Under attack right now? Active incident line — +1 480-999-0030 · Report an incident

Field guide · Compliance

What client security questionnaires ask.

Corporate clients now vet their law firms and SaaS providers the way they vet any vendor holding sensitive data. Here's what their questionnaires ask, why, and how to prepare answers that win the work instead of losing it.

The email arrives from a client's procurement or security team, usually mid-engagement or during a pitch: a spreadsheet full of questions about your firm's security. A questionnaire like a CAIQ contains over 260 items. It isn't optional, and "we take security seriously" is not an accepted answer. Corporate legal departments increasingly vet outside counsel via the same vendor risk programs that govern their software suppliers, because a law firm holds some of the most sensitive data a company has, and attackers know it.

The good news: the questionnaires are predictable. They draw from the same handful of frameworks (SOC 2, ISO 27001, NIST CSF, or a standardized set like the CAIQ), so preparing for one largely prepares you for all of them. Here's what they ask:

The questions that decide the outcome

Identity and access

  • Is multi-factor authentication enforced for all users, including partners, on email and remote access?
  • How quickly is access removed when someone leaves the organization?
  • Are administrative privileges restricted and reviewed?

This section carries the most weight, because compromised credentials are how organizations get breached. "MFA is available" and "MFA is enforced" are different answers, and reviewers know the difference.

Data protection

  • Is client data encrypted at rest and in transit?
  • How are documents shared externally, and can access be revoked and audited?
  • Are retention and destruction schedules actually enforced?
  • Do you conduct regular penetration tests?

Email attachments are the answer reviewers don't want to see. Firms that can point to an audited sharing mechanism with verified recipients (the problem Panthryx Courier was built to solve) answer this section with an ironclad audit trail.

Incident response

  • Do you have a written incident response plan? When was it last tested?
  • Will you notify us of a breach affecting our data, and how quickly?
  • Have you had a security incident in the last 36 months?

Answer the history question honestly. A disclosed, well-handled incident with documented remediation reads far better than a "no" that later turns out to be false.

People and training

  • Is security awareness training recurring and documented, not a one-time onboarding video?
  • Are phishing simulations run?
  • Do you conduct social engineering penetration testing?

Vendors and subcontractors

  • Who else touches our data: subcontractors, e-discovery vendors, court reporters, cloud services, your IT provider?
  • Do you assess their security?

This section matters: your client is extending trust through you to everyone downstream.

Independent validation

  • Has your security program been independently assessed?
    By whom, against what framework, and when?
  • Can you provide the report, attestation, or certification?

This is the section where an independent assessment pays for itself. A current review by a certified auditor often satisfies the entire questionnaire's intent. Some clients will accept an attestation in place of a spreadsheet.

How to prepare without gaming it

  • Build the answer file once. Maintain a living document with your standard answers, evidence, and policy references. The second questionnaire takes a fraction of the time of the first.
  • Close the real gaps first. If MFA isn't enforced everywhere, enforce it; don't misrepresent the situation. Reviewers have read ten thousand hedged answers and recognize the language.
  • Match the effort to the demand. Not every firm needs SOC 2. A risk assessment against the framework your clients reference is the right-sized first step. Full attestation makes sense when the questionnaires keep coming.
  • Answer as the firm you're becoming, honestly. "In progress, complete by Q1" with a real plan behind it is a legitimate and strong answer. "Yes" without evidence is not.

Staring at a questionnaire right now? Send it to us: [email protected]. We'll tell you which answers your firm can already give, which gaps are quick closes, and whether independent attestation is worth it for the clients you serve.

From questionnaire to attestation

Turn the next security review into a strength.

Independent assessment led by a CISA-certified auditor gives you documentation your clients, insurers, and investors will accept.