The first time a corporate client sends your firm a security questionnaire, it can feel like an audit in disguise. Sixty questions, a short deadline and a note that responses will be reviewed by the client's procurement team. Many firms respond by guessing optimistically, and that is where trouble starts.
A questionnaire answer is a representation. If you say you require multi-factor authentication for all users and later discover two partners were exempt, that discrepancy can surface at the worst possible time, such as after an incident. The goal is accuracy first, speed second.
Decide Who Owns the Process
One person should own each response from start to finish. That might be the firm administrator, an operations director or a managing partner at a smaller firm.
- Route all questionnaires to that person, rather than to whoever received the email.
- Involve IT or your managed provider for technical answers.
- Have a partner review and approve before it goes out.
- Keep a copy of every submission and the date sent.
Build an Answer Library
Most questionnaires ask the same things in different words. Create a master document with your accurate answers to common topics:
- Multi-factor authentication and password practices
- Encryption of laptops, email and stored data
- Backup frequency, location and testing
- Incident response plan and notification process
- Security awareness training frequency
- Vendor and subcontractor management
- Access controls and offboarding
- Data retention and secure disposal
- Physical security of the office
- Use of AI tools
Each time you answer a new question, add it to the library. The second questionnaire will take a fraction of the time.
Answer Honestly, Including "Partially"
An honest "partially implemented, with completion planned by the fourth quarter" is usually better received than an overstated yes. Clients that send questionnaires are used to seeing gaps. What they dislike is discovering one later.
Avoid Absolute Words
Words like "all," "always" and "never" are hard to defend. If most but not all devices are encrypted, say so, and explain the exception and the plan.
Do Not Copy Another Firm's Answers
Boilerplate from an internet template may describe controls you do not have. Every statement should be something you can demonstrate.
Gather Evidence Before You Need It
Clients sometimes follow up asking for proof. Keep these ready:
- A current written information security policy, even a short one
- Your incident response plan and contact list
- Training attendance records
- Evidence of MFA enforcement, such as a settings screenshot or report
- Backup success reports and a recent restore test
- Your cyber-insurance certificate, if the client asks for coverage details
Watch the Contract Language
Some questionnaires or outside counsel guidelines include commitments, such as notification windows after an incident or rights to audit. Have counsel review those terms. A notification period of a day or two may be tighter than your current process supports.
Use Questionnaires as a Roadmap
Every question you cannot answer well is a free list of improvements. Track them. Many firms find that three or four fixes, such as enforced MFA, tested backups and a written incident plan, resolve most of the uncomfortable answers.
Remember the Insurance Connection
Cyber-insurance applications ask similar questions, and inaccurate answers there can complicate a claim. Keeping a single, accurate source of truth helps with both. Confirm specifics with your broker and carrier.
A Short Example
Consider a hypothetical 20-attorney firm that receives its first questionnaire from a corporate client. The administrator forwards it to IT, a partner and the managed provider, and each answers a section. Nobody reconciles them, and the final document says MFA is required for all users while the backup section admits some accounts are exempt. A single owner with a review step would have caught the contradiction before it went out.
Consistency across sections matters as much as individual answers. Read the finished document once from start to finish, as the client's reviewer would, before you send it.
Counsel Cyber helps law firms build answer libraries, gather evidence and close the gaps that questionnaires reveal. If a questionnaire is sitting on your desk, we can help you respond accurately and without last-minute scrambling.