Overview
The stakes have never been higher in cybersecurity, privacy, artificial intelligence, and other emerging technologies. Cybersecurity and privacy laws and regulations continue to emerge and evolve from all directions. Cybersecurity attacks against businesses of all sizes continue to increase and become more sophisticated in part by the increased use of artificial intelligence. Finally, as more organizations adopt and explore how to harness the benefits and increased availability of artificial intelligence, they are looking for guidance in how to maximize its opportunities while managing its risks.
For these reasons, in our global information economy, it is more imperative than ever for organizations to understand their data and address cybersecurity and privacy realities. Fortunately, Maynard Nexsen’s Cybersecurity, Privacy, and Artificial Intelligence Practice offers comprehensive and practical approaches to address these pressing needs. Leveraging experienced attorneys and technology professionals, Maynard Nexsen’s team provides not only the legal proficiency and technical expertise our clients expect, but an unmatched practical business sense.
Data Security and Privacy Counseling
We help companies across multiple geographies and industry sectors to build out privacy and security programs from scratch, or to refine and strengthen existing ones, to adapt to changing business models and growth, and to ensure compliance with the ever-changing landscape of laws and regulations. Our services span the entire lifecycle of a company’s data, ranging from proactive measures – designed to comply with laws or regulations, allocate risk, or prevent incidents – to reactive measures in order to swiftly and effectively respond to a security or privacy incident, and to defend our clients in litigation when necessary:
Proactive Counseling
Cyber and/or Privacy Risk Assessment & Compliance:
Maynard Nexsen takes a global approach to risk assessment and compliance, evaluating the company’s full geographic footprint and operating environment, to determine the overall privacy and data security risk profile as well as assessing the policies and practices a company needs to have in place to manage a range of information assets, and the rules for managing data going forward.
Contractual Negotiations and Privacy Policy Work:
Our team works across our practice groups to negotiate data-related provisions in contracts: including nondisclosure agreements (NDAs), data protection agreements/addenda (DPAs), master service agreements (MSAs), SaaS/licensing agreements, and other technology or related agreements. We negotiate both upstream and downstream on behalf of and against customers, vendors (including IT/cyber consultants and IT managed service providers), business partners, and various other third parties. Often we are providing advice to ensure compliance with or allocate risk regarding various privacy laws – whether European (GDPR), Canadian (PIPEDA/Quebec 25), Japanese (APPA), Chinese (PIPL) or other international laws, as well as federal privacy laws, 23+ state comprehensives privacy laws such as California’s Consumer Privacy Act (CCPA), and targeted industry or sectoral laws such as BIPA (Illinois biometric data), Washington’s MHMD (health data), GINA (federal genetic privacy laws) and many others.
We also regularly draft or review and update clients’ internal and public-facing privacy policies/notices and website terms of use, which often require regular review due to a constantly changing legal and regulatory landscape, client changes in information / marketing practices, or geographic expansion due to acquisition or increases in their scope of operations.
We also negotiate contracts and ensure compliance around federal, state, and industry sector cybersecurity requirements and industry standards, including but not limited to:
- CIRCIA (critical infrastructure)
- Federal Privacy Act of 1974 (federal government agencies)
- FERC/NERC compliance (federal energy reliability, including cyber and physical security)
- SEC Regulation S-P and disclosure requirements
- FTC Safeguards and Red Flags rules
- Gramm-Leach-Bliley Act (financial institutions)
- NAIC Insurance Data Security Model Law (and state variations thereof) (insurance)
- HIPAA/HITECH (health care provider and business associates)
- DFARS/NIST SP 800-171/CMMC (government contractors)
- TSA Security Directives (transportation)
- CFPB (consumer protection)
- FERPA (educational institutions)
- PCI/DSS (payment card security standards)
- NIST Cybersecurity Framework, OWASP Top 10 web application security, ISO/IEC 27001 and other ISO/IEC standards, CIS controls, etc.
- and many more.
M&A/Due Diligence:
Our team works closely with our M&A and broader transactional teams to support due diligence on potential mergers and acquisitions, stock/equity purchase agreements, asset purchase agreements, and more. On behalf of both buyers and sellers, we assess compliance risk through reviewing documents in the data room, comparing and negotiating cybersecurity- and privacy-related representations and warranties (and disclosure schedules) against the evidence as well as market terms, and advise clients on “red flags” and risk assessments related to any issues that are identified.
Compliance and Risk Assessment:
Maynard Nexsen uses a number of tools to proactively work with companies to assess and mature their cybersecurity and privacy compliance. These include, but are not limited to:
- Website Review and Assessment
- Cybersecurity and Privacy Risk Assessments and Internal Audits
- Reviews of Policies, Procedures and Practices
- Legal and Regulatory Updates
- Cybersecurity Tabletop Exercises
- Employee Training and Awareness
Information Governance & Data Governance:
A key focus in our consulting practice is on the policies and practices a company needs to have in place to manage a range of information assets, and to set rules for how data will be managed moving forward. This often involves a number of efforts:
- Internal policy creation, review, and implementation
- Supply chain management, contract review and negotiation
- M&A Due Diligence
- Advisory Services
- Product Counsel
- SEC Reporting
- Artificial Intelligence (“AI”) and Other Emerging Technologies
Artificial Intelligence:
Artificial intelligence has moved from experiment to enterprise infrastructure, and with it comes a new layer of legal risk that traditional policies and frameworks were not designed to address— not only cyber and privacy risks, but also extending to issues like output ownership, training-data reuse, hallucinations, model drift, and algorithmic bias.
Nowhere is that risk more concentrated than in the contract, where standard AI vendor agreements systematically shift exposure onto the customer through broad data-usage rights, modest liability caps, and indemnities that may cover only third-party IP claims rather than regulatory fines, discriminatory outputs, or business disruption. Our firm advises clients on both sides of these transactions—representing AI consumers and AI providers in the negotiation of upstream and downstream agreements with vendors and customers alike. We help clients clarify, secure and calibrate the provisions that matter most, including training-data and input/output definitions, indemnification (with attention to exclusions and "super-cap" carveouts), data privacy and breach obligations, performance and bias-audit commitments, and meaningful limitations of liability tailored to AI-specific risk rather than legacy software language.
Beyond the deal table, we help businesses govern and regulate their own employee and enterprise use of AI—work that ranges from drafting a straightforward employee AI acceptable use policy to building a comprehensive AI governance program. Effective governance cannot live in a single department; it ideally depends on a cross-functional structure that brings together legal, compliance, IT, operations, sales, HR, security, data science, and business leadership with clearly defined roles, decision rights, and oversight across the AI lifecycle. Drawing on recognized frameworks such as the NIST AI Risk Management Framework (NIST AI RMF), the Duke Center on Law & Technology’s RAILS (Responsible AI Use in Legal Services) Risk Management Framework, ISO/IEC 42001, ISA/IEC 62443, and accounting for the rapidly evolving regulatory landscape including the EU AI Act and emerging U.S. state AI laws, we design governance structures, policies, and approval workflows that are convergent across business departments and functions—so our clients can capture the value of AI while managing legal, regulatory, and reputational exposure.
Cybersecurity Maturity Model Certification (CMMC)
The stakes have never been higher for government contractors due to the latest updates to the Cybersecurity Maturity Model Certification (CMMC) 2.0 requirements, which have now become the baseline of requirements in government contracts, solicitations and bids involving the handling of Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Certification is now a gating condition for award: contracting officers verify status in SPRS before making award decisions, and proposals lacking the required certification are rejected outright, regardless of price or past performance.
The risk does not end at the bid, however. Because contractors must self-attest to their compliance and provide annual NIST SP 800-171 affirmations, every certification, score, and POA&M representation is a potential basis for liability under the False Claims Act, the enforcement "hammer" that is increasingly being wielded against contractors that misrepresent or fail to maintain their cybersecurity posture.
Our Cybersecurity and Privacy team complements the extensive expertise of our Government Solutions team to help government contractors navigate both sides of this challenge—guiding clients through scoping, gap analysis, remediation, and the assessment process to achieve and maintain CMMC compliance, while drawing on deep regulatory and enforcement experience to manage, mitigate, and defend against False Claims Act exposure arising from cybersecurity representations.
The firm leverages its extensive expertise across government contracts, cybersecurity, and privacy to provide tailored solutions that meet the stringent requirements of the Cybersecurity Maturity Model Certification (CMMC). By focusing on simplifying the CMMC standard and providing clarity on cybersecurity regulatory, policy, and contracting requirements, Maynard Nexsen ensures that clients are well-prepared to handle advanced cybersecurity standards and third-party assessments, particularly for high-priority government programs. Additionally, the firm's proactive audit support and regulatory compliance strategies help clients navigate the complexities of CMMC, ultimately enhancing their ability to secure government contracts while maintaining strong cybersecurity postures.
Other Emerging Technologies:
In addition to artificial intelligence, our team also has specific and specialized expertise in certain emerging and critical infrastructure technologies:
- Fiber and Broadband Services. We have specific expertise and experience representing fiber infrastructure owners and operators, as well as telecommunications companies, data centers, internet service providers and other broadband service providers, with respect to fiber-related contracts and compliance. In this respect, our team of skilled attorneys represents a diverse range of clients, including electric utilities and cooperatives, and independent power producers; developers and investment funds; data centers; telecommunications providers, “dark” and “lit” fiber providers (both middle-mile and last-mile), broadband service providers, internet service providers, colocation service providers, and others. Our team has been responsible for landmark state legislation streamlining access to easements for broadband purposes, application for and compliance with federal and state broadband grant funds (e.g., CPF, ARPA, BEAD, etc.), and the successful negotiation of dozens of long-haul and distribution fiber lease agreements, colocation service agreement, remote hands and other types of agreements between fiber owners and operators and broadband service providers, middle mile networks, data centers, and hyperscalers. Our team includes a veteran of fiber agreements on behalf of large utilities, outside general counsel to several cutting edge broadband companies and their investors, and a telecommunications expert, J. Bradford Currier, who previously served in both the FCC’s enforcement bureaus as well as the first legal advisor to a state broadband office responsible for implementing grant funding programs and related procurement and legislative issues. Maynard Nexsen’s fiber team is proud to support and be members of the Fiber Broadband Association.
- Electric Reliability. Our team also has specific expertise related to electric grid reliability, including cyber and physical security compliance. Our practice groups’ leader, Brandon Robinson, has decades of experience as an energy regulatory attorney representing investor-owned utilities, electric cooperatives, and other electric service providers with respect to compliance with FERC and NERC reliability, including but not limited to NERC CIP standards related to cybersecurity and physical security. Over the years, the scope of this experience has been contractual, enforcement and policy-related: negotiating NERC services and auditing agreements, assessing compliance in context of self-reporting, spot check and audits by FERC, NERC, and Regional Entities, reviewing proposed notice of penalty(NOPs), training and preparing witnesses for audits, reviewing and providing input on draft RSAWs and proposed standards, and filing comments before FERC and NERC on proposed standards and other policy issues, either directly on behalf of clients or working with industry associations such as the National Rural Electric Cooperative Association (NRECA) or the Edison Electric Institute (EEI). He has also helped clients involved in the supply chain to electric providers, whether service providers, utility contractors, or providers of renewable or energy storage assets such as battery energy storage systems (BESS).
- Cryptocurrency and Digital Assets. Our team also has increasing experience working with blockchain and digital assets such as cryptocurrency. Working with our litigation, M&A, and financial service teams across the firm, our team assists in cryptocurrency and digital asset-related issues before financial regulators, in M&A transactions, contracts, and other needs. One of our team members, Danielle Dubose Cotter, previously served as Senior Counsel for the U.S. House of Representatives Committee on Financial Service’s Subcommittee on Digital Assets, spearheading legislative developments on cryptocurrency regulation and advising lawmakers on the intersection of technology and financial services. Additionally, she provided regulatory advocacy, compliance strategy, and expert witness support in her prior role at consulting firm Patomak Global Partners, serving the financial services sector. Danielle currently serves on the board of advisors to the Alabama Blockchain Alliance.
- Other Emerging Technologies. Our team also has specific experience related to drones/UAS and related FAA regulations, Internet of Things (IoT), smart homes and neighborhoods, microgrids, and other specific regulated technologies.
Reactive Services and Incident Response
In the heat of a cybersecurity or privacy incident, businesses need a law firm that can serve as a “one stop shop” to deliver an efficient and effective response that complies with regulatory obligations, maximizes the protection of the attorney-client privilege over the investigation, ensures consistency of messages and reporting across various audiences and stakeholders, and swiftly analyzes the forensic investigation to determine notification obligations.
Our Incident Response team prepares clients to navigate through incident response, internal investigations, regulatory inquiries, individual and regulatory notification requirements, and civil litigation (including class actions).
We handle all types and sizes of incidents, from small and accidental “leaks” of personal information by an employee, to large-scale breaches and ransomware attacks, to vendor breach notifications and indemnification efforts, to the increasingly prevalent business email compromises (“BECs”) where social engineering results in the misdirected transfer of funds to fraudulent accounts.
- Business Email Compromises (BECs) and Fraudulent Funds Transfers. When caught early enough, we can leverage our contacts at federal law enforcement as well as bank fraud departments, to try and quickly claw back the funds. If / when that fails, we can advise clients on negotiations and settlements (and sometimes litigation) with counterparties over liability for the risk of loss of the misdirected funds. We also engage under privilege with forensic investigators to determine whether such incidents may have compromised the business’s network and carry any breach obligations.
- Incident Response. In incident response, we act as a “one stop shop” in response to any confirmed or suspected incidents, to quarterback as a single point of contact amongst various stakeholders (i.e., insurance carriers, law enforcement, third-party vendors, regulatory authorities, media, crisis communications, customers, executive management and board members, etc.) to maintain compliance and consistency of messaging, and to provide calm and consistent guidance to our clients who must make crucial decisions within critical time windows. If notifications are required, we handle regulatory as well as individual notifications and credit monitoring, working with trusted third-party vendors under privileged engagement to meet applicable obligations and handle escalations.
- Class Actions and Other Data Breach Litigation. For large scale or otherwise critical data breaches that require notification, and which may result in class action or other large-scale complaints, we work with our nationally renowned team of class action litigators to defend our clients in class actions and other lawsuits involving data breaches or privacy incidents, both before Article III courts as well as regulatory agencies (e.g., FTC, SEC, CPPA, state AG offices or other state regulatory agencies, etc.). We also work closely with our litigation team to pursue indemnification or other reimbursement in the event of large scale vendor breaches.
- Regulatory Investigations. When cyber or privacy incidents or practices lead to investigations or inquiries by regulatory agencies, we work closely with our clients to respond efficiently and effectively with our clients’ federal and state regulatory authorities (in some cases multiple authorities) in ways that protect their interests, remain consistent and compliant over time and jurisdictional inquiries, and take into account multiple other stakeholders and audiences (e.g., customers, investors, boards, media, etc.)
Privacy Litigation & Regulatory Investigations
In addition to security incidents, our team works tirelessly with clients to prepare them for regulatory inquiries or litigation related to privacy. When investigations and litigation arise, Maynard Nexsen has the expertise and depth to meet those needs. Our multi-disciplinary, cross-functional teams stand ready to handle cases or investigations that may arise following a compromise of personal information, involving cybersecurity, privacy, or the intersection of the two. In addition to handling litigation and demands before federal and state courts, our team has experience addressing inquiries and enforcement actions from state attorneys general, the FTC, HHS OCR, and international data protection authorities.
Our team also defends causes of action arising from statutory violations of privacy and cybersecurity laws including but not limited to:
- BIPA (Illinois biometric privacy law)
- FTC Section 5 (unfair and deceptive practices) and state corollary UDAP laws
- FTC Safeguards Rule
- GLBA (financial institutions), including implementing regulations such as Regulation P and Regulation S-P
- SEC disclosure rules
- COPPA (federal law regarding children’s privacy)
- DOJ Bulk Transfer Rule
- CCPA (California comprehensive privacy law) and 23+ comprehensive privacy laws in other states
- California Invasion of Privacy (“CIPA”) and other state wiretapping laws (as applied to website cookies, tags, pixels and other adtracking technologies)
- CMMC (cybersecurity requirements for government contractors)
- FERPA (educational privacy)
- CPNI (telecommunications)
- HIPAA/HITECH (health care)
- TCPA (texts and robocalls)
- CAN-SPAM (emails)
- And many more.