Five Questions Every Law Firm Should Ask Technology Vendors

Technology decisions have become business decisions. Every software platform, cloud service, AI tool, and vendor relationship introduces opportunities to improve efficiency and service delivery, but also introduces risk that firm leadership must understand and manage. Throughout The Business of Security series, we’ll explore how law firms can evaluate technology providers, assess cybersecurity maturity, strengthen operational resilience, and build governance practices that support growth without creating unnecessary friction. We begin with the foundation of every security program: vendor evaluation. Because before you can assess a provider’s security posture, incident response capabilities, or AI governance practices, you need to know how to separate meaningful answers from marketing claims and ask the questions that matter most.

Most law firms approach vendor security reviews the same way people approach buying a house for the first time. The seller walks you through the renovated kitchen. The countertops are beautiful. The appliances are new. The natural light is perfect at 3 p.m. on a Tuesday. Everything you can see looks impressive, and before long you’re mentally arranging furniture and imagining yourself living there. Meanwhile, nobody has looked in the crawl space, checked the wiring, or asked whether the foundation is sound.

After reviewing thousands of technology products over the years, I’ve noticed that most vendor evaluations suffer from the same problem. Too much attention gets paid to the visible parts of the product, including feature lists, demonstrations, implementation timelines, and roadmap presentations, while far less attention is devoted to understanding how the company operates when something goes wrong. The challenge isn’t that law firms don’t care about security. It’s that many assume evaluating security requires specialized expertise, lengthy questionnaires, and hundreds of technical questions. In practice, a handful of thoughtful questions often reveals more about a vendor’s maturity than a spreadsheet containing two hundred generic ones.

The goal is not to become a security expert overnight. The goal is to learn how to distinguish between a vendor with a mature security program and a vendor with a polished marketing program. Those are not always the same thing, and the difference often becomes apparent surprisingly quickly once you know what to ask.

This is usually the question that tells me the most because it reveals something far more important than whether an incident occurred. Every company with a meaningful operating history has experienced an outage, a security event, a process failure, or some other unexpected challenge. The specifics matter less than the organization’s response. What I’m really evaluating is how the company thinks about adversity and whether it treats incidents as learning opportunities or public relations problems.

Mature vendors usually tell a story. They can explain what happened, what they missed, how they discovered the issue, what corrective actions they implemented, and what changed afterward. The conversation tends to be specific, candid, and grounded in operational reality. By contrast, immature vendors often claim they have never experienced a significant incident at all. That’s either remarkable or a sign they lack the visibility necessary to know otherwise. Over time, I’ve come to trust an admitted flaw more than a flawless record because organizations that openly discuss their worst day usually demonstrate a stronger understanding of how to prevent the next one.

This question is really another way of asking whether security exists in practice or only on paper. One of the most common responses you’ll hear is, “We’re SOC 2 compliant.” That’s useful information, but it shouldn’t end the conversation. A compliance report tells you certain controls existed and were reviewed within a defined scope. It does not automatically tell you whether those controls remain effective, how frequently they are tested, or how seriously the organization treats ongoing risk management.

The more meaningful discussion begins when you start asking how the organization validates its environment on a continuous basis. Do they conduct regular penetration tests? Are those tests performed by an independent third party? How are vulnerabilities prioritized and remediated? What lessons emerged from recent assessments? Mature vendors are usually comfortable discussing these topics because they view them as normal components of operating a security program. Less mature vendors often retreat toward generic statements about taking security seriously. When a direct question with a factual answer receives a marketing response instead, that should always be noted.

One of the most reliable signals during a vendor review has very little to do with the content of the answer and everything to do with who provides it. Ask a technical security question and pay close attention to what happens next. Does the answer come from someone who owns the security program, understands the controls, and can speak confidently about operational practices? Or does every security discussion get filtered through layers of account management before eventually producing a generic response?

Not every company needs a large security team or a dedicated Chief Information Security Officer. Security maturity is not measured by headcount. What matters is whether ownership exists and accountability is clear. Mature organizations can identify who is responsible for security, how decisions are made, and who customers can speak with when deeper diligence is required. When security is treated as a side project bolted onto someone else’s job description, that often creates the same risks and blind spots that eventually surface elsewhere in the organization.

If I could ask only one practical security question, this might be it. Technology headlines tend to focus on sophisticated attacks, advanced threat actors, and highly technical exploits. In reality, many incidents still begin with something much simpler: compromised credentials. That is why identity and access management remain among the most important security controls an organization can implement.

The questions themselves are straightforward. Is multi-factor authentication required for employees? Are privileged accounts managed differently from standard user accounts? How frequently are access reviews conducted? How quickly is access removed when an employee leaves the company? The answers matter, but just as important is the level of specificity behind them.

Mature vendors typically respond with details about frequency, ownership, exception handling, and oversight processes. Less mature organizations often provide answers so broad they could apply to virtually any company on earth. Over years worth of evaluations, I’ve found that specificity remains one of the most reliable indicators of operational maturity.

Every vendor relationship eventually gets tested. The question is rarely whether change will occur. The question is how customers will learn about it. Security incidents, platform changes, acquisitions, new sub-processors, and major infrastructure updates all have the potential to affect risk.

Organizations often focus heavily on prevention while giving relatively little thought to communication, but transparency during difficult moments is one of the strongest indicators of trustworthiness.

Ask how quickly the vendor will notify customers following a security incident. Ask whether notification timelines are documented in the contract. Ask how significant operational changes are communicated and whether customers receive meaningful advance notice when appropriate. The language used in these answers is often revealing. “Within 24 hours” communicates something concrete and measurable. “As soon as reasonably possible” sounds reassuring while providing almost no useful information at all. Vendors with mature programs tend to be direct, transparent, and precise about communication expectations because they understand that trust is built through clarity, especially when circumstances are difficult.


As software ecosystems continue to expand, law firms are being asked to evaluate more technology vendors than ever before. The volume alone can make vendor reviews feel overwhelming, which is why many organizations default to lengthy questionnaires and highly complicated assessment processes. Unfortunately, complexity does not always produce better outcomes. In many cases, it simply creates more paperwork while obscuring the handful of questions that truly matter.

The organizations that make the best vendor decisions are not necessarily the ones asking the most questions. They’re the ones asking the right questions. If a vendor can demonstrate how it learns from incidents, explain how it validates security controls, identify who owns security, describe how customer data is protected, and communicate clearly about risk and change, you’ve already learned more than many extensive due diligence exercises will ever reveal.

The goal isn’t to eliminate risk because that isn’t possible. The goal is to understand risk well enough to make informed business decisions. In vendor evaluations, just like home inspections, the most important discoveries rarely happen in the kitchen. They happen in the crawl space, where someone took the time to look beneath the surface and ask the questions that actually matter.

Next in the Business of Security Series

Why Compliance Isn’t Enough: How to Identify Real Security Maturity.

You Might Also Like…

Gould & Ratner was facing the challenge of optimizing efficiency and profitability and in need of a comprehensive solution. The firm not only wanted to use financial and practice management software to efficiently manage its

As legal professionals, managing client funds is a significant responsibility. Trust accounts provide a critical mechanism for keeping client funds separate from firm assets, thereby protecting your clients and your practice from ethical pitfalls. Download

FAQs

Does SurePoint support LEDES and client billing guidelines?
Yes. UTBMS codes, validations, and client-specific rules are baked in.

Will attorneys actually use the workflows?
Adoption improves when steps happen where they work; automation reduces administrative burden. Industry data shows growing use of workflow automation across firms.

How is knowledge secured?
Role-based access, governance, and audit trails ensure only the right people see sensitive content. KM programs emphasize taxonomies and stewardship for accuracy.

Is AI safe to use in legal work?
Practical AI should be embedded with guardrails, human review, and clear governance—a trend reflected in 2025 tech surveys.