Outside counsel guidelines are the standing terms a corporate legal department requires every law firm it retains to follow. They started as billing and staffing rules and now carry binding information security requirements, usually incorporated by reference into each engagement.
What Outside Counsel Guidelines Are and Why the Security Section Grew

A firm rarely negotiates these terms matter by matter. They sit in a master document, they apply to every engagement the client sends, and they are updated on the client's schedule rather than the firm's. That is what makes the security section different from every other security conversation a firm has: it is not a questionnaire you answer once, it is an ongoing obligation that follows the relationship for as long as the client keeps sending work.
The Difference Between a Questionnaire and a Guideline
A security questionnaire is a snapshot. You answer it, the client scores it, and the result is a point-in-time picture of your controls. Outside counsel guidelines are the contract that follows the questionnaire. They carry attestation clauses that you must sign again each year, audit rights that let the client or its assessor look at your systems, breach duties with a clock attached, and consequences that range from remediation plans to removal from the client's panel.
The practical consequence is that a guideline is a promise about the future, not a description of the present. A firm that answers a questionnaire honestly with a few "not yet" responses is in a very different position from a firm that signs a guideline promising a control it does not have. The first is a gap to close, while the second is a misrepresentation waiting to be discovered during an incident, when the client reads the clause you signed with a different level of attention.
Where the Requirements Come From
Most guideline security sections trace back to a handful of sources. The Association of Corporate Counsel published its Model Information Protection and Security Controls for Outside Counsel in March 2017, organized into thirteen control areas that in-house departments could paste into their own guidelines, and many did. The ACC followed in December 2020 with its Data Steward Program, a standardized way for corporate legal departments to assess law firm security, which pushed the same expectations further down the market. Insurance carriers maintain their own panel counsel guidelines for the defense firms they appoint, and regulated clients in healthcare and financial services pass their HIPAA and Gramm-Leach-Bliley obligations downstream to their lawyers.
Underneath all of it sits the ethical floor. ABA Formal Opinion 477R in 2017 described the reasonable efforts lawyers owe to secure client communications, Formal Opinion 483 in 2018 set out a lawyer's duties after a breach, and Formal Opinion 512 in July 2024 addressed generative AI. California lawyers carry the same duties under Business and Professions Code section 6068(e) and Rule 1.6 of the California Rules of Professional Conduct, and the State Bar issued its own practical guidance on generative AI in November 2023. Client guidelines do not replace those obligations; they make them specific, measurable, and enforceable by contract.
The Security Clauses You Will See in Most Outside Counsel Guidelines
The wording varies by client, but the substance repeats. Eight clauses appear in nearly every guideline: multi-factor authentication on all access to systems holding client information, encryption of client information at rest and in transit, breach notification within a fixed window that is often 24 to 72 hours, restrictions on entering client information into generative AI tools, return or secure destruction of client information at the end of a matter, endpoint detection and log retention with someone monitoring the alerts, flow-down of equivalent controls to subcontractors, and cyber liability insurance at stated limits backed by an annual attestation and a right to assess. Each one reads as a sentence of legal language and lands as a configuration, a report, or a process in the firm's IT environment, and the sections below take them in turn.
Multi-Factor Authentication on Everything
Every guideline starts here, and it is the requirement firms most often believe they meet when they do not. "We have MFA" usually means MFA is available in Microsoft 365, not that it is enforced for every account through a policy that cannot be switched off by the user. The guideline language covers all access to client information, so the document management system, the practice management platform, remote desktop or VPN, and every administrative account count, not just the mailbox.
Two details decide whether the control survives an assessment. The first is coverage of the people outside the core roster: contract attorneys, lateral hires in their first week, paralegals working from home, and the IT vendor itself. The second is the method, because clients and insurers increasingly ask for phishing-resistant factors such as passkeys or hardware keys for privileged accounts rather than text-message codes. A firm whose identity and access management is built around conditional access policies can show a coverage report in minutes, which is exactly what an attestation asks for.
Encryption at Rest and in Transit
Encryption clauses are usually easy to meet and hard to prove. Modern laptops and phones encrypt by default, but a guideline asks whether the firm can demonstrate it across the whole fleet, which requires central device management that reports encryption status and escrows recovery keys. Email in transit is encrypted between major providers, yet the clause often reaches further, asking for end-to-end protection or a secure portal for the most sensitive categories.
The categories that trip firms are the ones nobody thinks of as systems: the scanner in the copy room that stores images on an internal drive, the external hard drive a partner uses for trial exhibits, and the backup set that was never encrypted because it was configured years ago. An assessor will ask about all three, and will also ask whether privileged attachments leave the firm through email encryption for business or through ordinary unprotected email.
Breach Notification Windows
The ACC model language requires notice to the client within 24 hours of discovering an actual or suspected data security breach, and it defines a breach broadly enough to include suspected unauthorized access, not just confirmed theft. Carrier panel guidelines and corporate versions commonly land between 24 and 72 hours. The word that matters is "suspected," because it moves the clock to the moment someone notices something odd, not the moment a forensic report confirms what happened.
Meeting that clock requires three things that small firms often lack. The firm needs monitoring capable of noticing an intrusion in hours rather than weeks, a written incident response plan that names who decides whether an event is "suspected" and who calls the client, and a relationship with breach counsel so the notice does not waive privilege over the firm's own investigation. The ACC model also asks for a single point of contact the client can reach around the clock, which for most firms means the managed security provider's on-call line rather than a partner's cell phone.
Restrictions on Generative AI
This is the newest clause and the one changing fastest. Guidelines updated since 2024 typically prohibit entering client information into generative AI tools without the client's written consent, bar any use that allows a vendor to train on the data, and require disclosure of which tools the firm uses. ABA Formal Opinion 512 reached a similar place from the ethics side, advising that lawyers obtain informed consent before inputting information relating to the representation into a self-learning AI tool.
The trap is the tools nobody classified as AI: the meeting notetaker that joined a client call, the summarization feature inside a research platform, and the assistant now built into office software. The firm's AI and cybersecurity practices for law firms need to account for these before a client reads the guideline's definition of "AI tool" more broadly than the firm did.

Data Return and Destruction at the End of a Matter
Guidelines increasingly require the firm to return or destroy the client's information when a matter closes and to certify in writing that it did so. Client versions usually add a deadline. The requirement sounds simple until someone maps where a matter's data actually lives: the document management system, the mailbox of every timekeeper who touched it, a shared drive, a litigation support vendor, a cloud file-sharing link that never expired, and eleven months of backups.
Most guidelines carve out backups and routine email on the understanding that they are retained under a written schedule and protected, which is why the firm's own retention policy becomes the document that makes the certification defensible. A firm that cannot state what it keeps and for how long cannot honestly certify that it destroyed the rest.
Endpoint Detection, Logging, and Someone Watching
Older guidelines asked for antivirus. Current ones ask for endpoint detection and response, central log collection with a retention period, and monitoring that produces alerts a human reviews. The underlying question is whether the firm would know about an intrusion before the client did, and a firm whose only detection is a staff member noticing a slow computer cannot answer yes.
For a firm of ten to fifty people, this is nearly always purchased rather than built. Managed threat detection and response supplies the tooling, the 24-hour coverage, and the written escalation path that the breach clause assumes exists, at a monthly cost that is a fraction of a single analyst's salary.
Vendor and Subcontractor Flow-Down
The clause that surprises firms is the one about everybody else. Guidelines require that subcontractors with access to client information meet equivalent controls, and a litigation firm's subcontractor list is long: e-discovery platforms, court reporters, copy services, translators, expert witnesses, and the cloud providers behind all of them. The firm is expected to know who holds client data, to have vetted them, and to have contract language that passes the obligations along.
A basic vendor inventory with a due diligence file for each vendor satisfies most assessors, and the discipline described in our guide to third-party risk management scales down to a firm with a dozen vendors. The mistake is assuming that a large vendor's own security makes the firm's review unnecessary; the guideline asks whether the firm did the review, not whether the vendor is famous.
Insurance, Audits, and Annual Attestations
The ACC model requires outside counsel to carry cyber liability insurance with stated minimum limits from a rated carrier, and most corporate guidelines adopted the idea. Annual attestations ask a firm representative to certify continued compliance, and assessment rights let the client or its designee review evidence, sometimes including a site visit or a third-party assessment. Some guidelines reference ISO 27001 or a SOC 2 report as preferred evidence while accepting alternatives.
The insurance clause interacts with the rest of the list in a way firms should notice. Carriers now condition coverage on the same controls the guidelines require, so the firm that cannot enforce MFA may find it cannot obtain the policy the guideline also demands, which is one reason cyber insurance for small businesses has become a security project rather than a purchasing decision.
How a Small or Mid-Sized Firm Meets Client Security Requirements Without an Enterprise Budget
Large firms have information security teams whose entire job is responding to client guidelines. A fifteen-lawyer firm in Encino or Sherman Oaks does not, yet it may hold guidelines from a studio, a hospital system, a bank, and two insurance carriers, each with slightly different language. The method that works is the same at every size, and it begins with paperwork rather than technology.
Start With an Inventory of Every Guideline You Have Already Signed
Pull the outside counsel guidelines attached to every active client relationship, including the ones incorporated by reference in engagement letters nobody has reread since signing. Put the security clauses side by side in a simple matrix: MFA scope, encryption scope, notification window, AI restrictions, return and destruction terms, subcontractor requirements, insurance limits, and attestation dates. The firm does not need to meet each client's version separately; it needs to meet the strictest version of each clause once, because a control that satisfies the 24-hour client satisfies the 72-hour client as well.
This exercise usually produces two findings. Some clauses are already met and simply undocumented, and one or two are genuinely unmet, typically the AI restriction, the destruction certification, or the vendor flow-down. Knowing which is which turns a vague sense of exposure into a short project list.
Map Each Clause to a Control You Can Prove
An assessor does not want assurances, it wants artifacts. For each clause in the matrix, identify the control that meets it and the report that proves it. MFA is proven by a conditional access policy and its coverage report, encryption by a device management compliance report, and the breach clause by the incident response plan and the record of the last tabletop exercise. The AI clause is proven by the AI policy and the approved-tool list, close-out by the written retention schedule and a sample destruction certificate, and the subcontractor clause by the vendor inventory with its due diligence files.
For most firms under 300 people, the bulk of this evidence comes out of a correctly configured Microsoft 365 Business Premium tenant, which includes conditional access, device management, endpoint protection, and sensitivity labels. The gap is rarely the license and nearly always the configuration, because the features exist whether or not anyone turned them on and tested them.

Negotiate What You Cannot Meet Rather Than Signing and Hoping
Corporate legal departments expect redlines on outside counsel guidelines, and the security section is negotiable more often than firms assume. A firm that cannot meet a 24-hour notice window for confirmed details can usually agree to 24-hour initial notice followed by updates, and a firm without ISO 27001 can offer a third-party assessment report instead. Clients generally prefer an honest compensating control over a signature they will later discover was aspirational.
The one thing never to negotiate by silence is an attestation. Certifying a control the firm does not have converts a security gap into a misrepresentation, and after an incident the client's first move is to compare what happened against what the firm certified.
Breach Clauses Deserve Counsel's Eye Before Signing
Of all the security clauses, the breach notification section should be read by a lawyer who handles incidents, because its definitions decide when the clock starts and what the notice must contain. A clause that defines a breach as "suspected" unauthorized access to any client information, with no materiality threshold, can require notice of a phishing email that one paralegal opened. The firm's incident response plan must be written to the strictest definition it has signed, and the plan should state who makes the "suspected" call and within what internal deadline.
Build the Attestation Package Once and Refresh It Yearly
Annual attestations arrive from different clients in different months, and each one asks for roughly the same evidence. A firm that assembles a single package, with the policy set, the MFA and encryption coverage reports, the training records, the incident response plan, the vendor inventory, and the insurance certificate, answers every attestation with the same folder and updates it once a year. This is the same discipline that compliance and risk management services apply to HIPAA and PCI programs, and it works for client guidelines because the evidence overlaps almost completely.

Where Law Firms Most Often Fall Short on Client Security Requirements
The failures assessors find are rarely exotic. They are the ordinary gaps between what a firm believes about its environment and what the environment actually does, and the same ones appear across practice areas:
- MFA enforced for partners and staff but not for contract attorneys, law clerks, or the IT vendor's own accounts
- Client documents on personal phones and home computers that no device policy reaches
- File-sharing links created for a matter that never expired, still live years after the matter closed
- An aging on-premises server holding closed-matter archives, unencrypted and unmonitored
- AI notetakers and browser assistants adopted by individual attorneys without review
- No documented close-out process, so destruction certifications are signed on faith
- E-discovery and court reporting vendors engaged by email with no security terms at all
Every item on that list is fixable with policy, configuration, and a modest amount of ongoing management. None of them requires a dedicated security department, which is the point: the gap between a firm that passes a client assessment and one that fails is usually discipline rather than budget.
What Meeting Outside Counsel Guidelines Looks Like for a Los Angeles Firm
The Los Angeles legal market concentrates the industries whose guidelines are strictest. Entertainment and media clients care intensely about pre-release confidentiality, healthcare systems pass HIPAA obligations to their counsel, financial firms carry Gramm-Leach-Bliley and SEC expectations, and real estate and insurance clients have been burned by wire fraud often enough to write specific email controls into their terms. A firm with clients in two or three of those sectors is effectively running a regulated security program whether or not it thinks of itself that way, which is the situation our overview of IT and cybersecurity for law firms is written for.
GlobeVM works with law firms on exactly this problem: translating the security section of a client's guidelines into a configured, monitored, and documented environment, and then producing the evidence each attestation asks for. The firm's attorneys keep practicing law, and the security questions that used to land on a managing partner's desk get answered by people whose job it is to answer them.
There is a commercial upside that firms sometimes miss. A practice in Los Angeles that can hand a prospective client a clean answer to its guidelines, with evidence attached, wins work from firms that cannot, and corporate legal departments have started treating demonstrated security as a selection criterion rather than a compliance afterthought. Security evidence, in other words, has become part of the pitch.
Treat the Guidelines as the Specification for Your Security Program
Outside counsel guidelines are not going to get shorter, and the security sections are not going to get looser. The realistic response is to stop treating each client's version as a separate emergency and start treating the strictest clauses, taken together, as the written specification for the firm's security program. A firm that meets that specification once, documents it, and refreshes the evidence annually will find that new guidelines arrive as a comparison exercise rather than a scramble. If your firm has signed client security requirements it has never audited itself against, a short assessment of where the environment stands today is the sensible first step.
Frequently Asked Questions
Comments
0 Comments