All professional firms
How to answer a client security questionnaire
· PS ProTech
A long-standing client sends a spreadsheet with a hundred and fifty questions about encryption, access reviews and incident response. It is due in two weeks, and the relationship partner forwards it to whoever "does the IT".
This is now routine. Larger companies are required to assess the suppliers who handle their data, and professional firms are among those suppliers. How you respond affects whether you keep the work.
Understand what they are asking
Most questionnaires cover the same ground under different headings:
- Access: who can reach client data, and whether multi-factor authentication is enforced.
- Devices: whether laptops are encrypted, patched and protected.
- Data handling: where data is stored, how it is shared and when it is deleted.
- Resilience: backups, recovery testing and continuity plans.
- People: background checks, training and confidentiality terms.
- Incidents: how you detect a breach and how quickly you tell the client.
- Vendors: which third parties you pass their data to.
Answer honestly
Never answer "yes" to a control you don't have. These responses are often incorporated into your engagement terms, and a false answer discovered after a breach is far more damaging than a gap disclosed up front.
For each question there are three good answers:
- Yes, and here is the evidence. A policy, a screenshot or a report.
- Partly, and here is the plan. State what is in place and give a date for the rest.
- No, and here is why it doesn't apply or what we do instead. A ten-person firm does not need every control a bank has.
Clients expect some gaps from smaller firms. What they look for is whether you understand your own environment.
Build an answer library
The second questionnaire should take a fraction of the time of the first. Keep a document with your standard answers and the evidence for each, and update it when something changes.
The core evidence pack for a small firm is modest:
- A written information security policy
- A record of MFA being enforced on email and document systems
- A device inventory showing encryption and patch status
- Backup reports and a recent restore test
- Training completion records
- A one-page incident response plan
Use the gaps as a to-do list
A questionnaire is a free audit. The questions you could not answer well tell you what to fix first, and fixing them makes the next questionnaire easier and your cyber insurance renewal smoother.
Answering these with you is part of our service. If one has just landed in your inbox, talk to us.
