Corporate clients increasingly send outside counsel security questionnaires before engagement and again at renewal. They range from a dozen questions to several hundred, and many arrive with a short deadline. Firms that handle them ad hoc burn days of partner and IT time, and sometimes give inconsistent answers to different clients.
A repeatable process turns questionnaires from a fire drill into a routine task, and it protects the firm from a worse problem: answers that overstate what is actually in place.
Why accuracy matters more than speed
A completed questionnaire is a representation. If a client later learns that a statement was untrue, such as "MFA is enforced on all accounts" when it is not, it can damage the relationship and may create contractual exposure. Never answer aspirationally. If something is in progress, say so and give a realistic date.
Build an answer library
Most questionnaires ask about the same dozen or so topics. Create a master document with approved answers, supporting evidence, and an owner for each topic.
Typical topics
- Governance: who is responsible for security, and what policies exist
- Access control: MFA, password standards, privileged accounts, offboarding
- Data protection: encryption in transit and at rest, data retention and disposal
- Network and endpoint security: patching, endpoint detection, firewall, remote access
- Email security: filtering, anti-spoofing, impersonation protection
- Backup and recovery: frequency, off-site copies, testing, recovery objectives
- Incident response: written plan, testing, notification procedures
- Vendor management: how you review third parties
- Training: frequency and content of security awareness
- Insurance: whether you carry cyber coverage, and limits if you choose to share
- Physical security: office access and device handling
- AI use: policy and approved tools
For each, write a clear, factual paragraph and note which document or screenshot supports it. Review the library at least twice a year and after any significant change.
Create a process
- Intake. Route every questionnaire to one person, such as the administrator or a designated partner.
- Triage. Check the deadline and the scope. Can you offer an alternative, such as a standard security summary or a call, if the questionnaire is excessive?
- First pass. Fill in answers from the library.
- Technical review. Have IT or your security advisor verify anything new or changed.
- Legal review. A partner reads the answers and any attached contractual language. Some questionnaires embed obligations such as audit rights or specific notification timelines that deserve attention.
- Sign-off and delivery. Keep a copy and note any commitments made.
- Update the library with anything new.
Evidence to keep ready
- Current written security policies and an incident response plan
- MFA enforcement screenshots or reports
- Endpoint protection coverage reports
- Backup test records
- Training completion records
- Vendor register with review dates
- A recent independent assessment, if you have one
Having these ready also helps with cyber insurance applications, which overlap heavily with client questionnaires.
Handling difficult questions
Questions you cannot yet answer yes to
Do not fudge. Say what you do have, name the gap, and give the plan. Many clients value candor and may accept a remediation timeline.
Requests for penetration test reports or audit rights
Decide in advance what you will share. Some firms provide an executive summary of an assessment rather than the full report. Discuss with counsel and your IT provider.
Requests for certifications
Some clients ask whether you hold a particular certification. If you do not, explain the controls you use and, if appropriate, the framework you align to, such as NIST CSF 2.0, without claiming certification you have not earned.
Contract language buried in the form
Read it. Obligations on breach notification windows, data return, and subcontractors can differ from your standard practice.
Avoid these mistakes
- Copying last year's answers without checking they are still true
- Letting different people answer for different clients with different language
- Skipping IT review because the deadline is near
- Promising controls you plan to implement without a date or budget
- Forgetting to tell clients when something materially changes
Use the work to improve
Each questionnaire reveals what clients expect. Track recurring gaps and use them to justify security investments. If three clients ask about security awareness training and you have none, you have a business case.
Where we can help
Counsel Cyber helps law firms build answer libraries, gather evidence, and respond to client questionnaires accurately and quickly. If you have one sitting in your inbox right now, we can help you work through it.