Photo by Mikhail Nilov / Pexels
Most small firms I talk to believe they already have confidentiality handled. Nobody discusses clients outside the office, the computers have passwords, and the email is encrypted. That is where I push back. Confidentiality stopped being mainly a conversation habit a long time ago. It is now a question of where client information actually lives and who can reach it.
At a typical Providence firm, that information is sitting in email, Microsoft 365, attorney laptops, shared folders, phones, backups, and sometimes a personal device at home. Rhode Island's confidentiality obligation is broad: it covers information relating to the representation, not just privileged conversations. If the duty is that wide, the IT environment has to be built to match it. In a lot of small firms, the protection effectively stops at the login screen.
Rhode Island changed its competence rule in June 2026, and that should change how you buy IT
In June 2026 the Rhode Island Supreme Court updated its competence rule to say that lawyers should keep up with the benefits and risks of existing and developing technology. That is not a national trend piece or a vendor talking point. It is the rule that governs practice here, and it applies to a two-attorney office in Providence the same way it applies to a large firm downtown.
It does not mean every attorney needs to become an IT expert. It does mean that "I don't understand technology" is not much of a strategy anymore. Someone at the firm has to be able to say what protects client files, what the known gaps are, and why the firm decided to accept or close each one.
Practically, that changes what a firm should be buying. An IT provider who installs equipment and sends an invoice does not get you there. You want one who will explain the risks in language an attorney can act on, document what protections are actually in place, and help the attorneys make informed decisions they can defend later. At a three-attorney firm with no IT staff, your provider is, for all practical purposes, where the firm's technology competence comes from. Hire with that in mind. If you are already wondering whether your current provider is the right one, our post on the signs it's time to switch IT providers is a good place to start.
At a two- or three-attorney firm, the bigger risk is sloppiness, not hackers
Real attackers are absolutely a threat, and I am not telling anyone to relax about that. But at that size, the exposure I expect to find first is ordinary everyday carelessness:
- A client document emailed to the wrong address, or to the right name at the wrong firm
- A shared folder opened up to everyone to solve a quick access problem, and never closed back down
- A former employee's or contract paralegal's account still active months after they left
- An attorney working from a personal laptop or phone with no controls on it at all
- Someone approving an unexpected multi-factor prompt just to make it go away
None of that requires a sophisticated attacker, and any of it can expose client information just as effectively as one. Attorneys handle sensitive information every single day, which means the small mistakes get a lot of chances to happen. That is why I would rather spend a client's money on controls that limit how much any one mistake can expose than on asking five people to be careful every time. If you want to see how we support law firms on exactly this, that is a conversation we have often.
"We use encrypted email, so we're covered"
I hear that sentence often, and my honest response is that encrypted email is one control, not a security program. It is a reasonable control and I am not telling anyone to turn it off. But it does nothing about:
- A compromised mailbox, where the attacker is simply reading mail as the attorney
- A lost or stolen laptop with local copies of client files on it
- An old account nobody got around to disabling
- Multi-factor that is easy to bypass, or easy to approve by accident
- Permissions that are far broader than anyone needs
- Confidential files downloaded to an unmanaged personal device
Even the ABA's guidance treats secure communication as a risk-based question. The standard is reasonable safeguards around the information, judged against how sensitive the matter is, not whether a particular message went out encrypted. Encryption gets the attention because it is the one control a client can actually see. The controls that would have prevented the worst outcomes are invisible to clients, so they tend not to get bought.
If you fix one confidentiality thing this year, fix identity and access
If a small firm came to me with budget for exactly one improvement, I would tighten identity and access control. Four things, in this order:
- Enforce strong multi-factor authentication on every account, including the attorneys who find it annoying. App-based approval or number matching holds up considerably better than text-message codes.
- Remove accounts the day someone leaves, and that includes contractors, temporary staff, and the old shared mailbox nobody uses anymore.
- Cut administrative privileges down to the people who genuinely need them, which is almost always fewer people than currently have them.
- Give each person access to the matters and folders they actually work on, rather than everything by default.
The reasoning is simple. A compromised account with broad access can expose far more client information than any single unencrypted email ever could. An attacker holding a valid login with firm-wide access does not have to break anything; they just read. If that same account has strong multi-factor and is scoped to the matters that person works on, the identical mistake becomes a contained incident instead of a notification event across your whole client list.
The honest takeaway is that confidentiality at a small firm is now mostly an access question, and that it is answered by configuration rather than by intent. If you want a concrete first step this month, get a current list of every account in your Microsoft 365 tenant, who holds administrative rights, and what each person can actually open. Most firms are surprised by at least one line on that list. If you would rather not work through it alone, get in touch and we will go through it with you and tell you plainly what we would tighten first.
