Meritas' New Cybersecurity Standard Requirement Is for Assuring Lawyers' Clients
Meritas has instituted a new cybersecurity requirement to showcase its members have a cybersecurity standard in place as clients demand more consistency.
October 17, 2018 at 09:00 AM
3 minute read
Meritas, a nonprofit association of law firms, now requires its law firm members to follow a new cybersecurity standard. The reason for this new standard? Law firms' clients.
“All of what you are seeing is because clients are requiring it of outside resource providers,” explained Tanna Moore, president and chief executive officer of Meritas.
Moore stated law firm clients have a heightened awareness of cybersecurity after recent breaches of law firms' confidential data. The 2016 Panama Papers, where Mossack Fonseca was breached and a plethora of data was exposed, leading to the firm's dissolution, inspired Meritas to develop a cybersecurity standard for the company and its member firms, Moore said.
“We [law firms] really have a lot of confidential information about clients; we need standards about how we store confidential client data,” she explained.
The Minneapolis-based company collaborated with a cybersecurity expert for nine months and announced its 10 cybersecurity standards that current and future Meritas members must follow. Meritas' new cybersecurity standards are:
1. Requiring a cybersecurity plan specifying what to do if a cybersecurity breach occurs;
2. Senior management commitment, which Moore called a “culture” requirement where senior management must be committed to safeguarding their data;
3. Yearly risk and compliance assessment;
4. Technical safeguards such as encryption;
5. Physical safeguards, which Moore defined as law firms having policies and procedures in place to ensure physical content and offices are secure;
6. Employee training;
7. Verifying a third-party service provider has a cybersecurity plan;
8. Having a business continuity plan in place to assess if the firm has “appropriate” backup;
9. Breach response;
10. Reviewing and updating cybersecurity plans.
Currently, penalties for not meeting the new standards haven't been set. “As the program is just being implemented, we are in the process of determining the long-term consequences,” Moore said. “At this point, we bring issues to the members' attention for them to resolve.”
The new cybersecurity standards are offered as an assurance to clients that law firms in the Meritas association are members of an organization that requires them to be equipped with cybersecurity standards. The way Meritas operates is that if a member law firm has client work that is out of the law firm's jurisdiction, it can refer a fellow Meritas member law firm to that client.
“If they are referring another firm in our organization, they are assuring that this firm has looked at and is aware of cybersecurity plans,” Moore explained.
Meritas has 181 law firm members spread across 90 countries, according to Meritas' website, and finding a simple core of cybersecurity requirements in a sea of differing international regulations was key, Moore said.
She added, “We wanted to be able to find the common denominator and simplify it so our firms would understand them.”
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1Bribery Case Against Former Lt. Gov. Brian Benjamin Is Dropped
- 2‘Extremely Disturbing’: AI Firms Face Class Action by ‘Taskers’ Exposed to Traumatic Content
- 3State Appeals Court Revives BraunHagey Lawsuit Alleging $4.2M Unlawful Wire to China
- 4Invoking Trump, AG Bonta Reminds Lawyers of Duties to Noncitizens in Plea Dealing
- 522-Count Indictment Is Just the Start of SCOTUSBlog Atty's Legal Problems, Experts Say
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250