Law Firms
Your Clients Trust You With Their Most Sensitive Matters. Who's Watching Out for You?
Ethics-driven cybersecurity for law firms - nationwide
Law firms have an ethical duty to protect client information. ABA Model Rule 1.6(c) — adopted in some form by nearly every state — requires attorneys to make reasonable efforts to prevent unauthorized access to, or disclosure of, client information. Most state bars now expect practical safeguards like multi-factor authentication, encryption, secure backups, access controls, and ongoing security training.
We help law firms nationwide put those safeguards in place in a way that's understandable, documented, and supportable.
Most states have adopted the ABA Model Rules with their own modifications, and many state bars have issued formal ethics opinions specifically addressing cybersecurity obligations. We help you align with the ABA framework as a baseline and can discuss your state's specific guidance during our assessment.

36 Years in Business | 50+ Written Testimonials | Live Phone Answered Every Time
You've gotten this far without an IT company.
Your computers mostly work. Why change now?
We are living in a different world now with AI, Cybercrime and the need for employee security training
It Happened to a Broker. True story. It Could Happen to You.
A few years ago, a bond broker received a call no one ever wants to receive.
His email had been hacked. $10,000,000+ that should have gone to his client ended up in the hands of criminals — and it was gone. Not delayed. Not recoverable. Gone.
Was it the bank's fault? Technically, yes. They wired the money without verifying where it was going. But the client didn't blame the bank.
They blamed him.
And just like that, a career built on trust and relationships was in serious jeopardy — not because of anything he did wrong, but because a criminal got into his inbox.
Sound familiar? Your clients trust you with sensitive information, private communications, and in many cases, their most important legal matters. That trust is everything. One compromised email, one stolen file, one data breach — and the question your clients will ask isn't how it happened.
It'll be: "Why didn't you protect us?"
You shouldn't have to become a cybersecurity expert to protect your clients. That's not why you went to law school. But you do deserve a partner who handles it for you — quietly, completely, and without drama.
That's exactly what we do.

Ethical duty to protect client information (ABA Model Rule 1.6)
ABA Model Rule 1.6(c) calls on attorneys to make reasonable efforts to prevent unauthorized access to, or disclosure of, information relating to client representation. In today’s threat landscape (phishing, ransomware, business email compromise), “reasonable efforts” commonly translate into clear, repeatable cybersecurity controls.
What “reasonable efforts” looks like in day-to-day practice
We help law firms implement and maintain safeguards such as:
- Multi-factor authentication (MFA) for email and critical systems
- Least-privilege access controls and regular access review
- Encryption where appropriate (devices, backups, secure file sharing)
- Secure, recoverable backups designed for ransomware scenarios
- Endpoint protection + monitoring to detect suspicious activity early
- Patch management for Windows/macOS, browsers, and key applications
- Security awareness training to reduce phishing and credential theft
- Incident response planning so you know what to do if something happens
Technology competence matters too
ABA Model Rule 1.1 Comment 8 highlights that attorneys should understand the benefits and risks of relevant technology. We translate that into simple policies, user training, and documented procedures that fit a small-to-midsize law firm.
State bar opinions on cybersecurity (examples):
- New York — NYRPC 1.6 commentary addresses electronic security and lateral moves
- California — Formal Opinion 2010-179 on cloud computing and confidentiality
- Texas — Opinion 665 on cybersecurity obligations for lawyers
- Florida — Ethics Opinion 12-1 on cloud storage and email security
- New Jersey — Opinion 701 on reasonable security measures
Your state likely has similar guidance. We’ll discuss it during your assessment.
Note: Note: Saunders I.T. provides IT and cybersecurity services, not legal advice. Attorneys should consult their applicable state rules, ethics opinions, and bar guidance for their specific obligations.
Want a quick, practical review of your current risk and gaps? Schedule a plain-English conversation.
Why Attorneys Are Specifically Targeted
39%
According to a survey by Arctic Wolf and Above the Law, 39% of respondents reported that their firm had a security breach they were aware of in the last year. Among those firms that experienced a breach, 56% lost confidential client data.
~40%
A 2024 survey cited by Embroker found that up to 40% of law firms have experienced a security breach, consistent with the "4 in 10" figure reported by Tech Advisors.
~50%
Attorneys Insurance Mutual of the South (AIM), which provides malpractice insurance for Alabama attorneys, references that "more than half of surveyed law firms in the United States experienced a data breach last year.
Free Download
The Law Firm IT & Cybersecurity Guide:
Questions Every Attorney Should Be Asking
Get your free copy of our comprehensive Q&A guide covering cybersecurity, client confidentiality, AI risks, backup & recovery, and much more — written specifically for small law firms in plain English.

Download Your Free Guide
What You Do About It
Protect Client Data. Stay Up. Keep Working.
Managed cybersecurity for small law firms (15 or fewer employees).
GUARD IT Complete
Monthly Managed Security, Monitoring & Training Service -- $197.00 Per Device (PCs and Macs)
Guard IT Complete is a monthly, per-device managed security, monitoring, and cybersecurity training service provided by JRSJR Corporation DBA Saunders I.T. The service includes delivery, installation, configuration, and ongoing management of the tools listed below as a unified, continuously managed protection platform. Service is billed monthly with a minimum of $300.00 per customer account. The first calendar month is billed at $1.00 for new customers. A 90-day money-back guarantee applies to service fees only; hardware is excluded. Saunders I.T. retains the right to select, substitute, or update third-party vendors provided the scope of protection described herein is maintained.
- Endpoint Protection
Continuous, automated protection against viruses, malware, ransomware, and advanced cyber threats, powered by SentinelOne EDR technology. Application control (software whitelisting). - 24/7 Monitoring & Alerting
Round-the-clock monitoring for suspicious activity and anomalies. Includes ransomware detection and MDR/SOC coverage. Email Filtering and Security. - Monitored Backup
Guard IT Complete - includes - Automated full system backup including OS, applications, settings, and all data. Recovery available upon request. - Patch Management
Scheduled delivery and installation of OS and software security updates to reduce exposure to known vulnerabilities. - Cybersecurity Training
Documented cybersecurity and AI training for all employees and attorneys as well as regular phishing email tests. - Annual Dark Web Scan & Security Assessment
One annual dark web scan and external vulnerability/penetration assessment. Results provided in a written report.
- Network Security Platform
Multi-function network security: next-gen firewall, secure remote access, SSL/TLS inspection, threat intelligence, secure DNS, URL/content filtering, ZTNA, IP anonymization, always-on VPN, web proxy IPS/IDS. - Application Control
Software whitelisting to prevent unauthorized applications from executing on covered devices. - Cybersecurity Training & Phishing Simulations
Employee cybersecurity and AI awareness training, simulated phishing campaigns, training reports, and security policy templates. Covers all employees. - Email Filtering
Automated filtering of inbound and outbound email to block spam, phishing, malware, and email-borne threats. - File & Document Backup
Automated backup of user's computer. We monitor the backups daily and correct any issues that may occur. Restoration of files and folders are included as needed. - Software Deployment Labor
Labor for installation and configuration of managed software agents and tools.
NOTE: Guard IT Complete includes remote helpdesk or technical support.
GUARD IT Secure
Monthly Managed Security, Monitoring & Training Service -- $97.00 Per Device (PCs and Macs)
Guard IT Secure is a monthly, per-device managed security, monitoring, and cybersecurity training service provided by JRSJR Corporation DBA Saunders I.T. The service includes delivery, installation, configuration, and ongoing management of the tools listed below as a unified, continuously managed protection platform. Service is billed monthly with a minimum of $300.00 per customer account. The first calendar month is billed at $1.00 for new customers. A 90-day money-back guarantee applies to service fees only; hardware is excluded. Saunders I.T. retains the right to select, substitute, or update third-party vendors provided the scope of protection described herein is maintained.
- Endpoint Protection
Continuous, automated protection against viruses, malware, ransomware, and advanced cyber threats, powered by SentinelOne EDR technology. Application control (software whitelisting). - 24/7 Monitoring & Alerting
Round-the-clock monitoring for suspicious activity and anomalies. Includes ransomware detection and MDR/SOC coverage. Email Filtering and Security. - Monitored Backup
Guard IT Secure - includes - File & document backup (documents, spreadsheets, presentations, PDFs) - Patch Management
Scheduled delivery and installation of OS and software security updates to reduce exposure to known vulnerabilities. - Cybersecurity Training
Documented cybersecurity and AI training for all employees and attorneys as well as regular phishing email tests. - Annual Dark Web Scan & Security Assessment
One annual dark web scan and external vulnerability/penetration assessment. Results provided in a written report.
- Network Security Platform
Multi-function network security: next-gen firewall, secure remote access, SSL/TLS inspection, threat intelligence, secure DNS, URL/content filtering, ZTNA, IP anonymization, always-on VPN, web proxy IPS/IDS. - Application Control
Software whitelisting to prevent unauthorized applications from executing on covered devices. - Cybersecurity Training & Phishing Simulations
Employee cybersecurity and AI awareness training, simulated phishing campaigns, training reports, and security policy templates. Covers all employees. - Email Filtering
Automated filtering of inbound and outbound email to block spam, phishing, malware, and email-borne threats. - File & Document Backup
Automated backup of user documents, spreadsheets, PDF files, and presentations only.-- does not include backing up pictures, music, emails, or anything else not listed above. - Software Deployment Labor
Labor for installation and configuration of managed software agents and tools.
NOTE: Guard IT Secure does not include remote helpdesk or technical support. Remote support is billed separately or added via upgrade to Guard IT Complete.
Testimonials
How It Works — 3 Steps
Step 1
Schedule a 15-minute phone call
(no obligation, no jargon)
Step 2
We review how your firm is set up and show you exactly where your risks are
Step 3
You decide if we're a fit — we never pressure anyone






