Proof it works

Answer the security questionnaire with evidence.

Corporate clients and cyber-insurers ask the same questions: MFA, EDR, monitoring, backups, an incident plan. We monitor your firm around the clock and produce a control-by-control record — so you answer “yes,” with proof, instead of guessing.

mdrwatchdog — outside counsel control baseline
tenant=RHODES_LEGAL · ACC Model Controls / ABA 1.6(c)
LEG-02 | Multi-factor authentication
  MET · evidenced from live identity telemetry
LEG-05 | Endpoint detection & response
  MET · 8 sensors reporting
LEG-06 | Monitoring & retained audit logs
  MET · 52,104 audit records retained
LEG-14 | Vendor oversight program
  GAP · attestation required — flagged for remediation
14
OCG controls mapped
ACC
Model Controls basis
1.6(c)
ABA duty supported
Legal & Law Firms · Outside Counsel Guidelines

A watchdog on the client secrets you're trusted to keep

We monitor your firm around the clock and turn it into a control-by-control security record—so you answer client questionnaires, Outside Counsel Guidelines, and insurance attestations with evidence, not guesswork.

Built for the firm that just got a 40-question client security form

Watch the whole firm

24/7 detection across attorney and staff endpoints, cloud mail, and identity—where wire-fraud and client-data attacks actually land.

Evidence the controls

A control-by-control record mapped to ACC Model Controls and common insurance questions, with evidenced items marked and gaps flagged.

Answer with proof

Turn a client questionnaire or renewal attestation from a scramble into a document you can produce on demand.

The outside-counsel baseline

Fourteen controls drawn from the ACC Model Information Protection and Security Controls, common cyber-insurance questions, and the professional-responsibility duties most firms are held to.

  • Written information security program
  • Multi-factor authentication
  • Endpoint detection & response on every device
  • Security monitoring with retained audit logs
  • Email security & business-email-compromise watch
  • Least-privilege access with periodic review
  • Encryption at rest and in transit
  • Incident response with client-notification window

Common questions

Why do law firms need security monitoring?+

Law firms hold concentrated client confidential information and face three pressures at once: client Outside Counsel Guidelines (OCGs) with security terms, cyber-insurance attestations at renewal, and professional-responsibility duties under ABA Model Rule 1.6(c) and the technology-competence duty of Rule 1.1 comment 8. Continuous monitoring produces the evidence these demand.

What is an Outside Counsel Guideline (OCG)?+

OCGs are the security and billing requirements corporate clients attach to an engagement. Many include specific controls—MFA, encryption, EDR, monitoring, breach-notification windows—with the client able to terminate the engagement for non-compliance. A firm with many corporate clients needs one baseline that satisfies them all.

How does MDRwatchdog help a firm answer a client security questionnaire?+

We monitor the firm's endpoints and cloud around the clock and produce a control-by-control record mapped to the ACC Model Information Protection and Security Controls and common insurance questions. Controls the platform can prove from live telemetry are marked as evidenced; the rest are flagged for the firm to attest—so answers are honest and defensible.

Is this legal advice?+

No. MDRwatchdog provides security monitoring and evidence to support a firm's compliance program. It is not legal advice or an opinion on professional responsibility, and it is not a certification of compliance with any client's specific OCG. Individual client terms vary and often exceed this baseline—firms must read their own engagement letters and consult their own counsel.

What about firms that serve healthcare or defense clients?+

When a firm's clients are hospitals or defense contractors, those regimes can flow downhill through the engagement. A firm handling PHI as a business associate may need HIPAA evidence; one with DoD work may face CMMC flow-down. Those frameworks can be assessed in addition to the outside-counsel baseline.

Related guides

Plain-language answers to the questions buyers ask most—readiness and evidence, not certification or legal advice.

Turn your next client security form into a two-minute answer.

Book a 15-minute review and we'll map your firm to the outside-counsel security baseline.

Schedule your 15-minute review