MDRwatchdog
Home › Outside Counsel Guidelines
MDRwatchdog Compliance

Outside Counsel Guidelines: answer the security questionnaire with evidence

Corporate clients and cyber-insurers ask law firms the same questions—MFA, EDR, monitoring, encryption, an incident plan. We monitor your firm continuously and produce a control-by-control record, so you answer 'yes,' with proof, instead of guessing.

Book a 15-minute review →

Outside Counsel Guidelines (OCGs) are the security and billing terms corporate clients attach to an engagement, and many now include specific controls with the client able to terminate for non-compliance. Layered on top are cyber-insurance attestations and professional-responsibility duties under ABA Model Rule 1.6(c) and the technology-competence duty of Rule 1.1 comment 8. A firm with many clients needs one baseline that satisfies them all.

MDRwatchdog monitors your attorney and staff endpoints, cloud mail, and identity—where wire-fraud and client-data attacks actually land—and maps that telemetry to a control record modeled on the ACC Model Information Protection and Security Controls and common insurance questions. Controls we can prove are marked as evidenced; the rest are flagged for you to attest, so your answers are honest and defensible.

MDRwatchdog provides security monitoring and evidence, not legal advice or an opinion on professional responsibility, and it is not a certification of compliance with any client's specific OCG. Individual client terms vary and often exceed this baseline—read your own engagement letters and consult your own counsel.

Industries we serve for Outside Counsel Guidelines

Frequently asked questions

What is an Outside Counsel Guideline?

OCGs are the requirements corporate clients attach to a legal engagement, increasingly including security controls—MFA, encryption, EDR, monitoring, breach-notification windows—with termination rights for non-compliance. Firms with many corporate clients need one baseline that satisfies them all.

How does MDRwatchdog help answer a client security questionnaire?

We monitor your firm continuously and produce a control-by-control record mapped to the ACC Model Controls and common insurance questions. Evidenced controls are marked as such; the rest are flagged for the firm to attest—so answers are honest and defensible.

Is this legal advice?

No. MDRwatchdog provides security monitoring and evidence to support a firm's compliance program. It is not legal advice, not an opinion on professional responsibility, and not a certification of compliance with any client's OCG. Read your own engagement terms and consult counsel.

What about firms serving healthcare or defense clients?

Those regimes can flow downhill through the engagement—a firm handling PHI may need HIPAA evidence; one with DoD work may face CMMC flow-down. Those can be assessed alongside the outside-counsel baseline from the same monitored environment.

MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).