If you practice law in Florida, a compliance clock is already running, and most attorneys have not started it. Florida Bar Recommendation 25-1, working alongside your existing duty of confidentiality under Rule 4-1.6, sets clear expectations for how firms protect client data. Here is what it says and what to have in place before the milestones arrive.
On March 28, 2025, the Florida Bar unanimously approved Recommendation 25-1, proposed by its Cybersecurity and Privacy Law Committee. It urges every Florida Bar member and their firm to complete a Data Mapping Survey and a Cybersecurity Maturity Assessment within two years, and to develop a formal Incident Response Plan within three years. Those timeframes point to March 2027 and March 2028.
The Recommendation is framed as guidance rather than a binding rule. But it is widely viewed as the emerging standard of care that judges, disciplinary committees, malpractice carriers, and cyber insurers will use to decide whether a firm made reasonable efforts to protect client data. Rule 4-1.6 already requires attorneys to make reasonable efforts to prevent the unauthorized disclosure of client information; Recommendation 25-1 describes what reasonable now looks like.
Many firms inherit their clients' regulatory duties. A firm defending healthcare providers may be a business associate under HIPAA. A firm serving banks or credit unions may fall under the Gramm-Leach-Bliley Act. Education-sector clients can bring FERPA into scope. And Florida's data-breach law, Section 501.171, already requires reasonable data security and breach notification for any business holding Floridians' personal information, including law firms of any size.
ArisGate is a cybersecurity-only managed security provider built specifically for solo and small Florida law firms of one to fifteen attorneys. Every plan is designed around Rule 4-1.6 and Recommendation 25-1: 24/7 human-led threat monitoring, identity protection, zero trust access, AI-aware email security, DNS filtering, patch management, and the documented policies and incident response plan the Bar expects. Pricing is flat and predictable, Shield at USD 139, Fortress at USD 199, and Vault at USD 279 per user per month, with a three-year price lock and no long-term contract.
The timeframes are set and the standard of care is clear. Firms that begin now will meet the milestones calmly and affordably. Firms that wait until 2027 will be negotiating under pressure, or after a breach. The time to act is before the incident, not after.