A more dispersed and remote workforce is likely inhibiting just how far law firms' cybersecurity protections can reach nowadays. With more attorneys potentially exposed to heightened cyberrisk, a once-centralized security approach is giving way to one more focused on improving individual attorney's cyber hygiene. And at least one state bar association is moving to ensure its attorneys know how to adequately protect themselves.

Today, the New York State Bar Association (NYSBA) announced it approved a recommendation by its committee on technology and the legal profession to require New York attorneys to take at least one cybersecurity CLE credit. The proposal now goes to before the New York CLE board for consideration.

The proposed change, which would modify the New York State CLE board Regulations and Guidelines, mandates that one CLE credit hour under the "Ethics and Professionalism" category be devoted to cybersecurity every two years. The amendment, which does not add any additional credit hour requirements for new or practicing attorneys, would sunset after four years if not reenacted.

Scott Karson, president of the New York State Bar Association and partner at Melville, New York-based Lamb & Barnosky said the NYSBA's support of the amendment was driven in large part by the increase in attorneys working remotely around the state. "Now more than ever I think what most members of the House of Delegates believe, in this era where so many of us are working remotely from home, is the concern for cybersecurity is greater than ever."

He explained that at home, "you don't have the infrastructure you would have working in your law firm office or whatever your principle place of employment is."

In advocating for the amendment, a January 2020 report by the committee on technology and the legal profession also cited  the rising number of data breaches among New York Law firms, the need for attorneys to keep pace with more sophisticated cyberattacks, and attorneys ethical obligation to protect privileged client communications. It also noted that New York's recently enacted cybersecurity law, the SHIELD ACT, applies to local law firms, and therefore makes cybersecurity education even more imperative.

Still, not all in the NYSBA were on board with the proposed requirement. In response to the report, The NYBSA's local and state government law section argued that while "cybersecurity for law firms is of critical importance," there should not be a mandatory CLE requirement because most attorneys do not have control over their organization's security or choice of vendors. It also noted that while attorneys need to be educated about phishing attacks, the "first line of defense" against such efforts is email software deployed by the firm or organization.

Furthermore, the section argued that the mandatory credit will take time away from "section-specific ethical education" and could burden those offering CLE credits with finding outside cybersecurity expertrs to provide instruction.

Karson said that the section's arguments were "presented to the House of Delegates and considered and found not to carry the day, so to speak."

He also said the notion that cybersecurity is mainly the responsibility of the law firm or organization did not hold much weight. "I think the consensus was that all lawyers are ultimately responsible for the security of the systems for which they work. It really isn't a defense or excuse that you work for an employer who ultimately may have control over the system. You have an obligation to make sure the system is secure."

To be sure, even if the amendment is enacted by New York CLE board, it's long-term impact is far from assured. Karson stressed that after four years, "In absence of any affirmative action by the CLE board it would sunset and expire." Still, it has the support of NYSBA's president. "Personally I voted in favor of it," Karson said. "I just think that cybersecurity is important enough today that it requires special attention and therefore I'm comfortable with the fact that lawyers would be required to take a credit in cybersecurity."