Corporate clients increasingly attach security requirements to the work they send outside firms. Sometimes these appear in a questionnaire. Sometimes they sit in the outside counsel guidelines, or in an engagement agreement, as terms the firm has agreed to follow. Many firm administrators discover the details only when a client audit or an incident forces a close reading.
Understanding the typical categories helps you spot obligations early and decide whether you can meet them. The terms vary widely by client and industry, so treat the following as examples, and have counsel review actual documents.
Where These Terms Appear
- Outside counsel guidelines issued at the start of a relationship
- Master services agreements and engagement letters
- Data processing or business associate addendums in regulated industries
- Annual or event-driven security questionnaires
- Audit and assessment requests
Make a habit of routing all of these to one owner at the firm, and keeping a log of what each client requires.
Common Categories of Requirements
Access and authentication
Expect requirements for unique user accounts, multi-factor authentication, least-privilege access and prompt removal of departed users. Some clients ask for periodic access reviews.
Encryption
Encryption of data in transit and at rest is a frequent demand, including laptops, mobile devices, backups and email containing sensitive information. Clients may ask for secure file-transfer methods in place of ordinary email attachments.
Data location and handling
Some clients limit where data may be stored, restrict copying to personal devices, or prohibit use of certain cloud services. Rules on data return and destruction at the end of a matter are common.
Incident notification
This is among the most important terms. Clients commonly require notice within a defined time after discovering an incident that may affect their data. The window may be short. Make sure your incident plan can meet it and that someone knows how to contact the client's security team.
Subcontractors and vendors
Clients may require approval before the firm uses a vendor that will handle their data, flow-down of security terms to vendors, and a list of subprocessors. This ties to the supervision duties in Model Rule 5.3.
Security programs and policies
Written information security policies, regular risk assessments, security training and incident response plans are common asks. NIST Cybersecurity Framework 2.0 is a widely recognized structure that some clients reference.
Audit rights
Some agreements allow the client to audit or assess the firm's security, request independent reports or send detailed questionnaires. Know in advance what you are consenting to and how much staff time it would require.
Artificial intelligence
A growing number of guidelines address generative AI, such as prohibiting its use on the client's matters without consent or requiring disclosure. Capture these in your AI policy and in matter-opening checklists.
Insurance
Clients may require specific cyber and professional liability coverage levels. Coordinate with your broker.
A Process for Handling Them
- Review before accepting. Do not sign outside counsel guidelines without reviewing the security sections with IT and a partner.
- Build a requirements register. For each client, note key obligations, deadlines and the system or person responsible.
- Identify gaps. If a term requires something you cannot yet do, raise it, negotiate or plan to close the gap before you take the matter.
- Flag matters in your systems. If a client prohibits AI or requires restricted access, set a visible flag in practice management.
- Train the matter team. The people doing the work should know the special rules.
- Review annually. Terms change, and so do your systems.
Negotiating
Firms are sometimes able to negotiate terms that are unrealistic for their size, such as unreasonably short notice windows or requirements that mirror a large enterprise's security program. Reasonable alternatives and documented compensating controls are often accepted. Do not agree to what you cannot deliver.
Why Standardizing Helps
The more your security program follows a recognized baseline, the easier it becomes to answer these requirements consistently. A single set of policies, controls and evidence serves clients, insurers and your own risk management.
Counsel Cyber helps law firms map client security requirements to practical controls and prepare for client audits. If a client agreement has landed on your desk, we can help you read the technical parts and plan what is needed.