Cybersecurity Compliance for San Antonio Law Firms: What the Texas Bar Expects

San Antonio law firms answer to the Texas Disciplinary Rules of Professional Conduct, not to a local bar association. You’ll find the practical expectations in a handful of State Bar ethics opinions on email, metadata, cloud storage and generative AI, plus the technology competence comment Texas added to Rule 1.01 in 2019. An average Bexar County law office has 6.7 people, and the duty doesn’t shrink with headcount. For day-to-day support, see our IT services for San Antonio law firms.

Cybersecurity compliance for San Antonio law firms means meeting the Texas Disciplinary Rules and the State Bar ethics opinions that interpret them. The San Antonio Bar Association is voluntary and sets no security rules. In practice, the bar expects reasonable safeguards on email, cloud files, vendors and AI tools.

I’m the CTO at Uprite. When a San Antonio firm asks us to make it compliant, my first question is always the same. Compliant with what?

Usually nobody’s sure. It shows up on a malpractice renewal form, in a corporate client’s security questionnaire or from a CLE speaker. Each source is real. None of them is the bar.

So I went back to the source documents. Rules. Opinions. Statutes. Texas never wrote a single cybersecurity rule for lawyers, and instead it spread the expectations across a comment to Rule 1.01, a handful of ethics opinions issued between 2006 and 2025, and a breach statute that covers every business in the state. You assemble it yourself. This post does that for a San Antonio firm and maps each expectation to the IT control that satisfies it.

Who actually sets cybersecurity rules for San Antonio lawyers?

Cybersecurity compliance for a Texas law firm is the set of safeguards a lawyer keeps so client information isn’t revealed, altered or lost. That duty comes from the Texas Disciplinary Rules of Professional Conduct, which the Supreme Court of Texas adopts, and the State Bar’s Professional Ethics Committee explains how it applies to technology.

The San Antonio Bar Association isn’t part of that chain. It describes itself as the largest volunteer bar association in San Antonio, founded in 1898, and it runs a Technology Section and a busy CLE calendar. It doesn’t license lawyers. It doesn’t discipline them. And as of September 2026 I couldn’t find a security standard anywhere on its site.

The State Bar is different. Every lawyer licensed here is a member by law under Government Code Section 81.051, and grievances run through the Chief Disciplinary Counsel. Its Professional Ethics Committee writes the opinions this post leans on. One catch. Section 81.092(c) says committee opinions aren’t binding on the Supreme Court. They’re advisory.

Advisory doesn’t mean optional, though. If a grievance or a malpractice claim ever turns on whether a lawyer took reasonable precautions with client data, those opinions are the most specific written Texas guidance on what reasonable looks like. I’d build to them.

Here’s how the layers stack up.

SourceBinding on a San Antonio firm?What it expects on security
Texas Disciplinary Rules of Professional ConductYes, enforced through the grievance processCompetence with relevant technology, confidentiality of all client information, supervision of staff and vendors
State Bar Professional Ethics Committee opinionsAdvisory under Gov’t Code 81.092(c)Specific precautions for email, metadata, cloud storage, vendors and AI
Texas Business and Commerce Code Chapter 521Yes, for every business in TexasReasonable procedures to protect sensitive personal information, plus breach notice deadlines
SB 2610, effective September 1, 2025Optional safe harborA cybersecurity program sized by headcount, in exchange for a defense against exemplary damages
Client outside counsel guidelines and cyber insuranceBy contractWhatever the contract or policy says, often MFA, encryption and prompt incident notice
San Antonio Bar AssociationNoNetworking, CLE and practice sections

One more gap worth knowing about. Texas requires 15 hours of CLE a year, 3 of them in ethics, and none in technology or cybersecurity. New York has required 1 hour of cybersecurity, privacy and data protection training per 2-year cycle since July 2023. Florida went first, requiring 3 technology hours per 3-year cycle starting in 2017. A Texas lawyer can practice for decades without a formal hour on any of this. Plenty do.

What do the Texas Disciplinary Rules say about data security?

Of the rules, 3 do most of the work. A fourth shows up the day a wire goes missing.

Rule 1.01 and technology competence

On February 26, 2019, the Supreme Court of Texas amended comment 8 to Rule 1.01 so that a lawyer’s competence now covers “the benefits and risks associated with relevant technology.” One sentence, in a comment. Everything else in this post hangs off it, because a lawyer who doesn’t understand the risks of the tools holding client files can’t take reasonable precautions with them. That’s the anchor.

Rule 1.05 and the sentence Texas never adopted

Texas Rule 1.05 defines confidential information broadly. It covers privileged information and all information relating to a client that a lawyer picks up during or because of the representation. That’s nearly everything in your document management system. Billing notes included.

What the Texas rule doesn’t have is the sentence in ABA Model Rule 1.6(c) telling lawyers to “make reasonable efforts to prevent the inadvertent or unauthorized disclosure” of client information. Paragraph (b) of the Texas rule bars knowingly revealing confidential information, which is a different thing from failing to lock the door. Plenty of cybersecurity content written for Texas firms quotes 1.6(c) anyway. It’s persuasive here. It isn’t the rule.

So in Texas the duty to safeguard arrives through competence, and through ethics opinions that keep repeating the phrase “reasonable precautions.” Same destination, mostly. Different citation, though, and when you’re answering a client questionnaire or a grievance, the citation matters.

Rule 5.03 and your IT provider

Rule 5.03 requires a supervising lawyer to make “reasonable efforts to ensure” that a nonlawyer’s conduct fits the lawyer’s own obligations, and it reaches nonlawyers “employed or retained by or associated with” the lawyer. Retained is the word that pulls in outside vendors. That’s my reading. I think it’s the natural one, but the rule never names IT providers.

An older opinion got there first anyway. Opinion 572, from June 2006, let lawyers hand privileged material to an independent contractor like a copy service if the lawyer “reasonably expects that the confidential character of the information will be respected.” Now swap the copy service for a managed IT provider holding admin rights to every mailbox in the firm. That’s a lot of trust. Your vendor contract should say something about confidentiality. If you’re reviewing one now, our MSP contract guide for Texas buyers walks through the rest of the agreement.

IT technician checking the firewall and patch panel in a small law office network closet

Rule 1.15 and the trust account

Safekeeping of client property now sits in Rule 1.15 after the 2024 renumbering. It isn’t a technology rule. But a spoofed email that reroutes a settlement disbursement out of the trust account lands right on it, and business email compromise cost victims about $3.05 billion across 24,768 complaints in the FBI’s 2025 Internet Crime Report. Verify every change to wiring instructions by phone, using a number you already had on file. Every single time.

Which Texas ethics opinions cover email, cloud storage and AI?

Nearly all of the committee’s technology guidance sits in 5 opinions. I’ve lined them up with the control I’d use to meet each one, because the opinions describe outcomes and leave the tooling to you. That part is our job.

OpinionIssuedQuestionWhat the committee expectsControl that meets it
572June 2006Can client files go to outside vendors?Yes, if the lawyer reasonably expects the vendor to keep them confidentialConfidentiality terms in every IT and software contract
648April 2015Can a lawyer email confidential information?Generally yes, but some situations call for warning the client and considering encrypted email or another channelMessage encryption on demand and a client portal for sensitive files
665December 2016What about hidden metadata in documents?Reasonable measures, including available technical means, to strip it before documents leave the firmMetadata cleaning on outbound attachments
680September 2018Can client files live in the cloud?Yes, with reasonable precautions such as reading the terms of service, checking built-in security and training staffA vendor file for each cloud app, MFA and yearly training
705February 2025Can lawyers use generative AI?Learn the tool first, protect confidential information, verify every output and don’t bill for time savedA written AI use policy and an approved tool list

Opinion 648 on email

Opinion 648 is the one I quote most. It’s specific. It says lawyers may generally email confidential information, then names 6 situations where a lawyer may need to warn the client and consider encrypted email or another way to communicate. These 5 matter most here.

  • Sending highly sensitive information by email or over unencrypted connections
  • Emailing to or from an account the sender or recipient shares with other people
  • Writing to a client when a third person, such as a spouse in a divorce, may know the password
  • Sending from a public or borrowed computer
  • Emailing a client who reads messages on devices other people can reach

The sixth is government surveillance, which reads a little differently now than it did in 2015. If you practice family law, look at the third item again. It describes a lot of your clients. Shared family iPads. Old passwords.

My practical answer is encryption that’s ready before you need it, plus a portal for anything you’d rather not email at all. A firm on Microsoft 365 Business Premium already has message encryption in its license. It just has to be switched on and taught.

Opinion 665 on metadata

Opinion 665, from December 2016, is the quiet one. It requires the sending lawyer to take reasonable measures, including “reasonably available technical means,” to remove confidential metadata before documents go to anyone other than the client. Tracked changes in a draft settlement agreement are the classic leak. Comments too. On the receiving side, the Texas rules don’t prescribe a course of action, but a lawyer can’t use what the metadata reveals in a misleading or fraudulent way.

Opinion 680 on cloud storage

Opinion 680 says lawyers can keep client files in the cloud but “must remain alert to the possibility of data breaches, unauthorized access, or disclosure.” The precautions it lists read like a vendor review checklist. Understand how the service works. Read its terms of service. Check its built-in security. Decide whether you need more, including encryption. Watch for news that the provider is deficient. Train your people.

Then comes the line I wish more firms had read before they migrated. The precautions “do not require lawyers to become experts in technology,” but they do require lawyers to stay vigilant about data security “from the outset.” From the outset means before the move to NetDocuments, Clio or SharePoint, not after the first incident. Order matters.

Opinion 705 on generative AI

Opinion 705 came out in February 2025 at the request of the State Bar’s Taskforce on Responsible AI in the Law. Its confidentiality line is blunt. If a lawyer isn’t reasonably satisfied that an AI program won’t reveal client information, the lawyer shouldn’t enter confidential information “without client consultation and consent.” Read that twice. It also says lawyers shouldn’t bill clients for time the tool saved. Few people notice that part.

On the IT side, 705 comes down to an approved tool list and a written policy. A free consumer chatbot and an enterprise AI tenant with data protection terms are different products, even when the chat box looks identical. We wrote an AI acceptable use policy guide for Texas businesses that a firm can adapt in an afternoon.

What does the bar expect from a 7-person San Antonio law office?

I pulled county data from the Bureau of Labor Statistics to see what a typical San Antonio firm actually looks like. In 2025, the Quarterly Census of Employment and Wages counted 1,072 offices of lawyers in Bexar County with 7,180 people on payroll. That’s 6.7 per office.

CountyOffices of lawyersEmployeesAverage per officeAverage annual pay
Bexar (San Antonio)1,0727,1806.7$113,260
Harris (Houston)3,18527,4948.6$163,712
Dallas2,18820,4569.3$176,832
Tarrant (Fort Worth)8544,5925.4$122,161
Texas statewide15,79895,2656.0$143,163

Figures are 2025 annual averages for private-sector offices of lawyers, NAICS 54111, from the BLS Quarterly Census of Employment and Wages.

Small shops, mostly. San Antonio firms run smaller than Houston’s or Dallas’s. They’re also growing, with law office employment in Bexar up 3.7% from 2024 to 2025. More people means more mailboxes, more laptops and more logins to protect.

Now add SB 2610. It took effect September 1, 2025, and it gives a Texas business with fewer than 250 employees an affirmative defense against exemplary damages after a breach, as long as it kept a cybersecurity program that meets the bill’s requirements. Those requirements scale with headcount. Under 20 employees, the bill asks for “simplified requirements, including password policies and appropriate employee cybersecurity training,” although every tier still has to follow a recognized framework such as the CIS Controls or the NIST Cybersecurity Framework. Nearly every law office in Bexar County sits in that bottom tier. Our SB 2610 compliance guide covers the tiers in full.

One statute most San Antonio firms can set aside is the Texas Data Privacy and Security Act. It exempts small businesses as the SBA defines them, and for offices of lawyers the SBA line is $15.5 million in annual receipts. There’s no attorney exemption above that line, so a larger firm should read our Texas data privacy law guide.

The ethics opinions have no tiers at all. Opinion 648’s divorce scenario applies to a solo exactly as it applies to a 300-lawyer firm, and Opinion 680 asks the same vendor questions whether you run 3 cloud apps or 30. That’s the gap I’d want every San Antonio managing partner to see. The statute sets a low floor for a 7-person office. The bar doesn’t. Build to the bar.

Small doesn’t mean ignored, either. FBI data says so. Its 2025 Internet Crime Report broke out ransomware complaints from businesses outside the 16 critical infrastructure sectors, and legal services came first at 18%. In May 2025 the FBI also warned that a crew it calls Silent Ransom Group has consistently targeted US law firms since spring 2023. We covered the local angle in why San Antonio businesses are ransomware targets.

What happens after a data breach at a Texas law firm?

Two duties start at once. One comes from state law and applies to any business. Your duties to clients supply the other. Both matter.

On the statute side, Business and Commerce Code Section 521.053 requires notice to affected individuals without unreasonable delay and no later than 60 days after you determine the breach happened. If it involves at least 250 Texans, the Attorney General has to hear within 30 days through an online form, a deadline SB 768 cut from 60 days in 2023. Section 521.052 separately requires reasonable procedures to protect sensitive personal information in the first place. Client files are full of it. Driver’s license numbers in a DWI file, account numbers in a probate file, medical records in a personal injury file.

On the ethics side, I couldn’t find a Texas opinion on breach response. The closest guidance is ABA Formal Opinion 483 from October 2018, which says lawyers have a duty to notify clients when a breach involves, or has a substantial likelihood of involving, material client information. Persuasive, not binding. Texas Rule 1.03 already requires keeping a client reasonably informed about the matter, and I’d treat a breach of that client’s own file as part of the matter.

Nobody in this system is immune, including the regulator. The State Bar of Texas said an intruder was inside its network from January 28 to February 9, 2025 and took certain information, and the INC Ransom gang claimed the attack, BleepingComputer reported. Back in May 2020, a ransomware attack forced the Office of Court Administration to take the Texas judicial branch network offline. If those two can get hit, so can a 7-person office near the Bexar County Courthouse.

Readiness is thin, too. The ABA’s 2023 Cybersecurity TechReport found 29% of respondents said their firm had been breached, while only 34% had an incident response plan. At firms of 2 to 9 lawyers, the plan rate was 19%. That’s roughly 1 in 5.

Here are the clocks.

What happenedDeadlineWhere it comes from
You find out privileged documents were produced by mistakeAmend your discovery response within 10 days of actually discovering it to keep the privilegeTexas Rule of Civil Procedure 193.3(d)
You determine a breach of sensitive personal information happenedNotify affected individuals without unreasonable delay, and within 60 daysBus. and Com. Code 521.053
The breach involves 250 or more TexansNotify the Texas Attorney General within 30 days through its online formBus. and Com. Code 521.053
You file anything with a Texas courtRedact sensitive data such as Social Security, driver’s license and bank account numbers before filingTexas Rule of Civil Procedure 21c
Your cyber policy’s notice clause is triggeredWhatever the policy says, so read it nowYour insurance policy

That 10-day window is easy to miss. People miss it. Texas Rule of Evidence 511(b) says an inadvertent disclosure in a Texas proceeding doesn’t waive privilege if the holder followed Rule 193.3(d), so the clock starts when someone at the firm notices the mistake. Your document management system’s audit log is often how they notice.

Which security controls satisfy the bar, your clients and your insurer?

Here’s the short list I’d put in front of a San Antonio managing partner. Every item traces back to a rule, an opinion or a statute above. That tracing is what turns a security purchase into evidence of reasonable precautions. Your cyber insurer will ask about most of it too, and the answers carry weight. In 2022 Travelers asked a court to rescind a policy after a breach, arguing the insured had only used MFA to protect its firewall despite what its application said.

Hand pressing a hardware security key plugged into a laptop, a phishing-resistant second factor for law firm sign-ins
  • Multifactor authentication on Microsoft 365, the document management system and remote access, with hardware security keys for partners and anyone who can move trust account money
  • Full-disk encryption on every laptop, and message encryption ready for the Opinion 648 situations
  • Metadata cleaning on outbound documents, per Opinion 665
  • A vendor file for each cloud service and for your IT provider, holding the terms of service, security documentation and a confidentiality clause, which covers Opinions 572 and 680 and Rule 5.03 in one folder
  • Backups with an offline or immutable copy, restored on a schedule so you know they work
  • A callback rule for any change to wiring instructions
  • An AI use policy and an approved tool list, per Opinion 705
  • Security training for lawyers and staff at least once a year, which Opinion 680 names and SB 2610’s smallest tier requires
  • A written incident response plan with your Section 521.053 notice steps, your carrier’s claims number and your breach counsel’s phone number

Most of that is configuration, not new software. A firm on Microsoft 365 Business Premium already owns the tools for conditional access, device encryption and message encryption. What usually isn’t there is the paperwork. That’s the real gap. For firms that want the whole list run for them, our cybersecurity services in San Antonio cover the monitoring, response and backup side.

How do you prove your precautions were reasonable?

Reasonable gets decided after something goes wrong, by someone who wasn’t in the room. A grievance panel. A claims adjuster. A client’s general counsel. They’ll ask what you knew and what you did about it, and the honest answer has to exist on paper dated before the incident. Memory won’t count.

I’d keep 6 documents current.

  • An inventory of every system that holds client data, including the ones a partner signed up for with a credit card
  • The vendor file described above
  • Your written security policies, AI policy included
  • Training records with names and dates
  • Backup restore test results
  • The incident response plan, reviewed within the last 12 months

None of this is glamorous. It’s also the difference between “we thought we were fine” and a folder you can send when a corporate client’s outside counsel guidelines ask how you protect their data. That client contract is its own layer, and it often sets a higher bar than any regulator. Our legal and professional services page covers it.

Four members of a small law firm meeting around a round table to plan the firm security program

How Uprite helps San Antonio law firms

We’re a managed IT and cybersecurity provider, so weigh this section accordingly. If your firm has an in-house IT director who already keeps the vendor file, the policies and the restore tests, you probably don’t need us for this. A second set of eyes once a year is plenty.

For everyone else, the work starts with an assessment. It isn’t complicated. We check the controls above against your actual systems, tie each gap to the rule or opinion behind it, and hand you a written list in priority order. It’s the same review we run in our compliance and regulatory assessment, pointed at the Texas Disciplinary Rules instead of HIPAA or CMMC.

Want to know where your firm stands against Opinions 648, 680 and 705? We’ll review your email, cloud apps, vendors and backups, then give you a written gap list tied to the rule behind each item.

Get a Law Firm Security Assessment

What San Antonio lawyers ask about cybersecurity compliance

Does the San Antonio Bar Association have cybersecurity requirements?

No. The San Antonio Bar Association is a voluntary association founded in 1898, and it does not license or discipline lawyers. Security expectations for San Antonio firms come from the Texas Disciplinary Rules of Professional Conduct and the State Bar ethics opinions that interpret them.

Do Texas lawyers have to encrypt email?

Not always. Opinion 648 says lawyers may generally email confidential information, but some situations call for warning the client and considering encrypted email or another channel, such as highly sensitive information, shared accounts, or a spouse who may know the password.

Can a Texas law firm store client files in the cloud?

Yes, with reasonable precautions. Opinion 680 from September 2018 allows cloud storage when the lawyer understands how the service works, reads the terms of service, checks its security, considers encryption, watches for problems with the provider, and trains staff.

Is there a cybersecurity CLE requirement for Texas lawyers?

There is none as of September 2026. Texas requires 15 hours of CLE a year, 3 of them in ethics, and none in technology.

Can lawyers put client information into ChatGPT or other AI tools?

Only with care, and sometimes only with consent. Opinion 705 from February 2025 says a lawyer who is not reasonably satisfied that an AI tool will protect confidential information should not enter it without client consultation and consent. It also asks lawyers to verify every output and not to bill clients for time the tool saved.

Does SB 2610 protect a small law firm after a data breach?

Partly. SB 2610 lets a Texas business with fewer than 250 employees avoid exemplary damages after a breach if it kept a qualifying cybersecurity program. It does not block claims for actual damages, and it has no effect on a grievance under the disciplinary rules.

Who must a Texas law firm notify after a data breach?

Affected individuals come first, within 60 days of determining the breach, under Business and Commerce Code Section 521.053. The Texas Attorney General must also hear within 30 days if 250 or more Texans are affected, and ABA Formal Opinion 483 adds a duty to tell clients whose material information was involved.

About Author

Learn More