Your client sent a security questionnaire. Now what?
It arrives as an attachment with a bland name: outside counsel guidelines, a security addendum, a vendor risk questionnaire. Inside are forty questions about how your firm protects the client's information, and a deadline. The two instincts it triggers, round everything up to yes, or set it aside and hope, are both wrong. Here is the reframe this guide argues for: that document is the client telling you, in writing, exactly what it takes to keep their work. Firms that treat it as a spec win; firms that treat it as paperwork get quietly rotated off the panel.
Why clients are asking now
To a bank, an insurer, or a hospital system, a law firm is a vendor that holds some of its most sensitive information, and their regulators and cyber carriers now require them to check what their vendors do with it. So the requirements flow downhill: the same controls the client had to prove internally arrive at your door as a condition of the engagement. This is why the questionnaires reaching small firms keep getting longer and why they no longer stop at big-firm panels. Being small does not exempt you; it just means the client has less patience for a slow answer.
What do outside counsel guidelines usually require?
The documents vary; the substance barely does. Nearly all of them ask for multi-factor authentication, encryption of data at rest and in transit, security awareness training with records, a written information security policy and incident response plan, access control with a real offboarding step, breach notification to the client within a stated window, and proof of cyber insurance. Some add background checks, audit rights, or questions about where data physically lives. If that list sounds familiar, it should: it is nearly the same list a cyber insurance questionnaire asks, which means one honest setup answers both documents for years.
Answer honestly: these answers are contractual
A marketing page can be optimistic. A questionnaire response attached to an engagement cannot, because it becomes part of what the client relied on in hiring you, and it gets reread with great care after any incident. That cuts both ways, and the productive side is this: a no with a date is a perfectly good answer. Sophisticated clients see hundreds of these responses and know that a page of confident yeses from a five-person firm is a page of guesses. What the guidelines legally obligate your firm to do is a question for you and your counsel; what the IT side owes you is answers that are actually true, with the records to show it.
Treat the document as the spec
Here is the strategic part most firms miss while groaning about the paperwork. That questionnaire is the rarest thing in business development: the client stating their requirements in writing. Meet them, and you have a durable, factual answer to why the firm should stay on the panel, one your competitors down the street cannot fake on short notice. The efficient move is to work through the document once, turn every gap into a dated item on a plan, and keep the evidence as each one closes. The next questionnaire, from this client or the next one, becomes paperwork instead of a scramble, and the firm gets to say yes to exactly the clients whose work is worth the most.
FAQ
Can we just answer yes and fix things afterward?
Answers on a client security questionnaire become representations the engagement rests on, and the moment they get tested is usually after an incident, when the client's lawyers and your insurer are both reading closely. A no with a date attached is a plan; a yes the records do not support is a liability. Most clients respect the first far more than they punish it.
What if we cannot meet a requirement at our size?
Say what you actually do instead, with evidence. Many guideline documents are written for vendors far larger than a five-person firm, and the client's real question is whether the risk is managed, not whether you match their template word for word. A documented control at small-firm scale is often an acceptable answer; silence or a false yes is not. Whether a specific requirement can be varied is a conversation for the client and your counsel.
Do we need a SOC 2 report or an ISO certification?
For a small firm, rarely. Those audits are built for technology vendors and large service providers, and most clients asking small firms accept documented, verifiable controls instead: the exported MFA policy, the restore-test log, the training records. If a client hard-requires a certification, that is a business decision about what the relationship is worth, made with real numbers instead of panic.
What does getting questionnaire-ready cost?
The controls client questionnaires ask about overlap almost entirely with what cyber-insurance carriers require, so one setup answers both documents. Work for businesses not on a plan is billed at $125 per hour, and larger projects are quoted up front so you approve the number before the work starts.
Holding a questionnaire right now? Working through one, honestly and with evidence, is squarely what I do for small law firms. A first conversation about where you stand is free, and there is nothing to decide on that call. What ongoing support costs is published in what IT support costs a small law firm in Florida.
About the author
Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.
