
Landing your first corporate or institutional client is a milestone for a small law firm. It's also the moment a security questionnaire shows up in your inbox - and for most two- and three-attorney firms, it's the first time anyone has ever asked them to prove how they handle technology.
The questions are predictable: multi-factor authentication, endpoint detection, encryption, backups, employee security training, incident-response plans, access controls, cyber insurance, and how client data is stored and shared. What surprises firms isn't the list. It's what the questionnaire actually wants.
The problem usually isn't your security. It's that you can't prove it.
Most small firms don't fail these reviews because their security is terrible. They fail because they can't demonstrate what they have. The attorney says, "Our IT person handles that" - and the questionnaire wants a written policy, a report, a date, an owner, or evidence that the control is actually enforced. "We think so" is not an answer a corporate client's risk team will accept.
That gap between having something and being able to show it is where nearly every first questionnaire goes sideways.
What "good enough" turns out not to be
The typical small-firm setup is Microsoft 365, antivirus, passwords, and a cloud file-sharing service - and the assumption that this equals a security program. It doesn't, at least not to a reviewer.
A corporate client reviewing your firm will generally expect MFA enforced for everyone (no exceptions for the senior partner), managed endpoint protection rather than store-bought antivirus, encrypted devices, secure file sharing, backups that are actually tested, documented offboarding when someone leaves, and limits on who can access each client's information. Owning the right products isn't the bar. The bar is products that are consistently configured, monitored by someone, and provable on paper.
Documentation is how the technical gaps get found
Is this a paperwork problem or a real security problem? In our experience, it's both - and the paperwork is what exposes the rest. A small firm often has decent tools but no written security policy, no incident-response plan, no asset list, no vendor-management process, and no proof its backups have ever been tested.
Then the evidence-gathering starts, and the real findings surface: MFA exceptions that someone granted years ago, unmanaged home computers touching client files, former users whose accounts still work, client documents shared in ways nobody formally approved. The questionnaire didn't create those problems. It just made them impossible to ignore.
Got a questionnaire this week? Don't guess.
If a Providence firm called us today with a security questionnaire in hand, the first five minutes of advice would be simple: do not guess, and do not answer based on what you assume your IT provider is doing.
Send the questionnaire to whoever actually manages your environment. Understand what information the new client will be trusting you with. Then compare every single answer against the real environment - not the intended one. Separate the quick fixes from the larger gaps, document what's genuinely in place, and be honest about anything still being implemented.
A confident but inaccurate answer is worse than admitting a control is scheduled or partially deployed. Corporate risk teams see "in progress, target date attached" all the time and can work with it. What they can't work with is discovering later that your "yes" was a hope.
Does Rhode Island change any of this?
Honestly: the security expectations themselves are not dramatically different here. A questionnaire from a Boston company reads the same in Providence as it does anywhere else.
What is different is the shape of the firms answering it. Rhode Island's small firms tend to run very lean - informal IT relationships, no office manager who owns technology, nobody whose job it is to keep evidence. At the same time, RI attorneys already depend heavily on technology whether they like it or not: electronic filing is generally mandatory, and the Rhode Island Supreme Court now expressly expects lawyers to stay current on the benefits and risks of the technology they use. The "we're a small firm, we don't really do IT" posture stopped being tenable a while ago.
And in a market this small, reputation compounds. Losing a corporate client's confidence over a weak questionnaire response doesn't stay contained to that one engagement - the people who refer institutional work to small firms talk to each other.
The takeaway
If corporate or institutional work is anywhere in your firm's plans, the time to build a provable security posture is before the questionnaire arrives, not the week it's due. The controls themselves - enforced MFA, managed endpoints, tested backups, clean offboarding - are achievable for a two-attorney practice. What takes lead time is the evidence: policies written, reports generated, dates and owners attached.
We help Rhode Island law firms get both in place - the controls and the proof. If a questionnaire just landed on your desk, or you'd rather be ready before one does, get in touch and we'll take a look at where you actually stand.
