Corporate clients and their in-house counsel increasingly send outside firms detailed security questionnaires before they will share sensitive matters. Some run to hundreds of questions. Others attach outside counsel guidelines with specific security requirements and audit rights. For a small or mid-size firm, these requests can eat hours of partner and administrator time, and a careless answer can create a contractual commitment the firm cannot meet.
This post offers a practical approach to answering them accurately, efficiently and honestly.
Treat answers as representations
What you write may become part of the engagement. If a questionnaire says you encrypt all laptops, and one laptop is not encrypted, the firm has made a statement that is not true. Clients may rely on it, and some will check. Accuracy matters more than a perfect-looking score.
Choose the honest answer and explain context where needed. "Partially implemented, full rollout planned by the end of next quarter" is better than a false yes. Most clients are looking for candor and a credible plan rather than perfection.
Build a master answer library
Many questionnaires ask the same things in different words. The firm can save time by keeping one approved set of answers.
- Collect your last several completed questionnaires.
- Group questions by topic: access control, encryption, backups, incident response, vendor management, training, physical security, business continuity.
- Write a single reviewed answer for each topic, with the date and the person who confirmed it.
- Store supporting documents alongside, such as policies, a network diagram summary and training records.
- Review the library at least twice a year and after any significant change.
When a new questionnaire arrives, start from the library and adjust, rather than starting from scratch.
Gather the evidence
Clients may ask for proof: a policy, a penetration test summary, a certificate, or a screenshot. Have these ready:
- A written information security policy
- An incident response plan
- A backup and recovery summary
- Evidence of MFA enforcement
- Training and phishing simulation records
- A list of key vendors and how they are vetted
- A description of how client data is segregated by matter
Certificates and third-party reports, such as SOC 2 reports, may be requested of vendors, and in some cases of firms. Do not claim a certification the firm does not hold.
Watch for words that create obligations
Pay attention to absolute language.
- "All" and "always": Answer "all laptops are encrypted" only if you have verified it.
- "Within X hours": Breach notification timelines in outside counsel guidelines can be very short. Confirm your process can meet them before you agree.
- "Right to audit": Understand what access you are granting to your systems and to other clients' data.
- "Subcontractors": Know which vendors will touch the client's data and whether you can flow requirements down.
- Data return and deletion: Make sure you can actually locate and delete a client's data from backups on the schedule requested.
Where a requirement is unrealistic, negotiate. Propose language you can meet, such as notification without undue delay, instead of a fixed number of hours.
Involve the right people
A questionnaire sits at the intersection of IT, risk and business development. The person who knows the answers is often your IT administrator or managed provider, while the person who signs is a partner. Have the technical owner draft, and a partner review. If your IT provider supports you, ask for their input on questions that cover their tools.
Reference the ethics rules carefully
Clients sometimes ask whether the firm complies with applicable ethical obligations. You can mention that the firm has safeguards intended to meet Model Rule 1.6(c) and to supervise vendors and staff under Rules 5.1 and 5.3, but avoid broad legal conclusions in a questionnaire. Have the firm's general counsel or a partner review that language.
Use the questionnaire as a free gap analysis
When you notice you answered "no" to the same question for several clients, that is a signal. Track the common gaps and budget to fix them. A firm that can answer yes to MFA, tested backups, endpoint monitoring and training will move through questionnaires faster and may win work over firms that cannot.
Mistakes to avoid
- Letting an assistant fill in answers without technical review
- Copying answers from another firm's template without checking them
- Agreeing to audit terms without consulting counsel
- Failing to update the library after changes
- Sending sensitive diagrams or credentials as email attachments
Getting help
Counsel Cyber helps law firms assemble answer libraries, produce supporting evidence and review outside counsel guidelines for commitments the firm can realistically keep. If you have a questionnaire sitting on someone's desk, we are happy to take a look.