A client sends over a spreadsheet with sixty security questions and a two-week deadline. Does your firm enforce multi-factor authentication? Is client data encrypted at rest? Do you have a tested incident response plan? Somewhere around question five, the honest internal answer becomes “we don’t know,” and the questionnaire lands on the managing partner’s desk with an engagement, or a renewal, riding on it.
If that’s roughly where you are, you’re in the most common position there is. Here’s why these questionnaires are arriving, what they’re really asking, what separates a good answer from a disqualifying one, and how a firm gets from “can’t answer” to a documented program.
Why is a client asking a law firm about security?
Because to your client’s security team, your firm is a vendor. Corporate vendor risk programs assess every outside party that touches company data, and outside counsel touches the most sensitive data the company has: deal terms, disputes, investigations, employee matters, intellectual property. A firm holding that material with unknown security is exactly the gap those programs exist to find, so counsel gets the same questionnaire the software vendors get, and sometimes a stricter one.
Attackers reached the same conclusion years ago. A law firm concentrates many clients’ most sensitive information behind one perimeter, often with lighter defenses than any of those clients run themselves. The questionnaires are the corporate world’s response, and they now show up before engagements, during outside counsel guideline updates, and at renewal. Cyber insurers ask nearly identical questions on applications, which turns out to be good news, covered below.
There’s also a professional backdrop. ABA Model Rule 1.1’s duty of competence is widely understood to extend to the technology lawyers use, and Rule 1.6 calls for reasonable efforts to prevent unauthorized access to client information. That’s general ethics framing, not legal advice, and what your bar expects is a question for ethics counsel. But it means the questionnaire isn’t asking for anything beyond what the profession already points firms toward.
What questions show up on nearly every questionnaire?
Formats vary, length varies, but the core questions barely change from one client to the next. Each one maps to a specific control and a specific piece of evidence.
| Questionnaire item | The control behind it | The evidence a good answer points to |
|---|---|---|
| Multi-factor authentication | MFA enforced on email, remote access, and key systems for all users | Tenant policy export or enforcement report showing coverage |
| Encryption at rest and in transit | Full-disk encryption on laptops and servers; TLS for data in motion | Device encryption status report from management tooling |
| Endpoint protection | EDR (endpoint detection and response) on every device, monitored | Deployment report and the name of who watches the alerts |
| Email security | Filtering, anti-phishing controls, and SPF, DKIM, and DMARC | Configuration summary and DMARC policy record |
| Backup and recovery | Backups of matter files, email, and key systems, tested by restore | Backup schedule plus dated results of an actual test restore |
| Incident response plan | A written plan naming roles, contacts, and first steps | The document itself, with its last review date |
| Security awareness training | Recurring training and phishing simulation for all staff | Completion records and simulation results |
| Access control and offboarding | Role-based access, unique accounts, prompt removal at departure | Access review records and a documented offboarding checklist |
Notice the pattern in the third column. Every strong answer ends in something you can attach or produce on request. That’s the real difference between a firm that has security and a firm that hopes it does.
What does a good answer look like, and what disqualifies a firm?
Take the MFA question. A disqualifying answer looks like “Yes” with nothing behind it, or “We use passwords and are careful,” or the classic, “our IT company handles that.” A good answer looks like: “Yes. MFA is enforced for all users on email, remote access, and our document management system through our identity platform. Enforcement reporting is available on request.” Specific scope, specific mechanism, evidence offered.
The reviewer reading your response evaluates dozens of these. Vague answers, blank answers, and answers that dodge the question all get scored the same way: as a no. And a pattern of them can end the conversation, because the reviewer’s job is to flag risk, not to give a longtime firm the benefit of the doubt.
“Our IT company handles that” deserves its own paragraph, because firms reach for it constantly and it never works. The client is assessing your firm’s handling of their data. Delegating the work of security to a provider is normal and sensible. Not knowing what that provider actually does with your client’s files is the finding. The answer has to come from the firm, in the firm’s voice, even when a provider drafted it, and the firm has to be able to stand behind it if the client’s security team asks a follow-up on a call.
Why do honest answers beat aspirational ones?
When a truthful answer is no, the temptation is to answer “yes” on the theory that the control is coming soon anyway. Resist it. The questionnaire is a written representation to a client, it gets kept, and if an incident later shows the control wasn’t in place when you said it was, you’ve converted a security gap into a misrepresentation, made to the client, in writing, about the protection of their own information. That conversation is far worse than any conversation about a gap.
The honest version is stronger than firms expect: “Not yet fully deployed. EDR rollout is in progress across all firm devices with completion targeted for [date].” Vendor risk reviewers read hundreds of responses, and a candid in-progress answer with a date signals a firm that knows its environment. Many clients will accept a remediation timeline. Very few will forgive a false yes.
The same logic applies with more force to cyber insurance. Applications ask these same questions, MFA, EDR, backups, email authentication, incident response, and answers there are representations to your carrier. The efficient path is one program: build the controls once, keep the evidence current, and the client questionnaire, the insurance application, and next year’s renewal all draw from the same file.
How does a firm get from “can’t answer” to a documented program?
The questionnaire on your desk is really an inventory request, so start with the inventory: what controls actually exist today, on which devices and accounts, with what proof. Most firms discover a mix, some controls in place but undocumented, some partially deployed, some absent. A structured security risk assessment gets you that picture quickly and gives you honest language for the questionnaire in front of you, including truthful in-progress answers where needed.
Then close the gaps in order of impact. MFA enforcement and encryption verification usually come first because they’re fast and they anchor nearly every questionnaire. EDR deployment, email authentication, and tested backups follow. The written pieces, incident response plan, offboarding procedure, training program, get built alongside, because “written and dated” is what turns a practice into an answer.
The step firms skip is the one that matters most for the next questionnaire: keeping the evidence current. Controls drift, staff change, and a report from two years ago proves little. A managed security program maintains the controls and regenerates the proof continuously, so the next questionnaire, and there will be a next one, becomes an afternoon of assembly instead of a two-week emergency.
This is where Braintek fits. We’ve supported Texas businesses since 2002 with local teams in Houston and DFW, running fully managed IT for firms of roughly 10 to 50 people and co-managed support for larger firms. Our managed cybersecurity service includes both halves of this problem: implementing the controls and producing the documentation and evidence for client questionnaires and insurance applications, as part of the service rather than a billable surprise when the spreadsheet arrives. The law firm page covers how that looks for a practice day to day.
If a questionnaire is sitting on your desk right now, schedule a discovery call and bring it. Fifteen minutes is usually enough to tell you which questions you can already answer, which ones need work, and what a realistic timeline looks like, before the client’s deadline decides it for you.
