Florida Bar Rec 25-1: What Every Attorney Needs to Do Before March 2027

ArisGate Security Team

July 10, 2026

If you practice law in Florida, a compliance clock is already running, and most attorneys have not started it. Florida Bar Recommendation 25-1, working alongside your existing duty of confidentiality under Rule 4-1.6, sets clear expectations for how firms protect client data. Here is what it says and what to have in place before the milestones arrive.

What Recommendation 25-1 Actually Says

On March 28, 2025, the Florida Bar unanimously approved Recommendation 25-1, proposed by its Cybersecurity and Privacy Law Committee. It urges every Florida Bar member and their firm to complete a Data Mapping Survey and a Cybersecurity Maturity Assessment within two years, and to develop a formal Incident Response Plan within three years. Those timeframes point to March 2027 and March 2028.

Why Voluntary Does Not Mean Optional

The Recommendation is framed as guidance rather than a binding rule. But it is widely viewed as the emerging standard of care that judges, disciplinary committees, malpractice carriers, and cyber insurers will use to decide whether a firm made reasonable efforts to protect client data. Rule 4-1.6 already requires attorneys to make reasonable efforts to prevent the unauthorized disclosure of client information; Recommendation 25-1 describes what reasonable now looks like.

Your Pre-2027 Checklist

  1. Complete a data mapping survey, so you know what client data you hold, where it lives, and who can access it.
  2. Run a cybersecurity maturity assessment against a recognized framework to find your gaps.
  3. Put multi-factor authentication and identity controls on email, document storage, and practice-management systems.
  4. Deploy layered email and phishing defense beyond the defaults in Microsoft 365 or Google Workspace.
  5. Adopt a written information security policy and a documented incident response plan before the three-year mark.

Obligations You May Already Have

Many firms inherit their clients' regulatory duties. A firm defending healthcare providers may be a business associate under HIPAA. A firm serving banks or credit unions may fall under the Gramm-Leach-Bliley Act. Education-sector clients can bring FERPA into scope. And Florida's data-breach law, Section 501.171, already requires reasonable data security and breach notification for any business holding Floridians' personal information, including law firms of any size.

How ArisGate Helps

ArisGate is a cybersecurity-only managed security provider built specifically for solo and small Florida law firms of one to fifteen attorneys. Every plan is designed around Rule 4-1.6 and Recommendation 25-1: 24/7 human-led threat monitoring, identity protection, zero trust access, AI-aware email security, DNS filtering, patch management, and the documented policies and incident response plan the Bar expects. Pricing is flat and predictable, Shield at USD 139, Fortress at USD 199, and Vault at USD 279 per user per month, with a three-year price lock and no long-term contract.

The Bottom Line

The timeframes are set and the standard of care is clear. Firms that begin now will meet the milestones calmly and affordably. Firms that wait until 2027 will be negotiating under pressure, or after a breach. The time to act is before the incident, not after.

Schedule a Call