Use case
Getting through a customer's security review
A deal stalls on a security questionnaire nobody in the business can answer. The document is not the problem — it is the first time anyone has asked you to write down how you operate.
The situation
A large customer, or a customer in a regulated sector, sends a security questionnaire before signing. It runs to two hundred questions, uses vocabulary nobody in the business recognises, asks for policies that do not exist, and arrives with a deadline. The deal is otherwise agreed.
The instinct is to treat it as an administrative obstacle and answer optimistically to get past it. That is understandable and it is the wrong move, because the answers become contractual representations, and because the same questionnaire will arrive again from the next customer of that size.
The underlying situation is usually not that the business is insecure. It is that it has never written down how it operates, and the questionnaire is the first party to ask. That distinction matters, because the fix is smaller than it looks from inside the panic.
How it shows up
- The questionnaire has been sitting with whoever seemed most technical for three weeks.
- Several answers would have to be "no" and nobody wants to be the one who writes it.
- There are no written policies, or there are policies that were downloaded once and never followed.
- Nobody can produce a list of which suppliers hold customer data.
- Access to production systems is held by more people than anyone expected, including at least one former employee.
- The same questions were answered differently for a previous customer and nobody can find that document.
Symptom, cause and change
The most expensive mistake in this situation is treating a symptom as a diagnosis. These are the three columns kept apart.
Why it happens
- Growth outpaced formality
- Practices that were fine at ten people were never written down as the business reached forty.
- Security was treated as a technical topic
- So it sat with whoever ran IT rather than being an operating question with an owner.
- Nobody had asked before
- Smaller customers do not send questionnaires, so the first one arrives with a large deal attached.
- Suppliers accumulated quietly
- Tools adopted by individual teams each hold some customer data and none went through review.
- Offboarding was informal
- Access was granted when needed and revoked when someone remembered, which is how former employees retain logins.
How we approach it
Answer honestly, including the noes
A "no, and here is our plan and date" is routinely accepted. A "yes" that turns out to be false is a contractual misrepresentation and, in the sectors most likely to send these documents, a serious one. Reviewers read a great many of these and can tell the difference between a business that is candid and one that is guessing.
Find out where data actually is
List every system holding customer data, including the ones adopted by a single team, and record what each holds, where it is processed and who has access. This inventory answers a large share of the questionnaire directly and is a GDPR obligation in its own right.
Fix access first
Multi-factor authentication everywhere, an access list reviewed against current staff, former employees removed, and shared credentials eliminated. This is the highest-impact work available, it is cheap, and it addresses what most breaches actually exploit rather than what questionnaires theorise about.
Write the policies you will actually follow
A short accurate document beats a long aspirational one. Reviewers verify a sample, and a policy describing a process nobody performs is worse than not having it, because it demonstrates that documents here do not correspond to reality.
Establish the incident process before you need it
Who is called, who decides, who notifies the customer and within what window — noting that customer contracts and GDPR both impose timescales. This is one of the questions most commonly answered aspirationally and most commonly tested when it matters.
Build the reusable answer set
Compile the completed questionnaire, the evidence and the policies into a maintained pack. The next questionnaire asks eighty per cent of the same things, and the difference between a week of panic and a day of assembly is whether this exists.
What changes
- The deal moves
- With honest answers and a dated remediation plan, which is what reviewers are generally looking for.
- The next one is routine
- A maintained answer pack turns a recurring emergency into an administrative task.
- Real risk is reduced
- Access control and supplier inventory address what actually causes incidents, not only what gets asked about.
- GDPR obligations are met incidentally
- The data inventory and processor list are requirements you already had.
- Sales stops fearing large customers
- The questionnaire ceases to be a reason to deprioritise the enterprise pipeline.
- Certification becomes a decision
- You can judge whether a formal standard is worth pursuing, rather than being pushed into it by the next deal.
Where it goes wrong
Answering optimistically is the most damaging shortcut available. The answers are representations, they are frequently referenced in the contract, and being caught out later costs the relationship rather than the deal.
Buying a policy template pack and filing it unchanged fails at the first sampling. Reviewers ask for evidence that a policy is followed, and a document describing a process nobody performs is actively worse than an honest gap.
Treating it as purely technical misses most of it. A large share of these questionnaires concerns process, people and suppliers rather than infrastructure.
Rushing into a formal certification because a customer mentioned it. Certification is a real commitment with recurring cost, and it is a poor way to solve a single deal.
Forgetting the supplier chain. If your subprocessors hold customer data, the customer's obligations flow through you to them, and an incomplete list is one of the fastest ways to fail a review.
Doing the work and not keeping it current. A pack that is eighteen months out of date is a liability, because it will be submitted by someone who assumes it is accurate.
What else you could do instead
There is more than one route through this, and the right one depends on how often you expect it to recur.
- Answer this one and move on
- Reasonable if enterprise customers are genuinely rare for you. The risk is that the work is repeated from scratch each time and the answers drift between submissions.
- Build the reusable pack
- The usual recommendation for a business moving upmarket. Higher effort once, considerably lower each time after.
- Pursue a formal certification
- Worth it when questionnaires are frequent and customers accept a certificate in place of one. It is a recurring commitment with real cost and should be chosen deliberately rather than reactively.
- Decline the customer
- Occasionally correct. If a customer's requirements imply a compliance posture that is genuinely disproportionate to the contract value, saying so is better than committing to something you will not maintain.
How we would know it worked
Before starting, record how long the current questionnaire has been open, how many questions cannot be answered at all, and how many people hold production access compared with how many should.
During the work, track the proportion of questions answerable from the pack without new investigation, and the number of identified gaps with an owner and a date.
Afterwards, the measure is elapsed time to complete the next questionnaire. If it is still weeks rather than days, the pack is not being maintained.
How long it takes and what it costs
An honest first pass at a questionnaire, with gaps identified and a remediation plan, is usually one to two weeks. This is frequently enough to unblock the deal.
The access and supplier inventory work is typically two to six weeks, and much of the access portion can be done in the first few days because it is largely configuration rather than change.
The reusable pack accumulates over the first two or three questionnaires rather than being produced once. Formal certification, if pursued, is a matter of months and a recurring commitment thereafter.
Estimates are labelled as estimates. Timelines here are planning ranges from comparable work, not commitments, and not measured client outcomes. We quote against a defined scope after a discovery call.
Services involved
Cloud, DevOps & Infrastructure
The layer everything else runs on — deployed reproducibly, monitored properly, backed up in a way that has actually been tested.
Read more →Digital Transformation Consulting
Working out what to do, in what order, before anyone spends money building it.
Read more →Systems Integration
Making the systems you already pay for talk to each other, reliably, without a person in the middle re-typing things.
Read more →Maintenance & Ongoing Support
Keeping what has been built working — patched, monitored, backed up and quietly improved, with a response window written into a contract.
Read more →Business Process Automation
Removing the manual steps between systems — the copying, re-typing, chasing and exporting that consumes hours nobody counts.
Read more →CRM & Sales Systems
The system of record for revenue: where leads land, how they are routed, what happens next, and whether anyone can see the truth of the pipeline.
Read more →Questions
Can we just answer yes to everything?
No, and it is the single most damaging option available. These answers are representations, they are frequently referenced contractually, and in regulated sectors a false one is serious. A candid "no, with a plan and a date" is routinely accepted; a discovered "yes" is not survivable.
Do we need a formal certification?
Only if questionnaires are frequent enough that a certificate saves more than it costs, and if your customers accept one in place of their own document. Pursuing certification to unblock a single deal is an expensive way to solve a small problem.
What is the highest-impact thing to fix first?
Access. Multi-factor authentication everywhere, an access list reconciled against current staff, former employees removed, shared credentials eliminated. It is cheap, it is quick, and it addresses what incidents actually exploit.
How honest is too honest?
There is no such thing in this document. Reviewers read many of these and a candid gap with a remediation date reads as competence. What damages credibility is inconsistency — answers that contradict each other or contradict what they find when they sample.
The questionnaire asks about our suppliers. Why?
Because their customer's obligations flow through you to anyone you use to process data. An incomplete subprocessor list is one of the most common reasons a review stalls, and assembling it is a GDPR requirement you already have.
We are a small company. Is this proportionate?
The questionnaire is usually written for larger suppliers, and saying so is legitimate. What matters is that your answers are accurate and that your controls are proportionate to the data you actually hold — not that you match a document designed for a multinational.
Who should own this internally?
One named person with authority across IT, operations and legal. It fails when it is passed to whoever seems most technical, because most of the content is about process and suppliers rather than infrastructure.
Will this delay the deal further?
An honest first pass with a remediation plan typically takes one to two weeks and usually unblocks it. What delays deals is a questionnaire sitting unanswered because nobody wants to write the first "no".
What does it cost?
Quoted per phase. The first pass and the access work are deliberately small and separable, because they resolve most of the immediate risk and most of the deal pressure before any larger decision is needed.
Other situations
- Replacing spreadsheets with a real system
- Cutting cost per qualified lead
- Launching in a new European market
- Making company knowledge searchable
- Automating quote to invoice
- Recovering from a failed migration
- Inheriting undocumented software
- Merging systems after an acquisition
- Opening a second location
Recognise this?
Tell us what it looks like in your business. We will tell you what we would do about it, and whether it is worth doing.
Get in touch