Free Resource · guide

How Should a Law Firm Answer a Client Security Questionnaire?

Answer a client security questionnaire honestly, specifically, and with evidence behind every yes. Each question maps to a real control, MFA, encryption, endpoint detection, tested backups, an incident response plan, and a good answer names the control, states how broadly it's deployed, and points to documentation that proves it. Firms that can't answer yet should say so, close the gaps, and answer from a documented program rather than guessing.

A client sends over a spreadsheet with sixty security questions and a two-week deadline. Does your firm enforce multi-factor authentication? Is client data encrypted at rest? Do you have a tested incident response plan? Somewhere around question five, the honest internal answer becomes “we don’t know,” and the questionnaire lands on the managing partner’s desk with an engagement, or a renewal, riding on it.

If that’s roughly where you are, you’re in the most common position there is. Here’s why these questionnaires are arriving, what they’re really asking, what separates a good answer from a disqualifying one, and how a firm gets from “can’t answer” to a documented program.

Why is a client asking a law firm about security?

Because to your client’s security team, your firm is a vendor. Corporate vendor risk programs assess every outside party that touches company data, and outside counsel touches the most sensitive data the company has: deal terms, disputes, investigations, employee matters, intellectual property. A firm holding that material with unknown security is exactly the gap those programs exist to find, so counsel gets the same questionnaire the software vendors get, and sometimes a stricter one.

Attackers reached the same conclusion years ago. A law firm concentrates many clients’ most sensitive information behind one perimeter, often with lighter defenses than any of those clients run themselves. The questionnaires are the corporate world’s response, and they now show up before engagements, during outside counsel guideline updates, and at renewal. Cyber insurers ask nearly identical questions on applications, which turns out to be good news, covered below.

There’s also a professional backdrop. ABA Model Rule 1.1’s duty of competence is widely understood to extend to the technology lawyers use, and Rule 1.6 calls for reasonable efforts to prevent unauthorized access to client information. That’s general ethics framing, not legal advice, and what your bar expects is a question for ethics counsel. But it means the questionnaire isn’t asking for anything beyond what the profession already points firms toward.

What questions show up on nearly every questionnaire?

Formats vary, length varies, but the core questions barely change from one client to the next. Each one maps to a specific control and a specific piece of evidence.

Questionnaire itemThe control behind itThe evidence a good answer points to
Multi-factor authenticationMFA enforced on email, remote access, and key systems for all usersTenant policy export or enforcement report showing coverage
Encryption at rest and in transitFull-disk encryption on laptops and servers; TLS for data in motionDevice encryption status report from management tooling
Endpoint protectionEDR (endpoint detection and response) on every device, monitoredDeployment report and the name of who watches the alerts
Email securityFiltering, anti-phishing controls, and SPF, DKIM, and DMARCConfiguration summary and DMARC policy record
Backup and recoveryBackups of matter files, email, and key systems, tested by restoreBackup schedule plus dated results of an actual test restore
Incident response planA written plan naming roles, contacts, and first stepsThe document itself, with its last review date
Security awareness trainingRecurring training and phishing simulation for all staffCompletion records and simulation results
Access control and offboardingRole-based access, unique accounts, prompt removal at departureAccess review records and a documented offboarding checklist

Notice the pattern in the third column. Every strong answer ends in something you can attach or produce on request. That’s the real difference between a firm that has security and a firm that hopes it does.

What does a good answer look like, and what disqualifies a firm?

Take the MFA question. A disqualifying answer looks like “Yes” with nothing behind it, or “We use passwords and are careful,” or the classic, “our IT company handles that.” A good answer looks like: “Yes. MFA is enforced for all users on email, remote access, and our document management system through our identity platform. Enforcement reporting is available on request.” Specific scope, specific mechanism, evidence offered.

The reviewer reading your response evaluates dozens of these. Vague answers, blank answers, and answers that dodge the question all get scored the same way: as a no. And a pattern of them can end the conversation, because the reviewer’s job is to flag risk, not to give a longtime firm the benefit of the doubt.

“Our IT company handles that” deserves its own paragraph, because firms reach for it constantly and it never works. The client is assessing your firm’s handling of their data. Delegating the work of security to a provider is normal and sensible. Not knowing what that provider actually does with your client’s files is the finding. The answer has to come from the firm, in the firm’s voice, even when a provider drafted it, and the firm has to be able to stand behind it if the client’s security team asks a follow-up on a call.

Why do honest answers beat aspirational ones?

When a truthful answer is no, the temptation is to answer “yes” on the theory that the control is coming soon anyway. Resist it. The questionnaire is a written representation to a client, it gets kept, and if an incident later shows the control wasn’t in place when you said it was, you’ve converted a security gap into a misrepresentation, made to the client, in writing, about the protection of their own information. That conversation is far worse than any conversation about a gap.

The honest version is stronger than firms expect: “Not yet fully deployed. EDR rollout is in progress across all firm devices with completion targeted for [date].” Vendor risk reviewers read hundreds of responses, and a candid in-progress answer with a date signals a firm that knows its environment. Many clients will accept a remediation timeline. Very few will forgive a false yes.

The same logic applies with more force to cyber insurance. Applications ask these same questions, MFA, EDR, backups, email authentication, incident response, and answers there are representations to your carrier. The efficient path is one program: build the controls once, keep the evidence current, and the client questionnaire, the insurance application, and next year’s renewal all draw from the same file.

How does a firm get from “can’t answer” to a documented program?

The questionnaire on your desk is really an inventory request, so start with the inventory: what controls actually exist today, on which devices and accounts, with what proof. Most firms discover a mix, some controls in place but undocumented, some partially deployed, some absent. A structured security risk assessment gets you that picture quickly and gives you honest language for the questionnaire in front of you, including truthful in-progress answers where needed.

Then close the gaps in order of impact. MFA enforcement and encryption verification usually come first because they’re fast and they anchor nearly every questionnaire. EDR deployment, email authentication, and tested backups follow. The written pieces, incident response plan, offboarding procedure, training program, get built alongside, because “written and dated” is what turns a practice into an answer.

The step firms skip is the one that matters most for the next questionnaire: keeping the evidence current. Controls drift, staff change, and a report from two years ago proves little. A managed security program maintains the controls and regenerates the proof continuously, so the next questionnaire, and there will be a next one, becomes an afternoon of assembly instead of a two-week emergency.

This is where Braintek fits. We’ve supported Texas businesses since 2002 with local teams in Houston and DFW, running fully managed IT for firms of roughly 10 to 50 people and co-managed support for larger firms. Our managed cybersecurity service includes both halves of this problem: implementing the controls and producing the documentation and evidence for client questionnaires and insurance applications, as part of the service rather than a billable surprise when the spreadsheet arrives. The law firm page covers how that looks for a practice day to day.

If a questionnaire is sitting on your desk right now, schedule a discovery call and bring it. Fifteen minutes is usually enough to tell you which questions you can already answer, which ones need work, and what a realistic timeline looks like, before the client’s deadline decides it for you.

Staring at a questionnaire you can't answer?

Send us a note about your firm and the questionnaire on your desk. We'll map each question to what's actually in place, close the gaps that matter, and produce the documentation you hand to the client, with the same evidence ready for your next cyber-insurance renewal.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

Why did our client send a security questionnaire to a law firm?

Because their vendor risk program treats outside counsel as a vendor, and often as one of the highest-risk vendors on the list. Your firm holds their contracts, disputes, deal terms, and personnel matters, frequently with less security infrastructure than their other suppliers. Corporate security teams know that, and so do attackers, which is why the questionnaires keep coming.

Can we just answer "our IT company handles that"?

No. The client is assessing your firm, not your vendor, and that answer tells them the firm doesn't know its own security posture, which is itself a red flag. A workable answer names the control, states how it's deployed across the firm, and identifies who operates it. Your IT provider should supply that language and the evidence behind it, but the firm has to be able to stand behind the answer.

What if the honest answer to a question is no?

Say no, and say what you're doing about it. A no with a remediation date reads as a firm that knows its posture and is closing a gap. A yes that turns out to be false reads as misrepresentation, and if an incident later contradicts an answer you gave in writing, the questionnaire becomes evidence against you. Clients keep these documents.

How fast can a firm go from "can't answer" to "can answer"?

It depends on the gaps. Some controls, like enforcing MFA across the firm, can be deployed in days. Others, like a tested incident response plan or a trained staff, take longer to do honestly. Most firms we work with can answer the common questions credibly within a few months, and can give truthful in-progress answers almost immediately, which most clients accept.

Are these the same questions our cyber-insurance application asks?

Largely, yes. Insurance applications ask about MFA, endpoint detection, backups, email security, and incident response in nearly the same terms, and a misstatement there can jeopardize coverage when you need it. Build the controls and the evidence once and you've answered the client questionnaire, the insurance application, and the renewal after that.

Does answering these questionnaires connect to our ethical duties?

There's a general backdrop worth knowing. ABA Model Rule 1.1's competence duty is widely understood to include the technology lawyers use, and Rule 1.6 calls for reasonable efforts to prevent unauthorized disclosure of client information. What any particular bar requires is a question for your ethics counsel, but the controls a questionnaire asks about are the same reasonable efforts that framing points to.

Will Braintek fill the questionnaire out for us?

We do it with you. We map each question to the controls in your environment, draft accurate answers, and attach the evidence, and where a truthful answer isn't good enough yet, we tell you and give you the plan and timeline to fix it. What we won't do is help a firm claim controls that aren't in place.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.