Law Firm Security Questionnaires: What Evidence to Gather
A practical guide to answering client security questionnaires with evidence, clear ownership, and honest statuses for law firms.
A Client Sent Your Firm a Security Questionnaire. Can You Support the Answers?
Blog post - By Securing Your Law Firm
A corporate client asks whether MFA is enforced, backups are tested, or access is limited. Checking a box is easy. Establishing what the firm can substantiate is the useful task.
A policy, a configured control, and operating evidence are different
A written policy explains what the firm intends to do. A configured control shows that a setting exists within a defined system and scope. Operating evidence shows that the control has been used, reviewed, or tested during an identified period.
Do not answer “yes” to one question because another kind of evidence exists. A policy can be current while a former user still has access. A backup can be configured while restoration has never been tested.
Illustrative evidence map
These examples are not universal client requirements. Use the client’s wording and scope.
| Client question | Evidence to request | Responsible party | Gap requiring follow-up | | --- | --- | --- | --- | | Is MFA enforced? | Identity policy, scope, and recent sign-in or exception evidence | IT or identity administrator | Exceptions, legacy authentication, or unknown coverage | | Are joiners and leavers controlled? | Access-provisioning procedure and recent departure record | IT, HR, and firm administrator | Unassigned owner or delayed revocation | | Are endpoints covered? | Device inventory and protection/patch status for in-scope devices | MSP or internal IT | Unknown devices or stale reporting | | Are backups restorable? | Backup scope, retention, and dated restoration test | IT or backup provider | No test, incomplete scope, or unclear recovery target | | Who can access matter files? | Permission groups, sharing settings, and review record | Matter owner and IT | Broad groups, external links, or inherited access | | Is incident preparation documented? | Incident plan, contacts, decision points, and exercise record | Leadership and IT | Plan exists but has not been rehearsed | | Is staff trained? | Training dates, participation, follow-up, and testing scope | Firm administrator | Completion without demonstrated reporting behavior |
A working response process
- Identify the exact request, scope, deadline, confidentiality terms, and approval owner.
- Assign each answer to someone who can produce the evidence, not only someone who knows the policy.
- Gather current documents, settings, reports, and test records.
- Mark each answer verified within scope, partially verified, not verified, or not applicable with explanation.
- Agree remediation or a carefully worded limitation for gaps.
- Obtain firm approval before sending the response and retain the submitted version with its evidence notes.
“Unknown” is a useful status. It tells leadership where a claim needs verification before it becomes a client commitment.
How an independent assessment helps
An independent review can test the controls behind selected answers, identify the affected scope, and organize supporting evidence. It does not certify compliance, guarantee client approval, or turn every questionnaire into a penetration test.
Some requests need separate technical testing, certification, or remediation. A questionnaire that asks for penetration-testing results is not satisfied merely by buying a baseline assessment.
Securing Your Law Firm offers scoped client security questionnaire and evidence support. The service uses the client’s actual questions, flags gaps, and keeps the final approval with the firm. It does not collect confidential client files or tenant credentials through an ordinary contact form.
Before you submit
- Can you identify the system and population covered by each “yes”?
- Is the evidence dated enough for the request?
- Have exceptions and partial coverage been disclosed?
- Has the firm approved the wording and any remediation commitment?
- Does the client require a separate test, certification, contract clause, or insurance confirmation?
If the need is broader control verification, see the Law Firm Security Baseline. If the request is specifically about Microsoft 365 settings, the Microsoft 365 Security Checklist explains what an authorized review can and cannot establish.
Start with the actual request
Use Discuss a Client Security Questionnaire to share the question set, deadline, and high-level scope. Do not upload client data or passwords through the marketing form. We can confirm what evidence support is appropriate before any access is requested.
This article is for informational purposes only and does not constitute legal, compliance, or insurance advice.
