Skip to Main Content
Go to Why Work Here page
McDermott Will & Schulte logo

McDermott Will & Schulte

The following is an excerpt from Practice Perspectives: Vault's Guide to Legal Practice Areas.

Katy Linsky is a New York-based privacy and cybersecurity partner at McDermott Will & Schulte who counsels on data practices throughout the information life cycle. She represents a wide range of clients and advises on regulatory and compliance matters, data use and business strategy, incident response and preparedness, and transactions. Katy has a global practice and focuses on providing practical, risk-based advice to legal and business leaders with an emphasis on privacy by design, development, and innovation. Katy worked in-house at a multinational technology company where she supported AI.

David Sorenson is an associate in McDermott’s Los Angeles office, specializing in privacy and cybersecurity matters. David represents a wide range of clients, including professional services firms, large consumer goods companies, and social media companies. David advises these clients on international data privacy compliance programs, state privacy laws, international privacy laws, and data subject requests. While at McDermott, David has advised clients by investigating and responding to complex and, in some cases, ongoing security incidents. David also advises his clients on strategic technology transactions, international data transfers, implementation of AI, data breaches, and combating internet fraud.

Describe your practice area and what it entails.

Katy: My practice is focused on counseling, advisory, and regulatory compliance work. I help clients build and bring to market products and services and evaluate and comply with the requirements of various privacy and cybersecurity regulations that apply to them on an enterprise level. I also help clients with day-to-day privacy and security questions by, for example, responding to data subject requests and negotiating agreements.

David: Privacy and cybersecurity law involves many different types of projects, which are grounded in our clients’ need to protect the information entrusted to them. Our work typically includes conducting risk assessments to identify potential weaknesses that can be remediated; ensuring that clients understand their obligations under applicable laws, how these obligations apply to new products or projects, and how to design these products to comply with their obligations; and negotiating appropriate agreements where information is shared between multiple parties. We also assist clients in responding to security incidents, where necessary, which typically involves directing the investigation and documenting the incident itself, engaging third parties to assist in the investigation, advising the client on any notification obligations they have, and assisting in addressing any risks that the incident uncovers.

What types of clients do you represent?

Katy: I represent a wide range of clients in varying industries. Some of my clients include Big Tech, entertainment, and media companies; financial institutions; automobile manufacturers; and SaaS providers.

David: I represent all types of clients, including business-to-business, direct-to-consumer, and professional services firms, including law firms and accounting firms. These clients are unique in that, in addition to any legal obligations that most companies have, they also have professional obligations to protect their clients’ data.

What types of cases/deals do you work on?

Katy: My practice is primarily focused on daily counseling tasks and compliance projects. For example, each time a new regulation is introduced that impacts a client or new case law or regulatory enforcement is made available that may impact a client’s risk analysis or exposure, I work with the client to update their practices, policies, and procedures to address the new requirements. When a client is considering building a new product or service, I help them identify and work through any privacy or security issues that may arise.

David: I mainly work with clients in designing and implementing their privacy compliance programs or reviewing and improving their security programs. This frequently includes helping clients understand and strategically incorporate novel technologies, like generative AI. If a client has a security incident, I may also assist in investigating and in notifying individuals and regulators as necessary.

How did you choose this practice area?

Katy: I was introduced to this practice area as a first-year associate at a BigLaw firm. I was asked to help write an article about cyberinsurance, which was a new offering at the time. I was drawn to the novelty of the subject matter and recognized that the field would continue to grow in importance and complexity.

David: I chose this practice area because I am interested in the systematic implementation and development of technology and studied engineering as an undergraduate. I have really enjoyed the dynamic nature at the intersection of technological and legal issues and appreciate that it seems unlikely to settle on any typical set of challenges in the near future.

What is a “typical” day like and/or what are some common tasks you perform?

Katy: Every day is different, which is part of what is so exciting about this practice area. I may be negotiating an agreement one minute, working on a risk analysis for a new product the next, and researching a new law or regulatory framework after that. I meet regularly with my clients to issue-spot and provide gut checks based on ideas the business has brought to them that week.

David: My typical day includes a little bit of everything. Many of my clients are on the East Coast, so my morning often starts with meetings to discuss our projects and any other issues that have arisen. The rest of my workday is typically spent working on these matters or connecting with other McDermott lawyers. Usually, I get to spend my afternoon implementing the issues we discussed in our meetings, like revising contracts, but sometimes urgent new issues, like cyberattacks, require my immediate attention.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

Katy: Anyone looking to get into privacy and cybersecurity should find a way to demonstrate commitment to the field. Stay up-to-date with new laws and developments and seek out relevant internships and classes where available. The International Association of Privacy Professionals is also a great resource for attorneys looking to develop their privacy and cybersecurity skills.

David: If you have the opportunity, take an Introduction to Programming class. This will help you understand how data and computer systems work, which is critical background when determining how laws apply, how companies can comply with applicable laws, whether contractual terms are reasonable, and other similar issues. I also find that contracts—with their definitions and internal references—can be structured similar to computer programs, so it can help to think of a contract like the source code for a relationship between parties. You probably won’t need to write programs as a privacy and cybersecurity attorney, but this background can help you understand things such as how cookies work, how companies store data, or how companies can protect data when sharing it.

What is the most challenging aspect of practicing in this area?

Katy: In our practice, the most important things are flexibility, practicality, and comfort with the unknown. This field is constantly evolving, and regulation does not keep pace with the advancement of new technologies. One of the most challenging (and critical) aspects is keeping up with new developments and sifting through the noise to understand what’s really important from a risk perspective.

David: The most challenging aspect of privacy and cyber-security is ensuring that clients remain aware of relevant obligations under a rapidly changing legal landscape. Legislation related to privacy has matured significantly over the past decade and has expanded within the United States. Depending on their industry, companies may also be subject to industry-specific laws or standards. Understanding both these laws and our clients’ businesses is very important in advising them of not only their current obligations but also how they should anticipate new laws and regulations that will apply.

What do you like best about your practice area?

Katy: Privacy and cybersecurity is an exciting space with a lot of opportunity. My practice changes all the time, and every day, I am faced with complex questions that require thought and collaboration to work through. It’s never boring!

David: Privacy and cybersecurity is a relatively new field of law that comes with significant implications for every other field of law. I often get to work with and learn from experts in other fields, and usually I need to figure out a new issue that hasn’t been clearly answered before. As a result, I get to engage in very abstract and open-ended problem-solving, which I find very challenging but also fun and interesting.

What are some typical tasks that a junior lawyer would perform in this practice area?

Katy: Junior lawyers might help with implementing basic compliance requirements such as drafting privacy policies or taking a first pass at reviewing agreements. Junior lawyers can also help to evaluate and interpret new laws and regulations.

David: As a regulatory practice, junior lawyers will likely start by researching for specific projects and reviewing contracts. These research projects likely address specific questions under the law, such as whether a company can use a web form to receive data subject requests in certain jurisdictions. The contracts will likely be a mixture of data protection agreements and security addenda. Junior lawyers may also be staffed on data breaches, which are always unique and provide the junior lawyer an opportunity to demonstrate their adaptability. As junior lawyers gain experience in these areas, they will develop an ability to understand structural similarities and differences between different types of laws and to address the relative priorities of their clients.

How do you see this practice area evolving in the future?

Katy: This practice area will continue to grow and evolve. We may see additional sector-specific regulation requiring additional specialization within the privacy and cybersecurity umbrella. The practice will also shift with the introduction of new technologies, which we are already seeing in the AI space.

David: In the short term, I expect that we will see laws around the United States and around the world maturing to account for emerging technologies, including AI, and as technology expands further into our common, daily tools, it will become even more critical for companies to emphasize privacy and security at an early stage. Staying on top of the regulatory landscape will require understanding these laws and technologies so that we can properly advise clients on how, for example, “reasonable security” has changed such that it typically requires more controls than it did a decade ago.