (competence, technological competence per Comment [8])
- MR / NY RPC 1.3 (diligence)
- MR / NY RPC 1.4 (communication; prompt notice of material developments)
- MR / NY RPC 1.6(c) (reasonable efforts to safeguard confidential information)
- MR / NY RPC 1.7(a)(2) (personal-interest conflict)
- MR / NY RPC 1.9, 1.18 (former and prospective client confidentiality)
- MR / NY RPC 1.15 (safekeeping property)
- MR / NY RPC 5.1, 5.3 (supervision of firm personnel and vendors)
- MR / NY RPC 4.1 and Comment [2] (truthfulness; negotiation conventions)
- MR / NY RPC 8.4(b), (c), (h) (misconduct)
Statutes:
- N.Y. Judiciary Law (CLE cybersecurity requirement referenced)
Cases:
- SEC v. Covington & Burling, LLP, No. 23-mc-00002 (APM), 2023 WL 4706125 (D.D.C. July 24, 2023), order to disclose client identities affected by a cyberattack
- Sage Realty Corp. v. Proskauer Rose Goetz & Mendelsohn LLP, 91 N.Y.2d 30 (1997), fiduciary duty may continue after representation ends
Other opinions cited:
- ABA Formal Op. 483 (2018): lawyers' obligations after an electronic data breach
- ABA Formal Op. 481 (2018): no Rule 1.4 duty to communicate with former clients
- New York State Op. 842 (2010): notice of cloud-storage breach
- New York City Op. 2017-5: U.S. border searches of devices
- New York City Op. 2015-6: notice of inadvertently destroyed files
- New York City Op. 2012-1: meaning of "promptly" under Rule 4.4
See also
- ABA Ethics Op. 483: Data-breach obligations
- ABA Ethics Op. 481: Duty to inform client of material error
- NYC Bar Ethics Op. 2017-5: Border searches of lawyers' devices
- NYC Bar Ethics Op. 2015-6: Notice when client files are destroyed
Source
- Landing page: https://www.nycbar.org/reports/formal-opinion-2024-3-ethical-obligations-relating-to-a-cybersecurity-incident/
- Original PDF: https://www.nycbar.org/wp-content/uploads/2024/07/20221319_EthicsOpinionCybersecurityIncidents.pdf
Get today's answer for your situation
You just read a 2024 opinion on this question. Ezel checks the current New York Rules of Professional Conduct and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.