You have been sent a security questionnaire: what to do

You have been sent a security questionnaire: what to do

A client, a prospective client, an insurer or a head contractor has sent you a spreadsheet or an online form with anywhere from twenty to three hundred security questions, and a due date that is sooner than you would like. It arrives with no warning and usually lands on the person least equipped to answer it.

This is a normal part of doing business now, particularly if you are growing into larger clients or government work. It is answerable. It is not a test you can fail by being a small business.

First, take the pressure off

Two things are worth knowing before you start.

The questionnaire is almost certainly a standard template that the sender uses for every supplier, from a two-person firm to a multinational. Many questions will not apply to you. "Not applicable, we do not operate a data centre" is a perfectly respectable answer and reviewers see it constantly.

And an honest no is not a failure. Reviewers are looking for a supplier who understands their own environment. "No, but here is what we do instead" or "No, this is planned for the next quarter" reads far better than a yes that falls apart under a follow-up question. Overstating is the one thing that genuinely damages you, because if something goes wrong later, your answers are the document everyone reads.

What to do first

  1. Find the real deadline and the real contact. Not the automated one in the portal, the person who wants this. Extensions are usually available for the asking if you ask early.
  2. Read the whole thing once without answering. You are looking for how many questions there are, whether evidence or attachments are requested, and whether it is asking about your business or about a specific system you use.
  3. Split the questions into three piles. Questions about your business practices, such as staff training, contracts, insurance and who approves payments. Questions about your technology, such as multi-factor authentication, backups, patching and access control. And questions that are genuinely about a supplier of yours, such as Microsoft or Xero, where the answer is usually available in that supplier's own published documentation.
  4. Answer the business pile yourself. You know these better than anyone, and they are often the majority.
  5. Send us the technology pile. We can answer those accurately for the systems we manage, in the words the reviewer expects, without you having to translate anything.

How we help

Where we manage your environment, we can describe what is actually in place: how identities and access are managed, what multi-factor authentication is enforced, how devices are protected and patched, how backups run and how they are tested, how administrative access is controlled, and how we handle incidents when they occur.

We can also provide supporting evidence where it exists, and tell you plainly where a question describes something you do not have. That is the useful part of the exercise, because a questionnaire is often the first time a business gets an honest inventory of its own controls. Several times the questionnaire has turned into a short, sensible improvement plan that the client was going to need anyway.

What we will not do is help you write an answer that is not true. That protects you more than it constrains you.

Keep the answers

The single best thing you can do after finishing one is to save the completed questionnaire somewhere you will find it. The next one will ask most of the same things in a different order, and having last time's answers turns a two-week job into a two-day one. Keep the date on it, because answers go stale.

If you deal with several large clients, it is worth building one short document that describes your security arrangements in plain terms. Most questionnaires can then be answered largely by referring to it.

Talk to us

If a questionnaire has landed and you are not sure where to start, email admin@yougrowit.com.au with the document attached and the deadline. We will tell you what we can answer, what needs to come from you, and whether anything in it points to work worth doing.

Compliance work of this kind is scoped and quoted rather than priced from a list, because the size of the job depends entirely on the questionnaire and on what is already in place. We will give you the quote in writing before anything starts.

    • Related Articles

    • Evidence we can provide for a tender or a client audit

      Winning larger work increasingly means proving things rather than asserting them. A tender asks for evidence of your security arrangements, a big client's procurement team wants documentation before they will onboard you, or an auditor asks to see ...
    • The Essential Eight in plain English

      Someone has asked whether you follow the Essential Eight, probably in a tender document, an insurance form or a client questionnaire. Here is what it is, without the jargon. The Essential Eight is a list of eight practical controls published by the ...
    • Cyber insurance questions we can answer for you

      Cyber insurance applications and renewals used to be a page. Now they ask specific technical questions, and getting one wrong can mean a higher premium, a condition on the policy, or an argument at exactly the wrong moment. Most of these questions ...
    • Notifiable data breaches: your obligations in plain English

      If personal information held by your business is lost, or accessed or disclosed without authorisation, you may have obligations under Australian privacy law. This article explains the scheme in plain terms so that you know what you are dealing with. ...