A corporate client or a new institutional engagement arrives with a spreadsheet of two hundred security questions. The managing partner forwards it to IT. IT forwards it to the administrator. Three weeks later someone fills it out from memory, and nobody can later say who verified what.
Client security questionnaires are not going away. Corporate legal departments, financial institutions, healthcare organizations and insurers all want to know how outside counsel protects their data. The good news is that most questionnaires ask variations of the same fifty or so questions. A firm that prepares once can respond quickly and consistently.
Why accuracy matters more than speed
It is tempting to answer every question "yes" to win the work. Resist that. Questionnaire answers are often incorporated into outside counsel guidelines or the engagement agreement. A statement that MFA is enforced everywhere, when it is not, can become a contract problem later. If your firm cannot truthfully say yes, say "in progress" with a date or describe your compensating control.
Build the answer library
Create a single document, or a simple spreadsheet, with standard questions and approved answers. Include the date each answer was verified and the person who verified it.
Core topics to cover
- Governance. Who is responsible for security, whether you have written policies and how often they are reviewed.
- Access control. MFA, role-based access, onboarding and offboarding, and privileged account handling.
- Data protection. Encryption of data at rest and in transit, email encryption options, secure file sharing and data retention.
- Endpoint and network security. Endpoint detection and response, firewalls, patching cadence and mobile device management.
- Monitoring and incident response. Who watches for threats, your written response plan and how clients would be notified.
- Backup and recovery. Frequency, offsite and immutable copies, and restore testing.
- Vendors. How you vet third parties who access client data.
- People. Security awareness training, background checks and confidentiality obligations.
- Physical security. Office access, visitor handling and device disposal.
- Business continuity. Plans for outages, remote work and disasters.
Assemble supporting evidence
Clients may ask for documents beyond the form. Keep these in one folder, kept current:
- Security policy summary or full policies.
- Network diagram, redacted as appropriate.
- Most recent training completion report.
- Backup restore test records.
- Insurance certificate showing cyber coverage.
- Any independent assessment or penetration test summary, if you have one.
Not every firm has a formal third-party audit. If you do not, be candid, and describe what you do have. Many clients accept honest answers backed by good practices.
Decide what you will not share
Detailed network diagrams, vulnerability scan results and incident histories may be sensitive. Decide in advance what you will share, under what confidentiality terms and in what format, such as a call or a summary rather than a file. Having a standard position saves debate every time.
Create a response workflow
- Intake. One person receives all questionnaires and logs them with a due date.
- Draft. Pull answers from the library, flagging new questions.
- Verify. The IT lead confirms technical answers and a partner reviews anything that makes a commitment.
- Submit. Send the final version and save a copy.
- Update. Add new questions and approved answers back into the library.
Watch for contractual commitments
Some questionnaires include statements like "the vendor agrees to notify within 24 hours of a breach." Those are commitments, not information requests. Route them to the responsible partner and compare them with obligations you already have under law, your insurance policy and other client agreements. Clients may also reference ABA Formal Opinion 483, which discusses lawyers' obligations after a data breach, but your actual duties come from your jurisdiction and your agreements.
Use gaps as a roadmap
Every question you cannot answer well is a free assessment of what clients want. If three questionnaires in a row ask about immutable backups or security awareness training, that is a sign to invest there. Tracking gaps turns a chore into a planning tool.
Where we come in
Counsel Cyber helps firms build the answer library, gather evidence and complete questionnaires accurately. If you have a pending request or want a library ready before the next one arrives, we can help you prepare it.