The Association of Corporate Counsel (ACC) recently released their “Model Information Protection and Security Controls for Outside Counsel Possessing Company Confidential Information,” which specify baseline security measures that legal departments may require of outside counsel and set expectations with respect to their data security practices. This comes just as the New York State Department of Financial Services (NYS DFS) cybersecurity requirements went into effect on March 1 this year.

Law firms need to pay attention to both developments. The ACC guidelines will set client expectations of law firms while the DFS regulations mandate requirements for financial institutions operating in New York which extend to their service providers, including law firms. Most of the world’s notable brands have a presence in New York, so it’s hard to imagine many firms not being subject to compliance.

The New Standard of Care