The Lawxy Times

Author Image
Lawxy Times Reporter

MGM Resorts Spurs Rise of Multidisciplinary Crisis Management Teams

On July 1 2026, leading law firms announced the formal creation of multidisciplinary crisis‑management groups in response to the 2017 Mandalay Bay shooting. The development codifies crisis response as a distinct legal service that integrates litigation, public‑relations, and cybersecurity expertise. Public companies and hospitality operators are now required to engage such teams to mitigate exposure under securities‑disclosure and regulatory‑investigation rules. The shift clarifies that firms may bill for coordinated crisis services separate from traditional advisory work.

Full News Breakdown

The 2017 Las Vegas mass shooting exposed a gap in corporate emergency response, prompting MGM Resorts’ counsel to summon lawyers with crisis‑management experience. Law firms subsequently debated whether to treat coordinated emergency response as a standalone practice or as an extension of existing litigation and regulatory work. By mid‑2026 the majority adopted the former model, launching dedicated multidisciplinary units.

  • Primary Legal Issue: Coordination of multidisciplinary crisis response for corporate emergencies

  • Practical Outcome: Law firms now market structured crisis‑management groups to corporate clients

How Does This Affect You?

Before this development, companies lacked clear guidance on who could provide integrated legal, public‑relations, and technical advice during sudden emergencies. The industry consensus now resolves that gap by recognizing multidisciplinary crisis‑management groups as a legitimate, billable legal service. This makes it certain that clients can secure a single point of contact for coordinated response, while regulators may assess the adequacy of such structures when evaluating compliance with disclosure and investigation obligations.

For Lawyers & Advocates

  • Boards may wish to adopt a trigger‑based clause in corporate governance manuals that obligates activation of the firm’s crisis‑management unit when a material event meets the SEC’s “prompt disclosure” threshold under the Securities Exchange Act.

  • Counsel may consider re‑evaluating ongoing securities‑class‑action defenses to incorporate coordinated media statements prepared by the crisis team, thereby reducing the risk of adverse jury perception.

  • Firms may find it useful to draft the crisis‑management engagement agreement as a separate retainer, specifying fee structures for legal, PR, and cybersecurity components to satisfy Rule 1.5 of the Model Rules on fees.

  • Counsel may wish to cite the 2026 industry shift as persuasive authority when arguing that a client’s failure to engage a multidisciplinary team constitutes a breach of fiduciary duty under Delaware law.

  • The new model does not eliminate exposure to attorney‑client‑privilege challenges when non‑lawyer consultants are involved; privilege logs should clearly delineate privileged communications.

For Law Students

Courts evaluate the scope of professional services when new business models intersect with traditional legal duties. This expands the fiduciary duty to include proactive risk‑mitigation through multidisciplinary coordination. The decision is particularly relevant for the study of:

  • Corporate Governance and Fiduciary Duties

  • Securities Law and Disclosure Obligations

  • Professional Responsibility and Attorney‑Client Privilege

  • Crisis Management and Business Continuity Planning

  • Regulatory Enforcement Strategies

Comparing this development with In re Volkswagen Emissions Scandal (2016) and United States v. Theranos, Inc. (2022) shows how courts assess the interplay between internal investigations and external communications, highlighting the tension between disclosure duties and privilege.

For Businesses

  • Publicly traded firms may want to consider amending their board charters to include a crisis‑management activation clause, reducing the risk of SEC enforcement for untimely material disclosures.

  • Hospitality operators may find it useful to embed a joint legal‑PR‑cybersecurity response protocol in their emergency‑response manuals, mitigating potential state‑attorney‑general penalties for inadequate consumer‑protection practices.

  • Technology companies handling personal data may want to integrate cybersecurity experts into crisis teams to satisfy the FTC Safeguards Rule during breach notifications, avoiding civil penalties.

Key Takeaways

  • The law now treats multidisciplinary crisis‑management groups as a recognized legal service distinct from traditional advisory work.

  • Law firms must create, document, and bill for integrated crisis engagements, and counsel must embed activation triggers in client agreements.

  • Regulators can evaluate the existence and adequacy of a client’s crisis‑management structure when determining compliance with disclosure and investigation obligations.

  • The SEC’s anticipated 2027 guidance on material‑event communication is expected to codify expectations for coordinated legal‑PR responses.

References

  1. SEC

  2. Securities Exchange Act

  3. Rule 1.5 of the Model Rules on fees

  4. Delaware law

  5. attorney‑client‑privilege

  6. In re Volkswagen Emissions Scandal

  7. United States v. Theranos, Inc.

  8. FTC Safeguards Rule

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested