ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Security Questionnaire Red Flags: Terms That Should Prompt a Pause

Some questionnaire questions and contract clauses create obligations beyond what a firm can deliver. Learn which terms to flag for review before you sign.

3 min readBy Counsel Cyber Team

Most security questionnaires from clients are routine. A few contain questions or attached terms that go beyond a request for information and quietly create contractual commitments. Spotting them before you sign saves headaches later.

This post highlights terms that deserve a pause and a conversation with counsel. It is general information, not legal advice.

Why the Fine Print Matters

Questionnaires are often attached to outside counsel guidelines, master services agreements or engagement terms. Answers can become representations or warranties, and some include audit rights and breach obligations. A firm that answers "yes" casually can find itself bound to something it cannot deliver.

Terms to Flag

Absolute language

Questions or clauses that use words like "always," "all," "never," or "guarantee" are difficult to satisfy fully. "Do you encrypt all data at all times?" deserves an honest answer about where encryption applies and where it does not, rather than a quick yes.

Specific certifications

Some clients require SOC 2, ISO 27001 or similar certifications. These are significant undertakings that a small firm may not hold. Do not claim an equivalent unless it is accurate. Offer alternatives such as a summary of your controls or an independent assessment, and ask whether the client will accept them.

Short breach notification windows

Many agreements require notice of a security incident within a stated number of hours or days. Check whether you can realistically meet it, how the clock starts, and what counts as an incident. Align it with your incident response plan and insurance notice requirements. ABA Formal Opinion 483 discusses duties after a data breach, and your state's laws may impose others.

Audit and inspection rights

Clauses that allow clients to inspect your premises or systems at any time can be disruptive and may conflict with obligations to other clients. Seek reasonable limits, such as notice, scope, frequency and confidentiality terms.

Unlimited or uncapped liability

Indemnification and liability provisions tied to security incidents can be significant. Counsel and your insurer should review these. Check whether your cyber and professional liability policies would respond.

Data location and subprocessors

Requirements to keep data in a specific country, or to disclose and obtain approval of every vendor, can affect your choice of cloud tools. Confirm that your current services comply and that you can track changes.

Return and deletion deadlines

Clients may require return or destruction of data within a set time after the matter ends. Compare it with your own retention obligations and backup cycles. Backups may keep copies for a time after deletion, so address this openly.

Restrictions on AI

Some clients prohibit using generative AI on their matters, or require approval. Make sure you can comply, and that staff know which clients impose restrictions. ABA Formal Opinion 512 addresses client communication and consent around AI tools.

Personnel and background checks

Requirements for background screening or specific training may be reasonable but need to be applied consistently, including for IT vendors with access.

Requirements that bind your vendors

If a client's terms require that third parties meet certain standards, check what your IT provider and cloud services have promised you. You may not be able to flow down terms your vendors will not accept.

How to Respond

  1. Read the attachments, not just the questionnaire itself
  2. Flag unusual terms and send them to counsel
  3. Be honest about current capabilities, with remediation dates where appropriate
  4. Propose alternatives when a requirement is unrealistic
  5. Get agreements in writing, including any exceptions
  6. Track commitments in a central register so operations can keep them

Keep a Commitments Register

Create a simple spreadsheet listing each client, the security commitments you made, review dates, and the owner. When controls change, check the register. This also prevents repeated surprises at renewal.

Say Yes Carefully

Winning a client matters, and refusing a reasonable request can cost business. The aim is not to resist security requirements, but to commit to what you can truly deliver and monitor.

How Counsel Cyber Helps

Counsel Cyber helps law firms interpret technical requirements in client questionnaires and guidelines, identify gaps against current practice, and plan remediation. Share a questionnaire with us and we will tell you which items need work.