
Direct Answer
If your law firm maintains private information about New York residents, the NY SHIELD Act requires you to develop, implement, and maintain reasonable administrative, technical, and physical safeguards to protect that information. The law also expanded New York's data breach requirements and broadened the definition of private information. (New York State Attorney General)
For most 10–25 employee law firms, the NY SHIELD Act should not be viewed as a checklist of specific technologies. It establishes a standard of reasonable safeguards, some of which are supported by technology. (New York State Attorney General)
Why This Matters
Law firms routinely maintain confidential client information, employee records, financial information, and other sensitive data.
If that information is compromised, the consequences may include business disruption, regulatory scrutiny, reputational damage, and loss of client trust.
The NY SHIELD Act recognizes that protecting private information is not solely an IT responsibility. It is a business responsibility that requires policies, people, and technology working together. (New York State Attorney General)
Editor's Insight
Technology alone doesn't make your law firm compliant, it helps you implement reasonable safeguards.
The NY SHIELD Act doesn't tell businesses which firewall to buy, which antivirus software to install, or whether to use a particular cloud provider.
Instead, it requires businesses to implement reasonable safeguards.
Technology is only one part of that responsibility.
Policies, employee training, vendor management, and ongoing risk assessment are equally important.
The Three Types of Reasonable Safeguards
The New York Attorney General explains that the NY SHIELD Act requires businesses to adopt administrative, technical, and physical safeguards. The examples provided are not intended to be an exhaustive list. (New York State Attorney General)
Reasonable safeguards are measured by what your law firm does consistently, not by a single security product you purchase.
1. Administrative Safeguards
Administrative safeguards focus on how your firm manages information security.
According to the Attorney General, examples include:
- Designating someone to coordinate the security program.
- Identifying reasonably foreseeable risks.
- Assessing existing safeguards.
- Training employees.
- Selecting vendors capable of protecting private information.
- Updating the security program as risks change. (New York State Attorney General)
Avenue M's Recommendation
Every law firm should have documented security policies, regular employee security awareness training, and a clear process for reviewing security risks as technology and threats evolve.
2. Technical Safeguards
Technical safeguards protect the systems that store, process, and transmit information.
The Attorney General lists examples such as:
- Assessing network and software risks.
- Protecting information during processing, transmission, and storage.
- Detecting, preventing, and responding to attacks or system failures.
- Regularly testing and monitoring security controls. (New York State Attorney General)
Avenue M's Recommendation
While the NY SHIELD Act does not require specific technologies, Avenue M considers several security controls to be foundational for today's law firms.
We recommend implementing:
- Multi-Factor Authentication (MFA) for Microsoft 365, email, remote access, and any system containing client or sensitive business information.
- Endpoint Detection and Response (EDR) to detect and respond to suspicious activity.
- Timely operating system and software updates.
- Secure backups with regular recovery testing.
- Continuous monitoring of critical systems.
- Encryption for laptops and other mobile devices that contain sensitive information.
These technologies help support the Act's requirement for reasonable technical safeguards. They also align with current cybersecurity best practices and are commonly expected by cyber insurance providers.
3. Physical Safeguards
Physical safeguards protect both paper and electronic records from unauthorized access.
Examples identified by the Attorney General include:
- Assessing risks related to information storage and disposal.
- Preventing unauthorized access.
- Protecting private information during its lifecycle.
- Securely disposing of information that is no longer needed. (New York State Attorney General)
Avenue M's Recommendation
Even firms that operate primarily in Microsoft 365 should have procedures for securing laptops, controlling office access, protecting paper records, and securely disposing of retired computers and storage devices.
What About Small Law Firms?
One of the strengths of the NY SHIELD Act is that it recognizes not every business has the same resources.
For small businesses, the law provides that reasonable safeguards should be appropriate for:
- the size and complexity of the business,
- the nature and scope of its activities, and
- the sensitivity of the private information it maintains. (NYSenate.gov)
That doesn't mean small law firms can ignore cybersecurity.
It means a 15-person law firm is not expected to have the same security program as a multinational corporation. The safeguards should be reasonable for the firm's circumstances.
Questions We Hear From Law Firms
Does the NY SHIELD Act require Multi-Factor Authentication (MFA)?
The Attorney General's guidance does not require a specific technology such as MFA. However, Avenue M considers MFA a foundational security control for modern law firms and recommends implementing it wherever sensitive information is accessed.
Does having good cybersecurity automatically make my law firm compliant?
Not necessarily.
Strong technology is an important part of a security program, but the NY SHIELD Act also emphasizes administrative and physical safeguards. Policies, employee training, vendor oversight, and ongoing risk management are all part of maintaining reasonable safeguards. (New York State Attorney General)
How Avenue M Helps
Helping law firms implement reasonable safeguards is about much more than installing technology.
Avenue M works with law firms throughout New York and New Jersey to strengthen their security programs through:
- Managed IT services
- Cybersecurity monitoring
- Multi-Factor Authentication (MFA)
- Endpoint Detection and Response (EDR)
- Microsoft 365 security
- Backup and recovery planning
- Security awareness guidance
- Technology planning and documentation
Our goal is to help your firm build a practical, sustainable security program that supports your business and protects your clients.
Three Key Takeaways
- The NY SHIELD Act doesn't require perfect security, it requires your law firm to take reasonable steps to protect private information.
- Technology alone doesn't make your law firm compliant, it helps you implement reasonable safeguards.
- Reasonable safeguards aren't a one-time project, they're an ongoing business responsibility.
Related Articles
- What Cybersecurity Requirements Should New York and New Jersey Law Firms Meet?
- How Often Should Law Firms Test Their Backups?
- How Should Law Firms Prepare for Cyber Insurance Questionnaires? (Coming Soon)
- What Should Every Law Firm Include in an Incident Response Plan? (Coming Soon)
Technology should help your law firm practice law more securely, efficiently, and confidently, not become another distraction.

