ABA Formal Opinion 477R (revised May 22, 2017, on securing client communications) lists steps lawyers should take, including: "Conduct due diligence on vendors providing communication technology. Take steps to ensure that any outside vendor's conduct comports with the professional obligations of the lawyer." The rules bind lawyers, not vendors, but they decide what a lawyer has to ask you.
ABA Formal Opinion 512 (July 29, 2024) is about generative AI, but it restates the vendor checks from the ABA's earlier outsourcing opinions: reference checks and vendor credentials; the vendor's security policies and protocols; its hiring practices; confidentiality agreements; its conflicts check system; and a legal forum for relief if the vendor breaks the agreement. Drawing on cloud computing opinions, it adds checks any software seller will hear: is the confidentiality obligation enforceable, will the lawyer be notified of a breach or of service of process seeking client information, does the tool keep information after the service ends or claim rights in it, and what limits the vendor puts on its liability. It notes lawyers may need IT or cybersecurity experts to read those terms, one reason firm IT joins the review.
ABA Formal Opinion 483 (October 17, 2018) covers what happens after a breach. Lawyers must notify clients when a breach involves, or has a substantial likelihood of involving, material client information, must make reasonable efforts to monitor external vendors that handle data, and should consider an incident response plan. A firm cannot meet those duties if its vendor tells it late, which is why breach notice clauses get negotiated hard. This is background for why firms ask, never a selling angle: do not approach a firm about its own incident.