Skip to content
Professional Services

Answering a client security questionnaire in an hour

Getting a 30-person firm from free mailboxes and unencrypted laptops to a documented security posture, because a client made it a condition of engagement.

Client
Commercial law firmNamed once permission is confirmed
Year
2025
Duration
4 weeks
Stack
Microsoft 365IntuneDefender
  • 1 hour

    To complete the client questionnaire, from documented controls

  • 100%

    Devices encrypted, enrolled and remotely wipeable

  • Enforced

    MFA on every account

  • Engagement retained

    Client condition satisfied

The situation

A major client sent a security questionnaire as a condition of continuing the engagement. The firm ran business email on ISP mailboxes with no SPF, DKIM or DMARC, client documents lived on individual unencrypted laptops, there was no MFA anywhere, and IT was handled by a partner alongside a full caseload.

What we did

  1. 1Worked backwards from the questionnaire itself to establish what actually had to be true, and in what order
  2. 2Migrated email to Microsoft 365 on the firm's own domain, with SPF, DKIM and DMARC configured and monitored
  3. 3Enrolled every device into management with disk encryption and remote wipe, and enforced MFA across all accounts
  4. 4Restructured client documents into per-matter permissioned storage, off individual machines
  5. 5Wrote the incident response plan, access review procedure and leaver process the questionnaire asked about

The questionnaire was the specification

Most security projects start with an assessment and produce a ranked list. This one had its list handed to it by a client, which made prioritisation straightforward and the business case unarguable.

We worked backwards from the questions. Do you enforce MFA. Are devices encrypted. Where is our data held. What is your incident process. Who has access, and how often is that reviewed.

Every one of those is answerable with cheap, standard controls, but only if the control is in place before the question arrives.

Email first, and the records nobody had set

The firm's domain had no SPF record, no DKIM signing and no DMARC policy. Anyone in the world could send email appearing to come from a partner, which is exactly how client-account fraud works in legal practice.

Fixing it took an afternoon. It had been exposed for years.

The result nobody asked for

Four weeks of work, driven by an external questionnaire, and the firm now has a security posture it can present without preparation.

Two further clients have since sent similar questionnaires. Both took under an hour, because the answers are documented rather than reconstructed. The partner who used to "do the IT" has their evenings back, which they mention more often than the security improvements.

Comparable project

Something like this, for your business?

We will say whether the same approach applies.

  • A reply within one working dayFrom an engineer.
  • We look before we quoteA call, and a site visit if needed.
  • The recommendation is yoursYours to take elsewhere.
  • Or call +20 109 777 8090