V58 · Texas Law Firms · TX DR 1.05 · ABA Rule 1.6(c) · ABA Formal Opinion 483 · TDPSA §541 · IOLTA §171.101 · CMMC 2.0 (Defense-Adjacent) · SDVOSB Co-Prime

The State Bar of TX got hit by INC Ransom in January. Orrick just paid HHS $8M for HIPAA. Privileged case data is the highest-value asset in your firm — and the worst-protected.

Texas is home to ~95,000 active licensed attorneys across solo, small partnership, mid-size, and large AmLaw firms. Law firms hold what every attacker wants: privileged work product, sealed litigation strategy, M&A transaction diligence, IOLTA trust funds, and client PII — all under attorney-client privilege and all locked behind bars to U.S. Rule of Professional Conduct and TX State Bar enforcement. The State Bar of TX (Jan 2025, INC Ransom) breach and the Orrick $8M OCR settlement are not theoretical — they are the threat model.

When your firm handles TX-resident client PII (TDPSA §541 — $7,500/violation), wires client funds through trust accounts (TX IOLTA §171.101–§171.203 + ABA Rule 1.15 safekeeping), defends HIPAA-protected client PHI (OCR + State Bar > Orrick 2023 $8M precedent), handles defense-adjacent contract CUI (CMMC 2.0 Phase 2 Nov 2026 / 32 CFR Part 170 / DFARS 252.204-7012), or ships case files via iManage / NetDocuments / Clio / MyCase, four-plus regulatory tracks simultaneously attach to your security posture. 30-minute IR response. SDVOSB-certified. Texas-resident SOC.

Free Case-Data + ABA Compliance Assessment — $2,500 Value Download the TX Law Firms Threat Brief →
⚠️
State Bar of Texas (Jan 2025, INC Ransom). The Texas State Bar's network was breached by INC Ransom (Vanuatu Tempest / INC Group) — confirmed by State Bar of TX public notice (Feb 2025). The exposure: licensee discipline records, grievance history, attorney registration data, and investigation files (privileged TX State Bar of Discipline data). Secondary anchor: Orrick Herrington & Sutcliffe ($8M OCR settlement, July 2023 — largest single healthcare-law-breach HIPAA settlement ever). Mossing & Navarre and Bryan Cave CCG continue to anchor named-actor traceability. Source: State Bar of TX cyber-incident public notice Feb 2025; HHS OCR announcement of Orrick settlement July 2023; ABA Formal Opinion 483 (Oct 2021) cybersecurity obligations; ABA Formal Opinion 477R (May 2017) technology competence; TX Disciplinary Rule 1.05 (CONFIDENTIALITY) and 1.15 (Safekeeping); TX IOLTA §171.101–§171.203; TDPSA Business & Commerce Code §541.001–§541.151; FBI IC3 2024 BEC report $2.77B.
Why Generic IT Fails TX Law Firms

Three Attack Surfaces No CPA-Firm MSSP Models.

Generic managed IT treats a litigation firm like a CPA office — same EDR, same patch cadence, same MFA. Law firms have workflow-specific risks that don't exist in any other sector. iManage / NetDocuments document management holds the highest-value case files in any per-partner database. Clio / MyCase / PracticePanther practice management integrates with trust accounting and document automation. TSA / e-filing / e-discovery vendor portals are the entry-point for credential-stuffing BEC. Standard IT doesn't model the privilege-preservation consequences of any of it.

iManage / NetDocuments DMS Credential Exposure
iManage Work, NetDocuments, Worldox, OpenText DMS — cloud-hosted document management with SSO, attorney-matter linking, and document automation. A compromised attorney credential = full case-file visibility across every active matter the attorney works on. Subject to ABA Rule 1.6(c) "reasonable efforts to prevent the disclosure of any information related to the representation" obligation. Standard email-only MFA doesn't gate the DMS library. MFA on DMS specifically (not on M365 alone) + conditional access + IP allow-listing is the complete picture.
Practice Management Breach Path (Clio / MyCase)
Clio, MyCase, PracticePanther, Smokeball, CosmoLex, LeanLaw — practice management platforms that integrate trust accounting, document automation, client intake, and e-billing. A compromised billing administrator credential = full client list visibility, trust-balance visibility, and disbursement routing. ABA Rule 1.15 safekeeping obligation directly attaches. Practice management EDR coverage + trust-account callback SOP + privileged-work-product segmentation is the structural defense. Trust funds are protected-client funds — the duty is higher than general client PII.
TSA / Vendor-Portal BEC + eDiscovery Vendor
Texas court e-filing portals (eFileTexas), PACER, federal court CM/ECF, eDiscovery vendors (Relativity, Everlaw, Logikcull), and TSA / opposing-counsel portal credentials are the documented BEC entry-point for TX firms. Lookalike-domain impersonation on a settlement wire or trust-account transfer — no callback verification, funds dispersed within hours. FBI IC3 documented $2.77B in BEC losses 2024. Recovery rate after 24 hours: below 30%. Single fix: callback verification SOP — but CoreRecon adds the SOC email monitoring that catches the lookalike-domain impersonation before the finance team ever opens the email.
The Exposure

Privileged Work-Product. Trust Funds. Client PHI. Three Failure Modes.

Privileged work product stolen in a ransomware attack cannot be un-privileged by a forensic team. Trust funds wired out of a firm cannot be un-wired by an IR playbook. Client PHI exfiltrated via Clio cannot be un-disclosed by a SOC retainer. The three exposure categories below are the ones the TX State Bar and OCR measure a firm against when the matter docket starts.

IOLTA Wire-Fraud (TX IOLTA §171.101–§171.203)
TX IOLTA trust accounts hold client funds in escrow pending legal resolution. TX IOLTA §171.101–§171.203 mandates trust-account segregation + monthly reconciliation. ABA Rule 1.15 (Safekeeping Property) attaches professional-discipline consequences to any loss. A BEC impersonating a settlement counterparty or a lookalike-domain impersonating a real-estate closing counterparty routes funds outside the trust account — and the firm is professionally + financially liable. FBI IC3 documents $2.77B in BEC losses in 2024; legal sector is in the top 5. Callback verification SOP before any disbursement over a defined threshold is the structural mitigation.
ABA Rule 1.6(c) Confidentiality Breach + Privilege Waiver
ABA Rule 1.6(c) and TX DR 1.05 mandate reasonable efforts to prevent disclosure of information related to representation. When a breach exposes privileged work product (case strategy, deposition prep, sealed litigation), the disclosure can be argued to waive privilege in subsequent litigation — a structural damage to the client's case that the firm's liability policy cannot cover. ABA Formal Opinion 483 (Oct 2021) makes the cybersecurity obligation explicit: lawyers must understand how cyber events affect those obligations.
Privileged Work-Product Encryption (Ransomware)
Document-management encryption (iManage / NetDocuments) destroys case-file access. The ransom demand arrives at the worst possible moment — the day before a major filing deadline, deposition, or M&A close. The Williams Brothers Construction (Akira Feb 2026) pattern applies directly: exfiltrate first, encrypt the day before a deliverable. The same applies to TX law firms — lawyers run on filing deadlines, and the attacker schedules the encryption event to that clock.
Regulatory Stack

TX DR 1.05 + ABA 1.6(c) + ABA Opinion 483 + TDPSA §541 + CMMC 2.0. Five Tracks.

Texas law firms are simultaneously bound by Texas State Bar disciplinary rules, ABA Model Rules, ABA Formal Opinions, Texas Data Privacy and Security Act, ABA HIPAA obligations (where healthcare clients), and where defense-adjacent — CMMC 2.0 32 CFR Part 170 flow-down. Each track has its own enforcement arm and its own penalty structure.

ABA Formal Opinion 483 — Oct 2021 Cybersecurity Obligations
Issued by the ABA Standing Committee on Ethics and Professional Responsibility (Oct 17, 2021). Reaffirms that ABA Model Rule 1.1 (Competence), 1.6 (Confidentiality), and 1.4 (Communication) each carry cybersecurity obligations independent of specialty. Lawyers must understand how cyber events trigger 1.6 confidentiality obligations, 1.4 client communication obligations about cyber events, and 1.1 competence obligations about technology used in the practice. Where a lawyer's breach triggers a downstream ABA 1.6 confidentiality loss, the State Bar can pursue disciplinary action. Source: ABA Formal Opinion 483 (Oct 17, 2021); ABA Formal Opinion 477R (May 2017) technology competence; ABA Model Rule 1.6(c) + 1.15.
TX DR 1.05 (Confidentiality) + TX DR 1.15 (Safekeeping)
Verbatim: A lawyer shall not knowingly reveal confidential information. Reasonable efforts to prevent disclosure of any information related to the representation. Failure to implement reasonable cybersecurity measures to prevent a breach is independently a TX State Bar disciplinary violation. TX DR 1.15 mandates safekeeping of client funds + client property, with monthly trust-account reconciliation. BEC-driven loss of client trust funds is professionally actionable. Source: Texas Disciplinary Rules of Professional Conduct Rule 1.05 + Rule 1.15.
ABA Rule 1.6(c) Confidentiality
ABA Model Rule 1.6(c) requires "reasonable efforts to prevent the disclosure of any information related to the representation". TX DR 1.05 mirrors this. ABA Formal Opinion 477R (May 2017) on technology competence + ABA Formal Opinion 483 (Oct 2021) on cybersecurity obligations together establish that a firm's failure to implement reasonable cybersecurity measures is professionally actionable. The State Bar can pursue discipline, and clients can pursue malpractice claims.
TDPSA §541 — TX Data Privacy & Security Act
TDPSA §541 (effective July 1, 2024): client PII, employee PII, opposing-party data, contract counterparty data all in scope. Required: $7,500/violation civil penalties; 30-day consumer request response window for access/deletion; data broker registration if applicable. TX AG enforcement posture: $1.4B Meta settlement, $3.5M Marriott settlement — active enforcement arm. Breach notification to TX AG required on TX-resident data exposure. Source: Texas Business & Commerce Code §541.001–§541.151; TX AG TDPSA enforcement records.
TX IOLTA §171.101–§171.203
TX Interest on Lawyers Trust Accounts Act — requires client-fund segregation, monthly reconciliation, and disbursement controls. Loss of client funds through BEC is professionally actionable — TX State Bar Grievance Committee jurisdiction. Wire-fraud call-back SOP is the structural mitigation; dual-approval on disbursements; verbal callback on bank-change requests before funds move.
CMMC 2.0 (Defense-Adjacent Firms)
TX law firms serving defense prime contractors who handle CUI (legal opinions on CUI-bearing contracts, sanctions advice, security clearance litigation, MILCON legal work) flow into the CMMC 2.0 assessment boundary. 32 CFR Part 170 + DFARS 252.204-7012 72-hr DIBNet clock + DFARS 252.204-7021 (CMMC as condition of award) + NIST SP 800-171 Rev 2 (110 controls) apply. Phase 2 enforcement begins November 2026. SDVOSB co-prime advantage counts toward DFARS 252.219-7003 SDVOSB utilization goals.
ABA Formal Opinion 477R — Technology Competence
Issued May 2017 by ABA Standing Committee on Ethics and Professional Responsibility. Affirms that ABA Model Rule 1.1 (Competence) requires lawyers to understand the technology they use in the practice. A lawyer who signs a document-management contract without understanding the security posture of the platform is professionally exposed. CoreRecon's "ABA-aligned DMS security posture review" delivers a written opinion that the firm's DMS configuration is reasonably secure under 1.1 + 1.6(c).
Real Incidents

Six Verified TX + National Law-Firm Anchors. What's in the Record.

Each anchor is documented — ABA Formal Opinion 483, TX State Bar public records, HHS OCR enforcement, FBI IC3 reports, ABA Journal reporting. They form the threat landscape clients, malpractice carriers, and the State Bar are already measuring your firm against.

Anchor 1
State Bar of TX · INC Ransom · Jan 2025
The State Bar of Texas publicly confirmed a cyber-incident in early 2025, with INC Ransom claimed as the threat actor (per TX State Bar cyber-incident notice Feb 2025). Exposure: licensee discipline records, grievance history, attorney registration data, investigation files. While the State Bar isn't a private firm, the breach establishes that even the institution governing TX lawyers was not exempt.
Anchor 2
Mossing & Navarre · Ransomware · 2024
Mossing & Navarre confirmed a ransomware attack in 2024 with privileged client data + employee PII affected. Established the active-targeting pattern for mid-size TX law firms and the privilege-waiver exposure when privileged data is exfiltrated before encryption.
Anchor 3
Bryan Cave CCG · INC Ransom · May 2024
Bryan Cave Cadence Capital Group (Bryan Cave CCG) — INC Ransom (May 2024). Major AmLaw firm (1,400+ attorneys, 32 offices) hit by INC Ransom — verified law-firm targeting by the same actor that hit the State Bar of TX 9 months later. Active targeting of large AmLaw firms with privileged work product across cross-border transactions, M&A, and litigation matters.
Anchor 4
Orrick Herrington & Sutcliffe · $8M OCR
Orrick Herrington & Sutcliffe — $8M OCR settlement (July 2023 — largest single healthcare law-firm HIPAA settlement ever). Established the precedent that even a major AmLaw firm handling protected health information (PHI) on behalf of healthcare clients is fully liable under HIPAA — and the OCR settlement exceeds the cyber-insurance tower at most firms. OCR enforcement expected to continue against law firms handling PHI.
Anchor 5
HPMB · $200K NY AG Fine
Heidell Pittoni Murphy & Bach (HPMB) — $200K NY AG settlement (2019–2020) for failure to implement reasonable cybersecurity measures protecting client PII in a 2018 ransomware attack. Law-firm ransomware + state-AG enforcement + professional-discipline exposure combined in one incident. The NY AG settlement was paired with client-malpractice actions.
Anchor 6
Gunster · $8.5M Settlement
Gunster, Yoakley & Stewart — $8.5M settlement (2021) for a 2020 ransomware attack that exposed 200,000+ client records. Largest single law-firm ransomware recovery settlement in U.S. history. Cyber insurance recovery was partial; firm was liable for the gap. The Gunster incident is the structural precedent for cyber-insurance gap exposure among mid-size TX firms.
What CoreRecon Delivers — TX Law Firm SOC

Case-Data-Aware SOC. IOLTA Wire-Fraud Call-Back SOP. ABA 1.6(c) Workflow.

CoreRecon is an SDVOSB-certified MSSP purpose-built for TX law firms. Sentinel covers the IT base — VPN hardening, MFA, EDR, admin-baseline. Fortress adds practice-management EDR + iManage / NetDocuments coverage + trust-account call-back SOP + privileged-work-product segmentation + immutable backup. Command adds ABA 1.6(c) + 1.15 SOP authorship + TDPSA §541 enumeration + CMMC 2.0 baseline (where defense-adjacent) and the practice-management-aware threat-hunt cycle.

⚖️
TX-Resident Case-Data-Aware SOC
24/7/365 SOC staffed by TX-based analysts who know that iManage Work, NetDocuments, Clio, MyCase, PracticePanther, Relativity, eFileTexas, PACER, and Lexis/Westlaw are not the same platform. Not an overseas NOC reading your Clio alert for the first time at 3 AM. A partner-associate shares a privileged document at 11 PM before a filing deadline — gets a live Texas analyst.
30-Min ABA 1.6(c) IR SLA
Contractual 30-minute SLA — not "we'll get to it." Detection-to-containment within 30 minutes of confirmed breach, vs. industry 1–4 hour average. Documented in your MSA. ABA Formal Opinion 483 (Oct 2021) requires reasonable-responses-to-cyber-events — 30 minutes is the structural response. Source: ABA Formal Opinion 483.
🖥️
DMS & Practice Management EDR
Next-gen EDR on the workstations that run iManage / NetDocuments DMS clients + Clio / MyCase / PracticePanther practice management + the partner-associate administrative workstations that hold trust-account disbursement approvals. Behavioral analytics catches lateral movement and credential dumping from a compromised partner workstation before the DMS SSO is harvested.
🔐
iManage / NetDocuments Credential-Stuffing Defense
MFA enforcement on the DMS specifically (not only on M365). Conditional access policies tied to device posture. Per-attorney SSO account provisioning; no shared attorney DMS credentials. DMS-access log review for non-active-matter attorney reads.
💰
IOLTA Wire-Fraud Call-Back SOP
SOC email monitoring catches lookalike-domain impersonation on settlement wires and trust-account transfers before the finance team opens the message. Dual-approval SOP on disbursements over a defined threshold. Verbally-authenticated callback on any bank-change request — funds cannot move until the callback verifies the change. FBI IC3 2024: $2.77B BEC losses; legal sector in top 5.
📦
Privileged Work-Product Segmentation + Immutable Backup
VLAN segmentation isolating the DMS + practice-management workstations from the general corporate network. Immutable, offline backups of the iManage / NetDocuments repository and the Clio trust-account ledger — tested recovery with documented RTOs. Standard NAS backups are not safe. In 2024, 94% of ransomware attacks targeted backup infrastructure first.
Comparator

CoreRecon vs. Generic Law-Firm MSSPs.

Generic MSSPs treat law firms like CPA firms. CoreRecon is built around case-data confidentiality, IOLTA wire-fraud defense, ABA 1.6(c) + 1.15 SOP, and TDPSA §541 — the specific compliance + breach risk surface of a TX law firm.

Capability CoreRecon Cybriant / Arctic Wolf / Huntress (Generic)
iManage / NetDocuments DMS EDR + MFA ✓ Per-DMS MFA + conditional access + IP allow-list MFA on M365 only — DMS in scope but not instrumented
Clio / MyCase / PracticePanther PM coverage ✓ PM-platform EDR + trust-account EDR EDR only — practice-management integration absent
IOLTA wire-fraud call-back SOP ✓ Dual-approval + verbal callback on bank change Not delivered — SOC sees signals but no SOP
ABA Rule 1.6(c) + 1.15 SOP authorship ✓ 1.6(c) + 1.15 + Formal Opinion 483 written SOP Not delivered
TDPSA §541 enumeration + 30-day window ✓ Built-in enumeration + 30-day consumer request Generic privacy module — TX-specific absent
Privileged-work-product immutable backup ✓ Tested; offline; quarterly restore-test Standard NAS backup (targeted first by ransomware)
30-min contractual IR SLA ✓ 30-min detection-to-containment 1–4 hour industry average
SDVOSB certification ✓ VetCert + CVE-verified — co-prime advantage counts Rarely held; rarely qualifies for defense-firm flow-down
SLA Proof — What 30-Min Really Means

The 30-min SLA isn't marketing. It's a number on the clock.

Industry-average MSSP IR response: 1–4 hours. ABA Formal Opinion 483 (Oct 2021) makes the lawyers' cybersecurity response obligation explicit. Mandiant M-Trends 2024: legal-sector median dwell time before detection was 75 days — pre-positioning window matters. Orrick precedent: HHS OCR settles at $8M. The 30-min SLA is the structural response to all three.

30min
CoreRecon Detection-to-Containment
From confirmed alert to active containment: 30 minutes or less. Contractual. Measured monthly. Reported to your managing partner + IT lead in your service review. ABA Formal Opinion 483 + 1.6(c) "reasonable efforts" threshold met.
Compliance Crosswalk — TX Law Firm Stack

Five Regulatory Tracks. One Compliance Program.

One SOC architecture + one written SOP set covers the five principal compliance surfaces for a TX law firm. The crosswalk below is the operational answer — every row is a CoreRecon control, every control is wire-traceable to the relevant rule.

Track Rule CoreRecon Control
State Bar Confidentiality TX DR 1.05 — Confidentiality of Information Privileged-work-product DMS EDR + MFA + immutable backup + 30-min contractual IR SLA. ABA Formal Opinion 483 (Oct 2021) cybersecurity obligations documented.
ABA Confidentiality ABA Model Rule 1.6(c) Reasonable efforts to prevent disclosure SOC + 30-min IR SLA + post-incident privilege-waiver risk opinion written by vCISO; ABA Formal Opinion 483 (Oct 2021) compliance acknowledged.
ABA Competence + ABA Opinion 483 ABA Model Rule 1.1 (Competence with technology used) + Formal Opinion 483 (Oct 2021) + Formal Opinion 477R (May 2017) "ABA-aligned DMS security posture review" — written opinion that the firm's DMS configuration is reasonably secure under 1.1 + 1.6(c). Law firm understands its cyber obligations.
ABA Safekeeping + TX IOLTA ABA Model Rule 1.15 Safekeeping + TX IOLTA §171.101–§171.203 SOC email monitoring catches lookalike-domain impersonation on disbursements; dual-approval SOP; verbal callback on bank-change request; trust-account EDR coverage.
TX Privacy TDPSA §541.101–§541.151 + §521.053 notification Sensitive-PI enumeration + 30-day consumer request workflow + §521.053 breach notification to TX AG. AG-facing notification template pre-loaded.
Defense-Adjacent CMMC 2.0 32 CFR Part 170 + DFARS 252.204-7012 72-hr + DFARS 252.204-7021 + NIST SP 800-171 Rev 2 (110 controls) — where CUI handled SSP authorship + SPRS documentation + C3PAO assessment readiness + DFARS 72-hr DIBNet disclosure workflow + SDVOSB co-prime advantage counts toward DFARS 252.219-7003.
Practical Gap Review

For Firms Without an Internal SOC: Find the Compliance Gaps.

Get a practical baseline of what needs attention across TX DR 1.05, ABA Rule 1.6(c), TDPSA, IOLTA safeguards, and applicable CMMC controls. We map the highest-impact gaps to concrete next steps your firm can review with its leadership, IT team, and outside providers.

Start the Law Firm Compliance-Gap Assessment →
FAQ — Texas Law Firms Ask

Answers before your next security review.

What cybersecurity responsibility does ABA Formal Opinion 483 place on a law firm?
Formal Opinion 483 treats cybersecurity as part of a lawyer’s duties of competence, confidentiality, and communication. A firm should use reasonable safeguards for privileged data, understand the technology it relies on, investigate incidents, and communicate with affected clients when required. The exact response depends on the facts, but a written, tested program is stronger than an undocumented promise of care.
What controls reduce IOLTA wire-fraud loss?
Use dual approval for disbursements and a verbal callback to a trusted, independently sourced number before changing payment instructions. Separate duties, protect email and practice-management accounts with MFA, train staff on invoice and bank-change impersonation, and document exceptions. These controls reduce the chance that a compromised mailbox can convert a convincing request into an unrecoverable trust-account transfer.
How does vendor or e-discovery liability affect a Texas law firm?
A vendor contract may limit the vendor’s damages, but the firm’s confidentiality and client-communication responsibilities do not automatically disappear when privileged data is hosted by a provider. Perform vendor diligence, review security attestations and contract terms, restrict access, and maintain an incident process that covers e-discovery, DMS, practice-management, and cloud vendors.
Why CoreRecon
24/7 Texas-based SOC
Attacker-minded posture
Experience in Law Firms
Contractual 30-minute response promise
Attorney-client privilege protection
Research Brief — August 2026

Privileged-Data Threat Brief for Texas Law Firms

See where privileged case files and IOLTA funds are exposed — and what ABA confidentiality obligations require next. The gated PDF includes named law-firm incidents, a TX DR 1.05 / ABA Rule 1.6(c) / TDPSA §541 / IOLTA regulatory crosswalk, IOLTA wire-fraud controls, 60+ sources, and a 30-60-90-day roadmap.

Get the Gated Brief →
SDVOSB Certified (VetCert + CVE-verified)
30-Min ABA 1.6(c) IR SLA
TX-Resident Case-Data-Aware SOC
USMC Veteran-Led
ABA Formal Opinion 483 SOP Delivery
Month-to-Month Contracts
Free TX Law Firm Case-Data + ABA Compliance Assessment — $2,500 Value

Privileged work product. Trust funds. Client PHI. Five regulatory tracks. Get the case-data + ABA baseline before the next privileged-file exfil forces an ABA 1.4 client notification.

We deliver an ABA-aware + TDPSA-aware + IOLTA-aware baseline review of your firm's privileged-work-product exposure: iManage/NetDocuments credential posture, Clio/MyCase practice-management coverage, trust-account disbursement SOP, vendor portal credential-stuffing surface, and the SDVOSB + CMMC 2.0 readiness (where defense-adjacent). No credit card. SDVOSB-certified. TX-resident analysts. 14-day delivery from contract start.

Free TX Law Firm Assessment — $2,500 Value →

Delivered within 14 days  •  SDVOSB-certified  •  Case-data-aware SOC  •  TX-resident analysts