Sales lead or owner chasing an enterprise contract
“A big client sent a security questionnaire and we cannot answer half of it”
Does this sound familiar?
- A prospect's procurement team sent a vendor security assessment
- Your insurer is asking questions you cannot answer honestly
- A prime contractor requires evidence of security controls
- The questionnaire asks for policies that have never been written down
- The contract is stalled pending your response
What it costs to ignore
These questionnaires are contract gates. An incomplete or obviously invented response stalls or loses the deal, and overstating controls creates real liability if an incident later shows the answers were false. Meanwhile the deal sits unsigned while your competitor answers theirs.
How the engagement runs
- 1
Work through the questionnaire honestly
We go item by item and establish what is true today. Many organisations already meet more requirements than they realise — they simply have no documentation proving it.
- 2
Separate the real gaps from the paperwork gaps
Some answers need engineering work. Many only need a written policy describing what you already do. Knowing which is which keeps the cost proportionate.
- 3
Fix what actually matters
Prioritised by genuine risk and by what the client is going to verify, not by what is cheapest to claim.
- 4
Write the documentation
Access control, incident response, backup and business continuity, data handling, vendor management. Written so they are followable, not just filed.
- 5
Answer, with evidence behind each item
A completed questionnaire you can defend under scrutiny, with something real behind every 'yes'.
The questionnaire is a sales blocker, not an IT task
It usually arrives at the worst moment: the deal is nearly closed, and procurement sends forty questions about encryption at rest, incident response plans, access reviews and sub-processors.
The instinct is to guess generously and move on. That is the one genuinely dangerous option — you are signing a document asserting controls you may not have, which becomes very awkward if anything ever goes wrong.
Most companies are closer than they think
Working through these, the pattern is consistent: a good share of the answers are already true and simply undocumented. You do have backups. You do restrict access. Nobody ever wrote it down.
So the work splits cleanly:
- Paperwork gaps — things you already do, needing a short written policy
- Real gaps — things you genuinely do not do, which need fixing or an honest “not currently, planned for Q3”
That distinction keeps the cost proportionate, and an honest roadmap answer is usually accepted. A false “yes” is not.
What you keep afterwards
A reusable evidence pack. The next client’s questionnaire becomes a mapping exercise instead of a fire drill, and the same documentation supports your cyber insurance renewal.
What you get
- A completed questionnaire you can stand behind
- Gap assessment separating engineering work from documentation work
- Written security policies proportionate to your size
- Remediation of the gaps that genuinely matter
- An incident response plan naming real people
- A reusable evidence pack for the next client who asks
Frequently asked questions
Can you just fill it in for us?
We will not invent answers, and you should be wary of anyone who offers to. Overstating controls is a liability: if an incident later reveals the answers were false, you have signed a document asserting protections you did not have. We establish what is true, fix what is worth fixing, and then answer accurately — which is also what survives the follow-up questions.
We are twelve people. Do we really need written policies?
For contracts with enterprise clients, yes — but proportionate ones. A twelve-person company does not need a hundred-page manual. It needs a handful of short documents describing what actually happens, that staff can follow and that an auditor can read. Oversized policies nobody follows are worse than none, because they are evidence you do not operate your own controls.
How long does this take?
Two to four weeks for most small and mid-sized businesses, assuming the gaps are ordinary. The assessment is fast; the timeline is driven by whatever remediation turns out to be necessary.
Will this help with cyber insurance too?
Substantially. Insurers ask a very similar set of questions, and the same evidence pack serves both. Increasingly, insurers require multi-factor authentication and tested backups as conditions of coverage — if you cannot demonstrate those, premiums rise or coverage is refused.
Do we have to do this again for every client?
No, and that is the point of building an evidence pack rather than a one-off answer. The underlying documentation is reusable; each new questionnaire becomes a mapping exercise rather than a project.
Services involved
Cybersecurity
Incident response, ransomware recovery, and hardening that holds up under audit.
Learn moreInfrastructure & Backup
Servers, clusters and backups designed so that failure is survivable and boring.
Learn moreEngineering Services
Systems and certification rigour from 25+ years in safety-critical aerospace.
Learn moreTell us what is breaking — or what you are trying to build.
You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.
Active incident? Write “URGENT” in your message and we prioritise it.