Skip to content

Security Questionnaires Worth Sending

Third-party assessment that produces information rather than a completed form.

Editorial team 2 min read

Most vendor security questionnaires measure the vendor's patience. A few produce useful information. The difference is what you ask and what you do with the answers.

Ask about this engagement

Generic questionnaires produce generic answers. The questions that matter depend on what the vendor will hold: where our data goes, who can access it, how access is logged, how it is deleted, who they subcontract to, and what happens when they are breached.

Prefer artefacts to assertions

A current audit report with its scope and exceptions, a penetration test summary, an architecture diagram, a subprocessor list, an incident response policy with real contact routes. One artefact beats fifty yes-or-no answers, and the exceptions section of an audit report is the most informative page you will receive.

Tier the effort

Not every supplier deserves the same scrutiny. Tier by data sensitivity, availability dependence and integration depth. A design tool with no customer data does not need the treatment given to a payroll processor.

Put it in the contract

A questionnaire answer is not binding; a contract clause is. The ones that earn their place: breach notification within a defined window, the right to audit or receive audit reports, subprocessor notification, data location, deletion on termination, and security requirements that survive renewal.

Reassess on change

Annual reassessment catches little. Reassess when the integration deepens, when the vendor is acquired, when they report an incident, or when the data they hold changes.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025