Use case

Getting through a customer's security review

A deal stalls on a security questionnaire nobody in the business can answer. The document is not the problem — it is the first time anyone has asked you to write down how you operate.

The situation

A large customer, or a customer in a regulated sector, sends a security questionnaire before signing. It runs to two hundred questions, uses vocabulary nobody in the business recognises, asks for policies that do not exist, and arrives with a deadline. The deal is otherwise agreed.

The instinct is to treat it as an administrative obstacle and answer optimistically to get past it. That is understandable and it is the wrong move, because the answers become contractual representations, and because the same questionnaire will arrive again from the next customer of that size.

The underlying situation is usually not that the business is insecure. It is that it has never written down how it operates, and the questionnaire is the first party to ask. That distinction matters, because the fix is smaller than it looks from inside the panic.

How it shows up

Symptom, cause and change

The most expensive mistake in this situation is treating a symptom as a diagnosis. These are the three columns kept apart.

Symptom, cause and change Each row reads left to right: what you notice, what is actually causing it, and what changes once it is addressed. Symptom Actual cause What changes The questionnaire has beensitting with whoever seemed mosttechnical for three weeks. Growth outpaced formality The deal moves Several answers would have to be"no" and nobody wants to be theone who writes it. Security was treated as atechnical topic The next one is routine There are no written policies,or there are policies that weredownloaded once and never Nobody had asked before Real risk is reduced Nobody can produce a list ofwhich suppliers hold customerdata. Suppliers accumulated quietly GDPR obligations are metincidentally
Each row reads left to right: what you notice, what is actually causing it, and what changes once it is addressed.

Why it happens

Growth outpaced formality
Practices that were fine at ten people were never written down as the business reached forty.
Security was treated as a technical topic
So it sat with whoever ran IT rather than being an operating question with an owner.
Nobody had asked before
Smaller customers do not send questionnaires, so the first one arrives with a large deal attached.
Suppliers accumulated quietly
Tools adopted by individual teams each hold some customer data and none went through review.
Offboarding was informal
Access was granted when needed and revoked when someone remembered, which is how former employees retain logins.

How we approach it

  1. Answer honestly, including the noes

    A "no, and here is our plan and date" is routinely accepted. A "yes" that turns out to be false is a contractual misrepresentation and, in the sectors most likely to send these documents, a serious one. Reviewers read a great many of these and can tell the difference between a business that is candid and one that is guessing.

  2. Find out where data actually is

    List every system holding customer data, including the ones adopted by a single team, and record what each holds, where it is processed and who has access. This inventory answers a large share of the questionnaire directly and is a GDPR obligation in its own right.

  3. Fix access first

    Multi-factor authentication everywhere, an access list reviewed against current staff, former employees removed, and shared credentials eliminated. This is the highest-impact work available, it is cheap, and it addresses what most breaches actually exploit rather than what questionnaires theorise about.

  4. Write the policies you will actually follow

    A short accurate document beats a long aspirational one. Reviewers verify a sample, and a policy describing a process nobody performs is worse than not having it, because it demonstrates that documents here do not correspond to reality.

  5. Establish the incident process before you need it

    Who is called, who decides, who notifies the customer and within what window — noting that customer contracts and GDPR both impose timescales. This is one of the questions most commonly answered aspirationally and most commonly tested when it matters.

  6. Build the reusable answer set

    Compile the completed questionnaire, the evidence and the policies into a maintained pack. The next questionnaire asks eighty per cent of the same things, and the difference between a week of panic and a day of assembly is whether this exists.

What changes

The deal moves
With honest answers and a dated remediation plan, which is what reviewers are generally looking for.
The next one is routine
A maintained answer pack turns a recurring emergency into an administrative task.
Real risk is reduced
Access control and supplier inventory address what actually causes incidents, not only what gets asked about.
GDPR obligations are met incidentally
The data inventory and processor list are requirements you already had.
Sales stops fearing large customers
The questionnaire ceases to be a reason to deprioritise the enterprise pipeline.
Certification becomes a decision
You can judge whether a formal standard is worth pursuing, rather than being pushed into it by the next deal.

Where it goes wrong

Answering optimistically is the most damaging shortcut available. The answers are representations, they are frequently referenced in the contract, and being caught out later costs the relationship rather than the deal.

Buying a policy template pack and filing it unchanged fails at the first sampling. Reviewers ask for evidence that a policy is followed, and a document describing a process nobody performs is actively worse than an honest gap.

Treating it as purely technical misses most of it. A large share of these questionnaires concerns process, people and suppliers rather than infrastructure.

Rushing into a formal certification because a customer mentioned it. Certification is a real commitment with recurring cost, and it is a poor way to solve a single deal.

Forgetting the supplier chain. If your subprocessors hold customer data, the customer's obligations flow through you to them, and an incomplete list is one of the fastest ways to fail a review.

Doing the work and not keeping it current. A pack that is eighteen months out of date is a liability, because it will be submitted by someone who assumes it is accurate.

What else you could do instead

There is more than one route through this, and the right one depends on how often you expect it to recur.

Answer this one and move on
Reasonable if enterprise customers are genuinely rare for you. The risk is that the work is repeated from scratch each time and the answers drift between submissions.
Build the reusable pack
The usual recommendation for a business moving upmarket. Higher effort once, considerably lower each time after.
Pursue a formal certification
Worth it when questionnaires are frequent and customers accept a certificate in place of one. It is a recurring commitment with real cost and should be chosen deliberately rather than reactively.
Decline the customer
Occasionally correct. If a customer's requirements imply a compliance posture that is genuinely disproportionate to the contract value, saying so is better than committing to something you will not maintain.

How we would know it worked

Before starting, record how long the current questionnaire has been open, how many questions cannot be answered at all, and how many people hold production access compared with how many should.

During the work, track the proportion of questions answerable from the pack without new investigation, and the number of identified gaps with an owner and a date.

Afterwards, the measure is elapsed time to complete the next questionnaire. If it is still weeks rather than days, the pack is not being maintained.

How long it takes and what it costs

An honest first pass at a questionnaire, with gaps identified and a remediation plan, is usually one to two weeks. This is frequently enough to unblock the deal.

The access and supplier inventory work is typically two to six weeks, and much of the access portion can be done in the first few days because it is largely configuration rather than change.

The reusable pack accumulates over the first two or three questionnaires rather than being produced once. Formal certification, if pursued, is a matter of months and a recurring commitment thereafter.

Estimates are labelled as estimates. Timelines here are planning ranges from comparable work, not commitments, and not measured client outcomes. We quote against a defined scope after a discovery call.

Services involved

Questions

Can we just answer yes to everything?

No, and it is the single most damaging option available. These answers are representations, they are frequently referenced contractually, and in regulated sectors a false one is serious. A candid "no, with a plan and a date" is routinely accepted; a discovered "yes" is not survivable.

Do we need a formal certification?

Only if questionnaires are frequent enough that a certificate saves more than it costs, and if your customers accept one in place of their own document. Pursuing certification to unblock a single deal is an expensive way to solve a small problem.

What is the highest-impact thing to fix first?

Access. Multi-factor authentication everywhere, an access list reconciled against current staff, former employees removed, shared credentials eliminated. It is cheap, it is quick, and it addresses what incidents actually exploit.

How honest is too honest?

There is no such thing in this document. Reviewers read many of these and a candid gap with a remediation date reads as competence. What damages credibility is inconsistency — answers that contradict each other or contradict what they find when they sample.

The questionnaire asks about our suppliers. Why?

Because their customer's obligations flow through you to anyone you use to process data. An incomplete subprocessor list is one of the most common reasons a review stalls, and assembling it is a GDPR requirement you already have.

We are a small company. Is this proportionate?

The questionnaire is usually written for larger suppliers, and saying so is legitimate. What matters is that your answers are accurate and that your controls are proportionate to the data you actually hold — not that you match a document designed for a multinational.

Who should own this internally?

One named person with authority across IT, operations and legal. It fails when it is passed to whoever seems most technical, because most of the content is about process and suppliers rather than infrastructure.

Will this delay the deal further?

An honest first pass with a remediation plan typically takes one to two weeks and usually unblocks it. What delays deals is a questionnaire sitting unanswered because nobody wants to write the first "no".

What does it cost?

Quoted per phase. The first pass and the access work are deliberately small and separable, because they resolve most of the immediate risk and most of the deal pressure before any larger decision is needed.

Other situations

Recognise this?

Tell us what it looks like in your business. We will tell you what we would do about it, and whether it is worth doing.

Get in touch

Tell us what you are trying to change

Describe the problem rather than the service — the two frequently differ, and working out which is which is the useful part of a first conversation. We reply within one working day, and if it is outside what we do well you will hear that in the reply rather than after a call.

We use what you send to reply to you. Nothing else, and no list.

WhatsApp