All articles
Security2 min read

Answering your first security questionnaire without panic

The first enterprise security questionnaire tends to arrive attached to the biggest deal you have ever been offered. It is more answerable than it looks, and honesty scores better than you would think.

OmnisgenEngineering team
inX
A security posture screen: an overall posture score, open findings ranked by severity with an owner each, and readiness against GDPR, PCI-DSS and HIPAA.
Findings with an owner and an age are answerable. Findings without either are not.

The first one usually arrives from a customer far larger than you, attached to a deal you very much want, with a deadline that assumes you have someone whose job this is. You do not, which is why it feels like a crisis.

It is less of one than it looks. Most of the document is asking a small number of things in several ways, and most small suppliers already do more than they can prove.

What the questionnaire is really for

The buyer is not trying to establish that you are perfect. They are establishing that you know what you hold, that access to it is controlled, that you would notice a problem, and that somebody there is accountable for all three. Almost every question is a version of one of those.

Their reviewer also reads a great many of these. Confident, specific, slightly boring answers move faster than expansive ones, and a claim that cannot be evidenced is worse than a gap.

“Not yet” is an acceptable answer

Nobody expects a twenty-person company to hold the certifications of a bank. What they will not accept is a claim that turns out to be untrue, which is the one failure mode that ends a review outright.

Where something is not in place, say so, say what you do instead, and give a date. “No formal penetration test yet; dependency scanning runs on every release and an external test is scheduled for Q4” is a perfectly good answer, and it is one you can be held to.

Fix the two that always come up

Single sign-on with MFA on every company application, and offboarding that actually removes access on the day someone leaves. These two carry more weight than anything else on the form, and both are a week of work rather than a project.

Assemble the evidence once

The reason the first one hurts and the fourth does not is that the answers are reusable. Keep a single folder: your access control policy, the offboarding checklist, a current list of sub-processors, your backup and restore procedure with the date of the last test, an incident response plan, and a network and data-flow diagram.

Put a review date on it twice a year. After that, a questionnaire is a copy-out exercise with a few new questions attached, and it stops being the thing that delays your largest deals.

Want us to run this exercise with you?

Send the process that costs you the most time. We'll reply with what could be automated this quarter and roughly what it takes.

Get in touch

Keep reading

All articles