Your clients trust you with data that regulators and plaintiffs' attorneys take seriously.
Legal and actuarial firms managing sensitive client information face growing cybersecurity governance obligations — from DFS, ERISA, professional liability insurers, and the clients whose data they hold.
The obligations are specific. The documentation gaps usually are too.
Law firms and actuarial practices occupy a particular position in the data governance landscape: they hold sensitive client data — financial records, personal information, privileged communications — under professional obligations that extend well beyond the IT systems they operate.
For actuarial and pension firms, ERISA DOL guidance on cybersecurity best practices has established an expectation of documented governance controls for plan administrators and their service providers. For law firms operating in regulated industries, client contractual requirements and professional liability standards increasingly demand evidence of cybersecurity governance — not just IT tools.
The firms that cannot produce that evidence are not just facing regulatory exposure. They are facing contract risk, malpractice exposure, and the reputational consequence of a breach in an industry where client trust is the primary asset.
The documentation that satisfies the governance standard — across frameworks.
For legal and actuarial firms, the governance obligation is rarely confined to a single regulatory framework. ERISA, state bar cybersecurity guidance, client security questionnaires, and professional liability insurer requirements often apply simultaneously.
IT On Demand builds governance programs that map to multiple frameworks — so that the documentation your firm produces satisfies the DOL examiner, the professional liability underwriter, and the client whose questionnaire arrived last Tuesday.
We also understand the third-party complexity that legal and actuarial practices carry: co-counsel relationships, data-sharing with plan administrators, court filing systems, and client-mandated platforms are all vendor relationships that require documentation. We build and maintain that inventory.
Questions we hear from legal and actuarial firms.
- Q: Our firm isn't a financial services firm. Does DFS apply to us?
- A: Not directly in all cases — though some law firms serving DFS-regulated clients may be covered as third-party service providers under those clients' 23NYCRR500 vendor management obligations. More commonly, the governance standards that apply to legal and actuarial firms come through ERISA DOL guidance (for pension and actuarial firms), professional liability insurance requirements, state bar cybersecurity guidance, and client contractual requirements. The applicable framework varies by firm. The Gap Assessment identifies which obligations apply to your specific situation.
- Q: Our largest client sent us a security questionnaire. We don't know how to answer most of it.
- A: That is the most common first conversation we have with legal and actuarial firms. The questionnaire is asking for the same governance documentation that a DFS examiner would request — penetration test results, vendor risk assessment processes, incident response plan testing, MFA coverage. If the documentation doesn't exist, the questionnaire cannot be answered accurately. We build the documentation first. Then the questionnaire answers itself.
- Q: Does ERISA require actuarial firms to maintain cybersecurity documentation?
- A: The DOL's cybersecurity guidance for ERISA plans — issued in April 2021 and reinforced through subsequent examinations — establishes expectations for plan fiduciaries and their service providers. Actuarial firms and third-party administrators serving ERISA plans are expected to demonstrate cybersecurity best practices to plan sponsors and DOL examiners. The guidance does not prescribe a specific framework, but DOL examinations have focused on documented governance controls — not just security tooling.
Start with a Compliance Gap Assessment.
The Assessment identifies which governance obligations apply to your firm specifically, what documentation you currently have, and what you are missing. 30 minutes. No pitch. No obligation.