Your Law Firm Was Sent a Security Questionnaire Before Anyone Will Wire Funds

It usually arrives from the title company or the lender, not from a client. Your firm is handling a closing, or holding funds in trust, and before anyone will send money to the firm’s account, someone wants to know how your law firm protects its systems.

The form asks about multi-factor authentication, endpoint protection, encryption, staff training, how you verify wire instructions, whether you carry cyber insurance, and whether you have a written incident response plan.

It is not a regulator asking. It is a counterparty deciding whether it is safe to send money to your firm. That makes it a business problem before it is a compliance problem — and it has a deadline attached to a closing date.

Why you are the one being asked

Real estate and trust account transactions are a standing target for wire fraud. The pattern is well known: an attacker gets into an email account, watches a transaction, and sends payment instructions that look exactly like yours at exactly the right moment.

Lenders and title companies have absorbed enough of those losses to stop taking counterparties on trust. So they ask, in writing, before funds move.

Two things follow from that.

The questionnaire is a contract condition, not a rule. Nobody has to accept your answers, and the counterparty can set whatever bar it likes.

And you cannot answer it with an opinion. A bare assertion that the firm takes security seriously is not what the form is for. It asks whether specific controls exist.

What the form is really testing

Strip away the wording and the questions fall into four groups.

Can someone get into your email. Multi-factor authentication, on every account, including the administrator accounts nobody thinks about. Email account compromise is a common mechanism behind wire fraud losses, which is why this is usually the first section.

Would you notice. Endpoint protection, logging, whether anyone reviews alerts.

What happens to funds instructions. Whether wire details are verified out of band, by phone to a number you already had, rather than by replying to the email that carried them. This is the control the counterparty cares about most, because it is the one that would have stopped the loss.

Whether any of it is written down. A policy, an incident response plan, a training record. The form asks for documents, not intentions.

The duties sitting behind the form

This is the part that is easy to miss. The questionnaire is a subset of what already applies to a Texas law firm, not a separate standard invented by the lender.

The Texas Disciplinary Rules of Professional Conduct state duties that reach this directly:

  • Rule 1.05, confidentiality of client information
  • Rule 1.01, competence
  • Rule 1.15, safekeeping property, which carries a five-year retention requirement
  • Rule 5.01, the responsibilities of partners and supervisory lawyers, which is how the rules reach a firm rather than only an individual
  • Rule 5.03, responsibilities regarding nonlawyer assistants

Rule 5.03 is worth reading twice if your firm uses outside IT. A lawyer who retains a nonlawyer must make reasonable efforts to ensure that person’s conduct is compatible with the lawyer’s own obligations. The duty stays with the lawyer. It does not move to the vendor.

The State Bar has also issued ethics opinions on technological competence, on cloud services, on email, and on generative AI. They are interpretive rather than binding, and they form a chain that has been extended as the technology changed.

Separately, and regardless of the Bar, Texas breach notification law reaches any person who conducts business in Texas and owns or licenses computerized data containing sensitive personal information. There is no registration test and no size test in that statute.

One thing we do not do. We do not tell you whether a given arrangement satisfies a Disciplinary Rule. That judgment belongs to your own counsel or to the State Bar, never to your IT provider. What we can do is establish what your firm actually has, and what it can show.

Answering it when the closing will not wait

You will not rebuild anything before the deadline, and the form is signed by someone at your firm.

Answer what is true. A no that is accurate is workable. A yes you cannot support is a representation to a counterparty who is about to send money on the strength of it.

Where a control is partial, say what compensates for it. A documented exception reads very differently from a bare no, and completely differently from a yes that does not hold.

Gather the evidence you do have. Screenshots of MFA settings, the endpoint console, a written wire verification procedure, the date of the last training.

Fix the wire verification step first if it is missing. Of everything on the form, out-of-band verification of payment instructions is the control most directly tied to the loss the counterparty is trying to avoid, and it is a procedure rather than a purchase.

Then close the rest properly, so the next questionnaire is a retrieval exercise.

See the eleven obligations that reach Texas legal and financial firms →

How Briggs IT Services helps

We start with a Compliance Readiness Review. We gather what your firm actually has, then review it against what the questionnaire asks and what Texas law and the Disciplinary Rules state as duties for your firm.

You get a written report: what you can answer truthfully today, where the gaps are, and what closing each one takes.

From there we create the plan. If you have IT, internal or outside, we guide them through the changes and they do the hands-on work. Your IT keeps doing their job. If you have no IT, we do the hands-on work ourselves, inside a scoped remediation phase with a defined end.

Then we build the documentation and keep it current, so the next form is answered from a file rather than from memory.

Common questions

Do we have to complete a lender’s security questionnaire?

Not as a matter of law. It is a contract condition. The counterparty is deciding whether to send funds to your firm, and it can set its own bar. Declining to answer is usually the same as declining the transaction.

Is the questionnaire the same as our compliance obligations?

No, and it is narrower. It asks about the controls that drive the counterparty’s own losses. The Texas Disciplinary Rules and Texas breach notification law reach your firm regardless of whether anyone sends you a form, and they do not stop at the edge of it.

Does our IT company answer this for us?

They can supply facts about the systems, and they should. The form is signed by the firm, and under Rule 5.03 a lawyer who retains a nonlawyer must make reasonable efforts to ensure that person’s conduct is compatible with the lawyer’s obligations. The duty does not transfer to the vendor.

What single control matters most on these forms?

Out-of-band verification of wire instructions — confirming payment details by phone to a number you already had, rather than replying to the email that carried them. It is a written procedure rather than a product, and it addresses the loss the counterparty is asking about.

Does Texas breach notification law apply to a small firm?

The statute reaches any person who conducts business in Texas and owns or licenses computerized data containing sensitive personal information. It contains no size test. Whether a particular incident triggers notice is a question for your counsel.

Find out what your firm can actually answer