Law firms
Outside counsel guidelines, the client security questionnaire, and the ethics opinions behind both. We know the paper each one arrives on.
What arrives
- The OCGs
- Client outside counsel guidelines. Contractual, not regulatory, and carrying the data security, audit, notification and indemnity terms the client's own vendors were given.
- The questionnaire, or the client audit
- The client vendor-security questionnaire, and in some engagements an on-site security audit of the firm.
- 477R and 483
- ABA Formal Opinion 477R on securing client communications, and Formal Opinion 483 on the duties owed after a breach.
- Rule 1.6(c)
- ABA Model Rule 1.6(c). Reasonable efforts to prevent unauthorized disclosure of information relating to a client.
What the Institute has found here
The Vigil LibraryInstitute
The Vendor as the Vector: Third-Party Risk Management Across Veterinary and Insurance Networks
Field notes · June 2026
Read itInstitute
The SMB Security Paradox
Analyst · February 2026
Read itInstitute
The Compliance Mirage: Why Regulatory Checkboxes Fail to Predict Breach Outcomes
Policy · June 2026
Read itStart the conversation
A short, plain conversation about the outside view, with an advisor who knows the paper.

