Law firms hold some of the most sensitive data in any organization: attorney-client privileged communications, litigation strategy, M&A deal details, personal financial information, and confidential settlement terms. That makes them a high-value target for cybercriminals and creates significant professional responsibility obligations around data security.
In New York, law firm IT compliance sits at the intersection of the Rules of Professional Conduct, the NY SHIELD Act, and increasingly, the contractual security requirements of enterprise and financial services clients. This guide covers what NYC law firms need to have in place — and the IT infrastructure decisions that determine whether you’re meeting those obligations.

Professional Responsibility and IT Security: The New York Framework
The New York Rules of Professional Conduct impose data security obligations on attorneys that translate directly into IT requirements:
- Rule 1.6 (Confidentiality): Attorneys must make reasonable efforts to prevent unauthorized disclosure of client information. The New York State Bar has clarified that “reasonable efforts” in the current environment require encryption, access controls, and employee security training — not just general care.
- Rule 5.3 (Responsibilities Regarding Nonlawyer Assistance): Partners and supervising attorneys are responsible for ensuring that IT staff, managed service providers, and other vendors handling client data comply with the same confidentiality obligations.
The NY SHIELD Act and Law Firm Data Security
New York’s Stop Hacks and Improve Electronic Data Security (SHIELD) Act applies to any business that handles private information of New York residents — which includes virtually every law firm in the state. SHIELD Act requirements include:
- Implementing a written data security program with administrative, technical, and physical safeguards
- Conducting risk assessments and addressing identified vulnerabilities
- Training employees on cybersecurity best practices
- Properly disposing of data that’s no longer needed
- Prompt breach notification to affected individuals and the NY Attorney General
The Technical Controls NYC Law Firms Need
Encrypted Email and Communication
Sending unencrypted emails containing client confidential information is a potential ethics violation. Law firms should use encrypted email solutions for sensitive client communications, or at minimum use Microsoft 365 with Message Encryption enabled and policies configured to protect attorney-client content automatically.
Document Management Security
Access to client matters should be role-based and matter-specific — not open to every attorney and staff member at the firm. Modern document management systems (iManage, NetDocuments, SharePoint) support matter-based access controls. Implementing and maintaining these controls is an IT responsibility, not just a configuration choice.
Endpoint Security and Device Management
The 2020 New York State Bar guidance on cybersecurity best practices specifically addresses mobile devices. All devices used for client work — firm-owned and BYOD — should have full disk encryption, remote wipe capability, and enforce screen lock policies. An MDM (Mobile Device Management) solution makes this enforceable rather than aspirational.
Multi-Factor Authentication
MFA on email, document management systems, and remote access is now a baseline requirement for firms that carry cyber liability insurance — and a strong argument for coverage in the event of a breach. Many NYC law firms still lack MFA on email, which remains the most common entry point for both data theft and business email compromise fraud targeting wire transfers.
Vendor Due Diligence
Under both professional responsibility rules and the SHIELD Act, law firms must assess the security practices of vendors who handle client data. This means signed data processing agreements, security questionnaires, and periodic reviews for cloud vendors, e-discovery providers, outsourced IT, and any SaaS applications with access to client information.
The New York State Bar has been clear: competence in the modern era includes technological competence. An attorney who doesn't understand whether their client's data is protected has a professional responsibility problem, not just a technology problem.
Cyber Insurance and IT Compliance
New York law firms face an increasingly rigorous cyber insurance underwriting process. Insurers now routinely ask about MFA deployment, EDR coverage, backup testing, and security awareness training before issuing policies — and are denying claims or reducing coverage where those controls were absent. Your IT security posture directly affects your insurability and your premium.
SolvedIT Inc. provides managed IT services and compliance support to law firms throughout New York City, New Jersey, and Connecticut. We understand the professional responsibility framework, work alongside your firm’s risk and ethics counsel, and build IT infrastructure that meets both your security requirements and your clients’ vendor security expectations. Contact us to assess your firm’s IT compliance posture.



HighLevel
Triton Sensors