For the compliance buyer
Answering your customer's security questionnaire.
A document arrives, it has ninety questions, and several of them you do not understand. This is what to do with it.
Supply chain security questionnaires have become routine. If you sell to a larger business, a public sector body, or anyone in financial services, one is coming. They are also increasingly attached to insurance renewals.
The questionnaire is not really a test of your IT. It is a test of whether you can evidence how your IT is managed, which is a different thing and a much more answerable one.
What we can evidence on your behalf
Anything concerning systems we run, we can answer with evidence rather than assertion. That typically covers a large part of the document.
- Patch management: what is patched, how often, and what the current compliance rate is.
- Endpoint protection and threat response, including what happens automatically and when.
- Backup arrangements, retention, and when a restore was last tested.
- Access control: multi-factor authentication coverage, privileged access, and how starters and leavers are handled.
- Incident response process, and how you would be told.
- Our own sub-processors and how they are assessed.
Our own certifications sit alongside that, with certificate numbers your customer can verify. They are evidence about us as your provider rather than about how your business runs โ which is a distinction worth keeping straight, and one the section below returns to.
What only you can answer
These are about your business rather than your technology, and no IT provider can answer them for you. Be wary of one that offers to.
- Who is accountable for information security in your organisation, by name.
- Your data retention and disposal policy, and whether you follow it.
- Staff vetting and pre-employment screening.
- Your business continuity plan, and when it was last tested with actual people. Send it to us and we will tell you whether the IT half of it is realistic โ a plan that assumes a same-day restore of something that takes two days is worse than no plan, because you will not find out until the day.
- Which third parties you share customer data with, and under what agreements.
- Whether you have had a breach, and what you did.
- Physical security of your premises.
Where businesses come unstuck
- Answering yes to something aspirational
- The single most common and most damaging error. If the answer is checked later, a false yes is a contractual problem. An honest no with a remediation date almost never loses the contract.
- Not knowing who owns the answer
- Questionnaires get passed between a director, an office manager and the IT provider until the deadline passes. Decide at the start who owns each section.
- Treating it as a one-off
- It will be asked again next year, and by the next customer. Keep the answers, keep the evidence with them, and the second one takes a fraction of the time.
- Confusing your provider's certification with your own
- Our ISO 27001, our Cyber Essentials and everything else we hold cover our systems, not yours. They are strong supporting evidence for the parts we manage, and they are not a certification of your business. Saying otherwise on a questionnaire is the kind of thing that unravels badly.
Where Cyber Essentials fits
Cyber Essentials is a UK government-backed scheme covering five basic technical controls. The self-assessed level is a questionnaire verified by a certification body. The Plus level adds an independent technical audit.
It is worth having because many questionnaires have a whole section that can be answered by attaching the certificate, and because an increasing number of buyers require it outright. It is also a realistic target: most well-run small businesses are closer to it than they expect.
We hold Cyber Essentials and ISO 27001 ourselves, which is what makes us useful helping you towards it. ISO 27001 is audited externally every year rather than self-assessed, so there is nobody marking their own homework and nothing quietly pushed under the rug. Our certificate numbers are published.
Send it to us first
Before you start filling one in, send it over. We will take a look, answer what we can off the top, and mark up what is evidenced by us, what is yours, and which questions need work before they can be answered truthfully. That first look costs you nothing and saves the week that usually goes into this.
What it is not is us certifying you by answering your questionnaire โ nobody can do that, and a provider offering to should worry you. A long or complicated questionnaire can become consultancy rather than a favour, and so can the remediation work if the answers show something needs fixing before you can honestly claim compliance. Either way we will tell you before it starts costing, rather than after.
Questions people ask
- Our biggest customer has sent us a security questionnaire. Where do we start?
- Send it to us before you start filling it in. A good proportion of a typical questionnaire concerns systems we run, and we can answer those with evidence. That leaves you a much shorter list of genuinely yours.
- What if the honest answer to a question is no?
- Then you write no, and where relevant what you are doing about it and by when. Most buyers are assessing whether you are managing risk, not whether you are perfect. A false yes that unravels later is far worse than an honest no with a plan.
- Do we need Cyber Essentials to pass one of these?
- Not always, but it short-circuits a lot of them. Many questionnaires have a section that can be answered simply by attaching the certificate, and an increasing number of public sector and larger private buyers require it outright.
- How long does this usually take?
- The answering is a few days. If the questionnaire exposes a genuine gap, closing it can take weeks. This is the argument for starting before a deadline rather than the night before one.
Before you get in touch
- How we charge What is charged per user, per device and per site, and what moves the number.
- Service levels Response and resolution targets, and the hours they run within.
- Certifications ISO 27001, ISO 9001 and Cyber Essentials, with the numbers to check them.
Talk to us
Twenty minutes on the phone will tell you more than any amount of reading. We will tell you honestly if we are not the right fit.