Skip to content
0800 374 775

The security questionnaire that decides whether you keep the contract

A spreadsheet arrives from your largest customer asking sixty questions about your security. How you answer it matters less than whether the answers are true.

It usually arrives without warning, forwarded by someone in sales with a note saying this needs to go back by Friday. Sixty or a hundred rows, three columns, and questions like whether you enforce multi-factor authentication, how long you retain logs, and whether you have a documented incident response plan.

The immediate reaction is that this is a procurement formality. It is not. Someone on the other side has been told to reduce supplier risk, and your answers are going into a comparison.

Why you are being asked

Larger organisations have worked out that their exposure is not limited to their own systems. If you hold their data, connect to their network, or ship them something they cannot operate without, then your security is part of theirs. Insurers have reached the same conclusion from the other direction.

So the questionnaire is not really asking whether you are secure. It is asking whether you are a risk they can justify carrying, and whether you can be relied on to say true things about yourself.

That second part is the one businesses underestimate.

The trap in answering optimistically

The pressure to tick the boxes is obvious. The contract is worth more than the remediation, the deadline is Friday, and some of these answers are nearly true. Multi-factor is on for most people. Backups are tested, in the sense that a restore worked once.

Two things make that a bad trade.

The first is that these documents are increasingly contractual. An answer becomes a representation, and a representation that turns out to be false at exactly the moment it matters, during an incident that affects your customer, is a significantly worse position than having said no in the first place.

The second is that saying no is survivable and often expected. “Not currently, and here is the date we will have it” is an answer a competent procurement person can work with. It signals that you understand your own environment. A row of unqualified yeses from a business of your size is more likely to prompt evidence requests than to close the matter.

What to do the first time one arrives

Answer it honestly, on time, and treat the gaps as the actual output.

The questionnaire has just done you a favour that you would otherwise have paid for: it has produced a specific, externally validated list of what your customers consider table stakes. That list is worth more than the contract it came attached to, because the next one will ask most of the same things.

From there the work is ordinary and finite. Most questionnaires cluster around the same handful of areas: identity and access, endpoint configuration, patching, backup and recovery, logging, supplier management, incident response, and staff awareness. None of it is exotic. What makes it slow is that it has usually never been anybody’s job.

Getting off the treadmill

The businesses that find this painful answer each questionnaire from scratch. The ones that do not have done two things.

They have aligned to a recognised framework rather than to a customer’s spreadsheet. Once your controls map to something like SMB1001, the Essential Eight, NZISM or ISO 27001 depending on who is asking, the questionnaire becomes a translation exercise instead of an investigation. Certification, where it is worth having, is the version of this you can hand over without argument.

They keep the evidence, not just the answers. The screenshot of the conditional access policy, the restore test result with a date on it, the onboarding checklist. Evidence is what turns a yes into a defensible yes, and assembling it once is much cheaper than assembling it four times a year under deadline.

That is the difference between a control being implemented and a control being asserted, and it is the whole game. An asserted control passes a questionnaire. An implemented one also works during the incident that the questionnaire was written to prevent.

The uncomfortable summary

If a questionnaire arrived tomorrow and you could not answer it honestly and quickly, that is not a paperwork problem to solve on Friday. It is a reasonable description of your current security position, delivered by your customer, for free.

Worth acting on while it is still just a spreadsheet.

Next step

Recognise any of this? Let's talk.

We respond within one business day.