A client, a prospective client, an insurer or a head contractor has sent you a spreadsheet or an online form with anywhere from twenty to three hundred security questions, and a due date that is sooner than you would like. It arrives with no warning and usually lands on the person least equipped to answer it.
This is a normal part of doing business now, particularly if you are growing into larger clients or government work. It is answerable. It is not a test you can fail by being a small business.
Two things are worth knowing before you start.
The questionnaire is almost certainly a standard template that the sender uses for every supplier, from a two-person firm to a multinational. Many questions will not apply to you. "Not applicable, we do not operate a data centre" is a perfectly respectable answer and reviewers see it constantly.
And an honest no is not a failure. Reviewers are looking for a supplier who understands their own environment. "No, but here is what we do instead" or "No, this is planned for the next quarter" reads far better than a yes that falls apart under a follow-up question. Overstating is the one thing that genuinely damages you, because if something goes wrong later, your answers are the document everyone reads.
Where we manage your environment, we can describe what is actually in place: how identities and access are managed, what multi-factor authentication is enforced, how devices are protected and patched, how backups run and how they are tested, how administrative access is controlled, and how we handle incidents when they occur.
We can also provide supporting evidence where it exists, and tell you plainly where a question describes something you do not have. That is the useful part of the exercise, because a questionnaire is often the first time a business gets an honest inventory of its own controls. Several times the questionnaire has turned into a short, sensible improvement plan that the client was going to need anyway.
What we will not do is help you write an answer that is not true. That protects you more than it constrains you.
The single best thing you can do after finishing one is to save the completed questionnaire somewhere you will find it. The next one will ask most of the same things in a different order, and having last time's answers turns a two-week job into a two-day one. Keep the date on it, because answers go stale.
If you deal with several large clients, it is worth building one short document that describes your security arrangements in plain terms. Most questionnaires can then be answered largely by referring to it.
If a questionnaire has landed and you are not sure where to start, email admin@yougrowit.com.au with the document attached and the deadline. We will tell you what we can answer, what needs to come from you, and whether anything in it points to work worth doing.
Compliance work of this kind is scoped and quoted rather than priced from a list, because the size of the job depends entirely on the questionnaire and on what is already in place. We will give you the quote in writing before anything starts.