A law firm signs an engagement letter or accepts a corporate client's outside counsel guidelines and moves on to the work. Buried in those documents, often in a section titled "information security" or "data handling," may be a list of commitments: encryption standards, breach notification deadlines, audit rights, restrictions on offshore access, requirements for background checks and more. Months later, when a questionnaire or audit arrives, the firm discovers it agreed to something it cannot demonstrate.
This post explains the types of terms to watch for and a practical way to keep track. It is general information and not legal advice; have counsel review specific contract language.
Where the terms appear
- Outside counsel guidelines or billing guidelines.
- Master services agreements and engagement letters.
- Data processing addenda or business associate agreements, where regulated data is involved.
- Standalone security exhibits or questionnaires.
- Annual attestation or certification requests.
Each may have different requirements for the same client, and later versions may supersede earlier ones.
Common clauses to look for
Breach notification timing
Some clients require notice within a stated number of days or hours of discovering an incident. Your own response plan has to be able to meet that deadline. A plan that can notify counsel and the insurer but cannot identify affected clients quickly will fall short.
Encryption and access controls
Requirements may reference encryption at rest and in transit, multi-factor authentication, role-based access and logging.
Data location and subcontractors
Clauses may restrict storage to certain countries, prohibit offshore support access or require approval before using new subprocessors, including cloud vendors and e-discovery providers.
Return and destruction of data
Clients often require return or secure deletion of their information at the end of an engagement. Backups and archived mail complicate that promise, so understand how your retention practices fit.
Audit and assessment rights
Some agreements allow the client to audit your security or send periodic questionnaires. Know how often, with what notice and at whose expense.
Insurance requirements
Clients may require a minimum amount of cyber coverage and ask for a certificate. Check that your policy matches what you promised.
Personnel requirements
Background checks, confidentiality agreements and security training for people who touch the client's data.
Keep a commitments register
The most useful tool is a simple spreadsheet or document with one row per client containing the security obligations that differ from your baseline.
- Client and matter type.
- Source document and date.
- Key requirements: notification window, encryption, location limits, deletion rules, audit rights, insurance minimums.
- Owner: who is responsible for compliance.
- Next review or attestation date.
- Evidence: where proof lives, such as training records or policy documents.
Review the register at intake, whenever a guideline is updated and at least annually.
Intake: stop the problem at the door
Before signing, someone with both legal and technical understanding should read the security terms. Ask three questions: Can we do this? Can we prove it? What does it cost? If the answer to the first is no, negotiate. Clients are often flexible when asked early and explicitly. Making promises you cannot keep is the worst outcome.
Common mistakes
- Accepting guidelines without anyone from IT seeing them.
- Answering questionnaires optimistically, then discovering the actual environment does not match.
- Forgetting that cloud and e-discovery vendors need to meet the same obligations.
- Treating each client's requirement as a one-off rather than raising the baseline for the whole firm.
A baseline works better than custom exceptions
Most clients ask for roughly the same things: MFA, encryption, training, backups, incident response, vendor oversight. A firm that meets a consistent, documented baseline can answer most questionnaires quickly and rarely needs special handling. Reserve exceptions for the genuinely unusual demands.
Link to your vendors
Model Rule 5.3 addresses supervision of nonlawyer assistance, and many client guidelines require flow-down terms. Maintain a vendor list showing what each vendor holds, where it is hosted and what contractual protections you have. When a client asks who has their data, you will have an answer.
Prepare evidence once
Assemble a standing evidence folder: security policy summary, training completion records, MFA and encryption screenshots or reports, backup test results, penetration or vulnerability scan summaries if you have them, insurance certificate, incident response plan outline. Reuse it for every request.
How Counsel Cyber can help
Counsel Cyber helps law firms review client security terms, build a commitments register and maintain a ready evidence package for questionnaires and audits. If you have a stack of guidelines you have never mapped to your environment, we can help.