ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Answering Client Security Questionnaires Without the Scramble

Corporate clients increasingly send security questionnaires to their law firms. Build a reusable answer library and a review process so each one gets easier.

3 min readBy Counsel Cyber Team

Corporate clients, insurers and financial institutions increasingly want proof that their outside counsel protects confidential data. That proof often arrives as a spreadsheet with 100 or more questions and a deadline measured in days. Firms that handle each one from scratch spend partner and administrator hours repeating the same research.

A better approach is to treat questionnaires as a recurring process, with a vetted set of answers you maintain and update. Here is how.

What these questionnaires usually cover

Formats vary, and some clients use their own forms while others use common frameworks, but typical sections include:

  • Governance: written security policies, a named person responsible, board or partner oversight
  • Access control: MFA, least-privilege access, joiner-mover-leaver processes
  • Data protection: encryption in transit and at rest, data retention and destruction
  • Network and endpoint security: firewalls, endpoint detection, patching
  • Email security and fraud prevention
  • Vendor management
  • Incident response and breach notification
  • Backup and disaster recovery
  • Physical security
  • Employee training and background checks
  • Use of AI tools with client data

Some larger clients also ask for evidence, such as a penetration test summary, policies, or a third-party attestation report.

Step 1: Build an answer library

Create a document or spreadsheet containing approved, accurate responses to the most common questions. Each entry should include:

  1. The standard answer, written in plain, specific language
  2. The evidence that supports it (policy name, screenshot, report)
  3. The owner who verifies it
  4. The date last reviewed

Specific answers are better than vague ones. "We enforce MFA on all email and remote access accounts" is clearer than "We follow industry best practices."

Step 2: Assign a single point of contact

Route all questionnaires to one person, usually the firm administrator or a designated partner, who coordinates with IT. This prevents inconsistent answers from different people and ensures that a partner reviews anything with legal significance.

Step 3: Answer honestly, including "not yet"

Clients and insurers generally prefer an honest gap with a remediation plan to an inaccurate yes. An overstatement can become a contractual or reputational problem later. If a control is partial, say so and describe the timeline for improvement. Keep a record of commitments so you actually deliver on them.

Step 4: Know what you are agreeing to

Questionnaires sometimes arrive attached to outside counsel guidelines or contract terms that include specific security obligations, such as breach notification within a set number of hours or the right to audit. Have a partner or your general counsel review those commitments before signing. They are not just IT questions.

Step 5: Track every request

Keep a log of which client sent what, when it was answered, who approved it, and what commitments were made. This helps you notice patterns. If three clients ask about the same missing control, that is a strong reason to prioritize it.

Step 6: Improve based on the gaps

Use questionnaires as free feedback. Recurring themes often point to the controls clients care most about. Review the log twice a year and add the top gaps to your roadmap.

Evidence worth keeping ready

  • Written information security policy and incident response plan
  • Acceptable use and AI use policies
  • Training completion records
  • Summary of the most recent vulnerability scan or penetration test
  • Backup restore test results
  • Vendor list and key contract terms
  • Cyber insurance certificate, if clients ask

Common mistakes

  • Copying last year's answers without verifying they are still true
  • Letting an administrator answer technical questions alone
  • Promising controls in the questionnaire that are not in place
  • Sending confidential internal documents without a nondisclosure agreement
  • Forgetting to update answers after a major system change

Support from Counsel Cyber

We help firms build answer libraries and complete the technical portions of client security questionnaires accurately. If you are staring at a spreadsheet with a deadline, reach out and we can help you through it and prepare for the next one.