A corporate client sends a forty-page security questionnaire, or outside counsel guidelines with a security schedule attached. For a fifteen-attorney firm this is genuinely difficult — not because the firm is insecure, but because the questions assume an information security function the firm does not have.
The instinct is to answer optimistically and move on. That instinct is the problem, because the answers become contractual.
What you are actually signing
Questionnaire responses and outside counsel guidelines are usually incorporated into the engagement. That has three consequences worth understanding before answering.
First, an inaccurate answer is a misrepresentation the client relied on. If an incident occurs and the control you claimed did not exist, you have a contractual problem on top of the incident.
Second, guidelines frequently impose notification windows far shorter than any statute — 24 or 48 hours is common — and obligations that continue for the life of the relationship.
Third, they often include audit rights and the right to require remediation. Agreeing to a control you do not have commits you to building it.
The rule to work by: answer what is true today, not what you intend to implement. "Not currently, planned for Q3" is a legitimate answer that has cost far fewer firms an engagement than a false yes has cost in the aftermath of an incident.
What they are really asking
Most questionnaires, whatever their length, are probing a consistent set of controls. If you have these, the majority of questions answer themselves:
- MFA on email and all systems holding client data
- Encryption at rest and in transit
- Endpoint detection and response, monitored
- Documented access control with periodic review and defined offboarding
- Backups that are tested, with a stated recovery objective
- A written incident response plan, with notification procedures
- Security awareness training, delivered and documented
- Vendor due diligence for subprocessors
- Patch management with a defined cadence
- Physical security for premises and equipment
- Cyber liability insurance, with the limits stated
A firm with these can answer almost any questionnaire honestly and well. A firm without them will struggle regardless of how the answers are worded.
Answering well without overstating
- Answer precisely. If MFA covers email but not the practice management system, say exactly that. Partial coverage described accurately is far better than a yes that is 80 per cent true.
- Use compensating controls where relevant. You may not have a dedicated security operations centre, but you may have monitored EDR through a provider. Describe what you actually do.
- Distinguish current state from roadmap explicitly, with dates you can meet.
- Where a requirement is disproportionate for a firm your size, say so and propose an alternative. Clients frequently accept this — the questionnaire was written for vendors of a very different scale.
- Get your IT provider to answer the technical sections, with evidence rather than recollection.
- Keep a maintained master response document so each questionnaire is an edit rather than a fresh exercise.
That last point saves an enormous amount of time. Questionnaires repeat heavily between clients, and a firm answering its fifth from scratch is wasting effort it could spend on the controls themselves.
Negotiating the guidelines
Outside counsel guidelines are frequently negotiable, and firms accept them unamended far more often than necessary. Terms worth pushing on:
- Notification windows measured from confirmed compromise rather than from suspicion, which is a meaningful difference in practice
- Audit rights limited to reasonable notice and frequency, at the client's cost
- Requirements scoped to systems that actually hold that client's data rather than the entire firm
- Certification requirements — a demand for SOC 2 or ISO 27001 is a significant undertaking for a small firm and is often accepted as a roadmap item rather than a precondition
- Insurance limits proportionate to the engagement
The client's security team is generally trying to manage risk rather than to impose burden. A firm that engages substantively, explains its actual controls, and proposes proportionate alternatives usually gets a reasonable outcome. A firm that signs without reading gets whatever was written.
| Term | What to push for |
|---|---|
| Notification windows | Measured from confirmed compromise, not suspicion |
| Audit rights | Reasonable notice and frequency, at the client's cost |
| Scope of requirements | Only the systems that actually hold that client's data |
| Certification (SOC 2, ISO 27001) | Accepted as a roadmap item rather than a precondition |
| Insurance limits | Proportionate to the engagement |
Turning it into an advantage
The firms that handle this well stop treating questionnaires as an obstacle and start treating them as a specification.
The controls corporate clients ask for are, with few exceptions, the controls that genuinely reduce risk — and they overlap almost entirely with what cyber insurers now require and what the ethics rules describe as reasonable effort. Building them once satisfies all three.
There is also a straightforward commercial argument. A small firm that can answer a security questionnaire quickly and credibly has a real advantage over competitors who cannot, particularly for corporate work where procurement will not proceed without it.
Sources
- AICPA & CIMA — System and Organization Controls: SOC Suite of Services
- New York State Senate — New York General Business Law § 899-AA: Notification; person without valid authorization has acquired private information
- Connecticut Office of the Attorney General — Reporting a Data Breach
- Cybersecurity and Infrastructure Security Agency (CISA) — Multifactor Authentication


