ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Client Security Questionnaire Answers: Owners, Evidence, Review

Corporate clients send long security questionnaires and expect accurate answers. Build a reusable answer library so each response is faster and more consistent.

3 min readBy Counsel Cyber Team

Corporate clients, especially in healthcare, finance, energy and technology, increasingly send their outside law firms security questionnaires before engaging them or at renewal. They may run to a hundred questions or more, arrive as spreadsheets or portal forms and ask about everything from encryption to employee background checks.

Many firms answer each one from scratch, pulling the IT provider and the managing partner away from other work, and giving slightly different answers each time. A better approach treats questionnaires as a repeatable process with a maintained library of vetted answers.

Why consistency and accuracy matter

A questionnaire response is a representation to a client. If you state that you encrypt all laptops or test backups quarterly and that is not accurate, you create a problem for the relationship and potentially for your professional standing. Clients may also incorporate your answers into contracts. Treat the answers as commitments.

Step 1: Build a master answer library

Create one document, spreadsheet or knowledge base containing approved answers to common questions, grouped by topic.

  • Governance: security policies, who is responsible, how often policies are reviewed.
  • Access control: MFA, password requirements, role-based access, access reviews.
  • Data protection: encryption in transit and at rest, data retention and secure disposal.
  • Endpoint and network security: patching, endpoint protection, firewalls, monitoring.
  • Email security: filtering, phishing protection and wire verification procedures.
  • Backup and recovery: frequency, location, immutability, testing.
  • Incident response: plan, testing, notification process.
  • Vendor management: how you evaluate third parties.
  • Personnel: background checks, confidentiality agreements, security training.
  • Physical security: office access, visitor controls, device handling.
  • Business continuity and insurance.
  • AI use: approved tools and safeguards.

For each answer, record the supporting evidence and the date last verified.

Step 2: Assign owners

Each topic needs an owner who confirms accuracy. IT confirms technical controls, HR confirms personnel items and the administrator confirms policy and training. One person coordinates the whole response and tracks deadlines.

Step 3: Gather evidence once

Clients may ask for documents such as policy summaries, training records or penetration test summaries. Keep a folder of current, approved materials. Decide in advance what you will share and under what confidentiality terms. Many firms provide summaries rather than full internal documents.

Step 4: Answer honestly, including "no" and "partially"

Questions are often phrased in ways that make gaps feel embarrassing. Resist the urge to stretch. If you do not have a control, say so and explain compensating measures or your plan and timeline. Clients often accept a candid answer with a plan better than a claim that falls apart in an audit. Avoid absolute words such as "always" unless true.

Step 5: Review before sending

Have a second person read the draft for accuracy and consistency with previous answers. A partner should sign off on anything involving commitments, such as breach notification timeframes or right-to-audit clauses.

Step 6: Track and learn

Keep a log of questionnaires received, who sent them, what they asked, what you committed to and any follow-up requests. Patterns will emerge. If several clients ask about multi-factor authentication or backup testing and you are weak there, that tells you where to invest.

Watch for contract commitments

Questionnaires and outside counsel guidelines may include obligations beyond the answers, such as notifying the client within a set number of hours after an incident, restrictions on subcontractors or limits on AI use. Make sure the person who signs understands them, and keep a register of client-specific commitments so staff can honor them.

Common mistakes

  • Different people giving conflicting answers to different clients.
  • Copying an answer from last year without checking whether it is still true.
  • Promising certifications the firm does not hold.
  • Sending sensitive internal documents without confidentiality protections.
  • Waiting until the deadline and rushing.

The overlap with insurance

Many questionnaire topics mirror those on a cyber insurance application. Keep both aligned, so what you tell your carrier matches what you tell clients. A single evidence library serves both.

Standards as a guide

Some clients ask whether you align with a framework. NIST Cybersecurity Framework 2.0 is a common reference, and mapping your controls to its functions can help you answer questions coherently. Only claim alignment if you can support it, and be precise about what you mean.

Where we help

Counsel Cyber helps law firms assemble answer libraries, verify controls and respond to client questionnaires. If you have a pending request, we can review it with you and help you answer accurately.