A new corporate client sends a 150-question security questionnaire the same week the engagement letter is signed. The general counsel's team wants answers in ten days. Somebody at the firm, often the office manager or a partner who drew the short straw, starts hunting through old emails for answers. Sound familiar?
Client security reviews have become a normal part of representing institutional clients, and they are not going away. The firms that handle them well treat them as a repeatable process rather than a fire drill.
Why clients ask
Clients are responsible for protecting their own data, and that includes data they hand to outside counsel. Their vendor-risk programs, insurers and regulators push them to verify. Questionnaires are the cheapest way to do it. Some clients also add audit rights, minimum control requirements or breach notification deadlines to outside counsel guidelines, so read those terms carefully.
Step 1: build an answer library
Create a single document, or a simple spreadsheet, that holds your standard answers to the questions that appear in almost every questionnaire. Group them by topic:
- Governance: who is responsible for security, written policies, training
- Access control: multi-factor authentication, password standards, administrator access, offboarding
- Data protection: encryption in transit and at rest, backups, retention and destruction
- Network and endpoints: patching, endpoint protection, monitoring
- Email security: filtering, spoofing protection
- Incident response: written plan, testing, notification process
- Vendors: how you evaluate and monitor third parties
- Physical security and remote work
For each answer, note the evidence behind it, the owner who confirmed it and the date. Update it at least twice a year.
Step 2: answer truthfully and precisely
This is the rule that matters most. Never write "yes" to a control that is partly deployed. If MFA covers email but not every application, say so, and describe your plan. Overstated answers are a liability: they can breach contractual representations and cause trouble if a later incident reveals the gap. Clients generally respond better to an honest answer with a timeline than to a perfect score that unravels on audit.
Step 3: have a designated responder
Assign one person to own questionnaires, with IT and a partner available to review. A single owner keeps answers consistent. Inconsistent answers across clients are a red flag to sophisticated reviewers.
Step 4: prepare standard supporting documents
Many questionnaires ask for the same attachments. Keep current versions ready:
- A summary of your information security policy
- Your incident response plan overview
- Evidence of staff training
- A description of your backup and recovery approach
- A copy of your cyber insurance certificate, when you are comfortable sharing it
- A list of subprocessors and key vendors
Check what you are willing to share. Detailed network diagrams or penetration-test results are sensitive, so prefer summaries and a call with the client's security team if needed.
Step 5: know when to push back
Some requests are unreasonable for a small firm, such as demands for certifications you do not hold or on-site audits at short notice. Ask about the purpose, offer alternatives, such as a call or a summary of controls, and involve a partner. Negotiation is normal.
Step 6: close the loop internally
When a questionnaire exposes a gap, log it. The same gap will come up again. Assign an owner and deadline, and treat the questionnaire as a free assessment of your weak points.
Ethics connection
ABA Model Rule 1.6(c) addresses reasonable efforts to prevent unauthorized access to client information, and Rule 1.4 addresses communicating with clients. Responding candidly to client security inquiries fits both. For your jurisdiction, confirm any additional requirements with your state bar.
Common mistakes
- Copying answers from a vendor's marketing page
- Letting different staff answer different sections without review
- Promising controls you intend to implement but have not scheduled
- Taking weeks to respond, which signals disorganization
How we help
Counsel Cyber maintains questionnaire answer libraries for law firm clients and can help you complete incoming requests accurately, including identifying gaps worth fixing first. If a questionnaire is sitting on your desk, send it our way and we will talk through it.