Client files shared by link
Discovery goes out through a personal Dropbox account or a plain Google Drive link because it was fast. Once that link gets forwarded, the firm has no say over who opens the documents.
Client files end up in email, the practice management system, a document store, and whichever laptop went to the courthouse this morning. Your duty of confidentiality goes with them. We run the IT behind all of it, from the help desk to the backups, for one monthly fee.
Managed IT services for a law firm cover the firm's whole IT operation: help desk, device and server management, security, backup, and vendor coordination. An outside team does the work, so the firm doesn't have to hire IT staff. For a Texas firm, that work should also line up with Rule 1.05 on confidentiality, the Texas ethics opinions on email, cloud storage, and AI, and the state's data breach law.
The same handful of gaps turn up at nearly every firm we walk into. Each one started as a reasonable shortcut on a busy day.
Discovery goes out through a personal Dropbox account or a plain Google Drive link because it was fast. Once that link gets forwarded, the firm has no say over who opens the documents.
A paralegal leaves in March and still has a working login in August. We find old accounts in email, in the practice management system, and in the conflicts database, which holds every client and opposing party the firm has ever had.
A new client hires you to collect a debt. The "debtor" pays right away with a cashier's check, and the client asks you to wire the money on. The check is counterfeit and the trust account takes the loss. The FBI warned in October 2024 that this scam targets law firms through fake debt collection matters. How the scam runs →
In May 2025 the FBI warned that a group it calls the Silent Ransom Group has consistently targeted U.S. law firms. A caller claims to be from the firm's IT department and asks for a remote session. A May 2026 alert says that if the call fails, the group sends someone to the office in person. That is much harder to pull off when your people know who their IT team is.
Someone on staff pastes a client's facts into a free AI tool to save an hour. Texas Ethics Opinion 705 doesn't prohibit generative AI. It does say the lawyer should make sure the tool doesn't put confidential client information at risk.
Most firms have backups. Far fewer have restored a full matter from one, so nobody knows how long recovery takes. Firms tend to find out the week of a deadline.
Sources: ABA 2023 Cybersecurity TechReport (the survey asked whether a firm had ever experienced a security breach). FBI IC3 2024 Texas report. Texas Attorney General, data breach reporting.
One team answers for the help desk, the devices, the security tools, the backups, and the software vendors. You don't hire IT staff, and your office manager goes back to managing the office.
24/7 monitoring, unlimited help desk, hardware lifecycle management, and remote or on-site support, with a 15-minute engineer-response guarantee in writing.
We support the IT under Clio, MyCase, Smokeball, and your document management system. When one of them breaks, we are the ones on the phone with the vendor.
Every device is encrypted and every account has multi-factor authentication. Access is set by role, so people see the matters they work on. When someone leaves, their accounts close that day.
Automated, encrypted backups of your matter files, email, and practice data. We test the restores on a schedule, so the recovery time you'd tell a client is the recovery time you'd get. How our backup works →
Attorneys work from the courthouse, from home, and from the road. Remote access gets the same sign-in protection as the office, and firm laptops are encrypted in case one gets left in a car.
We apply your written retention schedule inside your systems and help preserve data when a litigation hold lands. Before a device is reused or recycled, we wipe it and keep the record.
The disciplinary rules never name a firewall or a backup product. They set duties, and the Professional Ethics Committee's opinions explain how those duties apply to email, the cloud, and AI. State statutes add data protection and breach notice requirements on top.
A lawyer shall not knowingly reveal a client's confidential information, and that covers unprivileged client information too. The rule text doesn't mention technology. The opinions below are where it meets email and the cloud.
Read Rule 1.05 ↗Since 2019 the comment has said each lawyer should strive to stay competent in the practice of law, "including the benefits and risks associated with relevant technology." In our view, that starts with knowing where client data sits and who can reach it.
Read Rule 1.01 ↗A lawyer may generally send confidential information by email. In some circumstances the lawyer may need to advise the client of the risks and consider encrypted email or another channel. We set up encrypted email so it is there when a matter calls for it.
Read Opinion 648 ↗Lawyers must take reasonable measures to avoid sending confidential information hidden in a document's metadata, and the opinion counts available removal tools among those measures. We set up those tools on firm computers.
Read Opinion 665 ↗Cloud systems are allowed for client data when the lawyer takes reasonable precautions. The opinion's list includes understanding the technology, reading the terms of service, checking the provider's protections, and training lawyers and staff. We run that review with you before you sign.
Read Opinion 680 ↗The opinion doesn't prohibit generative AI. It says a lawyer should understand the tool before using it, make sure it doesn't put confidential client information at risk, and verify what it produces. Our Managed AI service gives the firm a governed workspace to use in place of free public tools.
Read Opinion 705 ↗A business in Texas has to keep reasonable procedures to protect sensitive personal information. That means a name combined with an unencrypted Social Security number, driver's license number, or financial account number, and it also means health information. Customer records holding that data must be shredded, erased, or made unreadable once the business stops keeping them.
Read Chapter 521 ↗After a breach of computerized data, the people affected must be told without unreasonable delay and, with limited exceptions, no later than 60 days after the breach is determined. When 250 or more Texans are affected, the Attorney General must be told within 30 days. Those reports are public, and Texas law firms are on the list.
Attorney General reporting page ↗Since September 1, 2025, a business with fewer than 250 employees that can show it had a qualifying cybersecurity program when a breach happened is protected from exemplary damages in a suit over it. Other liability and the notice duties stay. For a firm with under 20 employees the statute calls for simplified requirements, including password policies and employee security training. From 20 to 99 employees it calls for moderate requirements, including CIS Controls Implementation Group 1.
Read Chapter 542 ↗safemode IT is an IT provider and does not give legal or ethics advice. Ethics opinions come from the Professional Ethics Committee for the State Bar of Texas and are advisory. These summaries reflect the published rules, opinions, and statutes as of October 2026. For the longer version, read Texas law firm IT compliance.
Cyber insurance applications ask about the controls that protect client files: multi-factor authentication, tested backups, endpoint protection, staff training. The same work answers the application and protects the files.
Attackers try the same places first at a law firm: email, sign-ins, laptops, and the file store.
These are the everyday controls: who can open a matter, how documents leave the firm, and what happens to the data when a matter closes or an employee leaves.
Coverage follows your plan. See what safemode Shield and safemode Fortress include →
safemode IT has served Central Texas since 2006, and we work with law firms across the region. A filing deadline doesn't move because a server went down. A client's file is the one thing a firm can't buy again.
You get the same Kyle-based team every time you call. We bill flat-rate on a 36-month agreement, so the invoice matches the number you planned for. We support law firms in Kyle, San Marcos, Austin, Bastrop, and Lockhart.
Book a 10-Minute Discovery Call →Where Rule 1.05 and the Texas ethics opinions land in practice: vendor vetting, client portals, conflict databases, retention, and AI.
Read the post → FraudFake clients, counterfeit checks, and a wire request that drains the trust account. What to watch for and how to protect the firm.
Read the post →Managed IT services for a law firm cover the firm's whole IT operation: help desk, device and server management, security, backup, and vendor coordination. An outside team does the work, so the firm doesn't have to hire IT staff. safemode IT does this for law firms in Kyle, San Marcos, Austin, Bastrop, and Lockhart, with a 15-minute response guarantee and tested backups for one flat monthly fee.
We guarantee a 15-minute response time on support requests. An engineer is working your issue within fifteen minutes, and that's in writing in every managed IT services agreement.
Call 512-761-7652. During office hours a person answers, and after hours the same number reaches the on-call engineer. An engineer is working the problem within 15 minutes. Rule of Civil Procedure 21(f) requires attorneys to e-file in courts where e-filing is mandated, and that covers civil cases in the district and county courts. A filing-day outage can't wait until morning.
Yes. We support the IT those platforms run on, including workstations, networking, sign-in security, and backup, and we deal with the vendor directly on application problems. If your firm runs a different practice management or document system, we learn it.
Ethics Opinion 648 does not require it. The opinion says a lawyer may generally send confidential information by email. It also says some circumstances may call for advising the client of the risks and considering encrypted email or another channel. We set up encrypted email so the choice is yours on each matter.
Opinion 680 allows cloud storage when the lawyer takes reasonable precautions. We recommend a business or enterprise tier with the data protection terms in place. The consumer versions don't come with them. From there we turn on multi-factor authentication, configure retention policies, and shut off a former employee's access on their last day.
Opinion 705 (February 2025) addresses generative AI and doesn't prohibit it. It says the lawyer should understand the tool, keep it from exposing confidential client information, and verify the output. We'd keep client information out of free public tools. Our Managed AI service gives the firm a governed workspace with access controls and an audit trail.
We close their accounts the day they leave: email, practice management, document storage, remote access. Before that we preserve the mailbox and files for the firm. Ethics Opinion 684 says a departing lawyer may not delete client files from the firm's systems without the firm's approval, and the safest way to hold that line is a copy the departing lawyer can't touch.
The Texas disciplinary rules set no fixed period for closed client files, though other law or a client agreement can. Ethics Opinion 627 covers when they may be destroyed. Records of client funds and property are different: Rule 1.15(a) requires them to be kept for five years after the representation ends. Whatever schedule the firm adopts, we apply it in the systems and document the destruction.
Mostly with email security. Impersonation filtering catches look-alike senders, and multi-factor authentication keeps a mailbox from being taken over quietly. The State Bar of Texas said in September 2025 that several Texas attorneys had been targeted by wire transfer fraud. One attempt came close to $10 million through a look-alike email address. Technology catches a lot of it. A phone call to a number you already had catches the rest.
Yes. We implement the controls carriers ask about, including multi-factor authentication, EDR, tested backups, and documented policies. We also complete the attestation questionnaire with you so the answers hold up if a claim is ever reviewed. More on cyber insurance →
Yes. Co-managed IT leaves your person in charge of what they know best. We add after-hours coverage, 24/7 monitoring, and the security work most one-person IT departments don't have time for.
No. Every client is on the same flat-rate model: one monthly number per device on a 36-month agreement. The two plans are safemode Shield and safemode Fortress. Compare the plans →
Reviewed by the safemode IT team. Last updated October 10, 2026. safemode IT is an IT provider and does not give legal or ethics advice.
Start with a 10-minute call. Tell us what's going on with your IT and we'll tell you straight whether we can help. No pressure, no obligation.
By phone or Teams, on your schedule. If we're a fit, we'll plan the next step together.
Book a 10-Minute Discovery Call →