Florida Bar Rec 25-1: What Every Attorney Needs to Do Before March 2027

ArisGate Security Team

•
July 10, 2026
ARISGATE SECURITY BRIEF · COMPLIANCE & REGULATORY
The compliance clock is running. Most attorneys haven't started it.
Here's exactly what Recommendation 25-1 requires before the March 2027 and March 2028 milestones.

What Recommendation 25-1 Says

On March 28, 2025, the Florida Bar unanimously approved Recommendation 25-1, urging every member firm to complete a Data Mapping Survey and Cybersecurity Maturity Assessment within two years, and a formal Incident Response Plan within three, pointing to March 2027 and March 2028.

Why Voluntary Does Not Mean Optional

It is framed as guidance, but it is widely viewed as the emerging standard of care that judges, malpractice carriers, and cyber insurers will use to judge reasonable efforts under Rule 4-1.6.

Your Pre-2027 Checklist

  1. Complete a data mapping survey.
  2. Run a cybersecurity maturity assessment.
  3. Add multi-factor authentication and identity controls across email, storage, and practice management.
  4. Deploy layered email and phishing defense beyond default protections.
  5. Adopt a written information security policy and incident response plan.

Obligations You May Already Have

Firms serving healthcare, banking, or education clients can inherit HIPAA, Gramm-Leach-Bliley, or FERPA duties, and Florida's Section 501.171 already requires reasonable data security for any business holding Floridians' personal information.

How ArisGate Helps

Every plan is built around Rule 4-1.6 and Recommendation 25-1: monitoring, identity protection, email security, and the documented plans the Bar expects. Shield at USD 139, Fortress at USD 199, Vault at USD 279 per user per month, three-year price lock, no long-term contract.

The Bottom Line

Firms that start now meet the milestones calmly. Firms that wait will be negotiating under pressure, or after a breach.

Schedule a Call