The first security questionnaire a law firm receives from a corporate client usually lands in the managing partner's inbox with a two-week deadline and several hundred questions. The temptation is to forward it to whoever seems most technical and hope the answers come back as "yes." That approach creates real risk, because every answer you submit becomes a representation your client may rely on, and may later hold you to.
The better approach is to treat questionnaires as a repeatable process with a single owner, a source of truth, and a review step. Here is how to set that up.
Start With an Owner and an Intake Process
Pick one person to own every questionnaire. At a small firm that may be the firm administrator; at a larger one, an IT lead or compliance manager. That person logs each request, tracks the due date, and decides who must contribute. Without a single owner, answers drift between versions and contradict each other.
Log who sent it, the due date, the format, and who approved the final answers.
Build an Answer Library
Most questionnaires ask the same twenty or thirty things in different words: Do you require multi-factor authentication? How do you encrypt data at rest and in transit? How quickly do you patch? Do you have an incident response plan? Do you train staff? Who are your critical vendors?
Write a clear, honest answer to each recurring question once, have it reviewed, and store it in a shared document. Each time a new questionnaire arrives, you start from that library instead of from scratch. Record the date each answer was last verified so stale answers do not creep back in.
Answer What Is True Today
This is the rule that matters most. Answer based on what is actually in place across the whole firm, not what is planned, not what is true for most users, and not what the vendor's marketing page says the product can do.
Watch for the common traps
- Partial controls reported as complete. MFA enabled for email but not for the document management system is not "MFA enabled everywhere."
- Policies that exist only on paper. If the written incident response plan has never been read by staff or tested, say so, or answer with the real status.
- Plans described as present tense. "We are rolling out endpoint monitoring next quarter" is not a yes.
- Vendor claims repeated without checking. Your cloud provider's certifications cover the provider, not your configuration.
When the honest answer is "partially" or "not yet," most clients respond better to a candid answer with a remediation date than to a perfect-looking form that later turns out to be wrong. Many clients mainly want to see that the firm understands its gaps and manages them.
Collect Evidence Before You Need It
Clients increasingly ask for proof, not just answers. Keep a folder of supporting material you can share, redacting where needed:
- Your written information security policy and incident response plan
- A summary of your backup schedule and your last restore test result
- Screenshots or reports showing MFA enforcement and endpoint protection coverage
- Security awareness training completion records
- Your cyber insurance certificate, if the client requests it
- A current list of critical vendors and what data each one touches
Ask your IT provider to generate these reports on a schedule so they are fresh when a request arrives.
Review Before You Send
Have a second person read the finished questionnaire, ideally an attorney who understands the contractual weight of the representations. The ABA has long emphasized lawyers' duty to safeguard client information under Model Rule 1.6(c) and to supervise nonlawyer assistance under Model Rule 5.3, so clients reasonably expect that someone with authority has looked at these answers. Check that the answers do not contradict your engagement letter, your cyber insurance application, or earlier questionnaires.
Keep the Process Moving
Review your answer library at least twice a year and after any major change, such as a new document management platform or a change in IT provider. Track how long each questionnaire takes; if the process eats more than a few hours per request, that is a sign your documentation needs work.
How Counsel Cyber Can Help
Counsel Cyber helps law firms build their answer library, verify controls against what is actually deployed, and prepare evidence packages before the next client request arrives. If a questionnaire is sitting in your inbox, we are glad to review it with you and help you answer accurately.