Security reviews
Answering questionnaires, audits and client due diligence
The risk is not failing one. It is passing it inaccurately. I help licensed firms answer from what is actually configured rather than from the manual, and then get to a position where the next one is routine rather than a scramble.
If one has already arrived
There are three normal responses and none of them is unreasonable. Each produces a document you cannot stand behind.
Forward it to the IT provider
They answer what they control and answer optimistically about what they do not. Nobody is misleading anyone, and the finished document still says things nobody verified.
Copy it from the manual
The manual describes what the controls should be. Copying it across turns a statement of intent into a statement of fact, which is a different thing entirely.
Tick yes and move on
Most answers are probably close to true, the deadline is real, and the alternative is admitting you do not know. The most common response and the most expensive one.
If nothing has arrived yet
Then you are in the better position, and it is worth using. Getting the answers straight when there is no deadline costs a fraction of doing it under one, and it is the difference between a review being routine and a review being a fortnight of everyone dropping what they were doing.
This is most of the work I do. Not incident response, but keeping a firm in a position where the question can be answered on the day it is asked. If you are looking for someone to hold that standing rather than to arrive in a crisis, that is the arrangement I would suggest.
The answer you are tempted to give
A completed questionnaire is not a form. It is a set of written representations about your firm, made to a counterparty, and it frequently ends up attached to a contract or referenced by one.
That changes what a wrong answer costs. Failing a review loses you a deal, which is bad and recoverable. Passing one inaccurately means that if something goes wrong eighteen months from now, the conversation is no longer about a security incident. It is about what you told them in writing and whether it was true. The same applies to an insurance renewal priced on the answers you gave.
And most firms get this wrong in the other direction. An honest no, with a plan and a date against it, is usually received better than a confident yes. Reviewers read these all day and are accustomed to optimism. A firm that says "not yet, here is the plan, here is when" reads as one that knows its own estate. That is a stronger signal than a clean sheet, and considerably safer.
How we would work
Three shapes
Answer the one in front of you
Days
I go through the questionnaire with you and establish what is actually true by checking rather than asking. You get answers you can evidence, gaps stated honestly with a date against each, and the working behind every answer so you can defend it if challenged.
Close what it exposed
Scoped after
A questionnaire is a free gap analysis somebody else wrote for you. Access reduced and reviewed, MFA that resists phishing, device compliance, logging retained and monitored. Fixed scope, agreed before it starts.
Keep it answerable
Ongoing
The reviews keep coming, and the position drifts between them. Access reviews that actually happen, configuration kept documented, records where an auditor expects them. The next questionnaire becomes an afternoon.
The order matters. Establishing what is true comes before fixing anything, because half of what a firm plans to remediate turns out to be working and some of what it assumes is fine turns out not to be. On one engagement a security uplift tracker had materially under-reported its own status, and reconciling it against what was actually deployed was its own piece of work.
What you end up with
Questions that took a fortnight of asking around become queries against something that was already collecting the answer. Logging with a stated retention. Access reviews with a record of who reviewed what and when. Configuration held as code, so the current state is inspectable rather than remembered. Changes documented with a reverse command and a reason, which is also what an auditor wants to see.
Where this has been done
The three pieces a questionnaire asks about most often: what is being logged and for how long, who holds privileged access, and whether the framework covers the technology layer at all.
A$160
monthly run cost for the full monitored estate
Security monitoring and evidence retention975
privileged directory role assignments on the primary administrative account
Privileged access and endpoint hardening13
policies added across the IT, cyber and privacy layer
Compliance manual and coverage map
Tell me where you are
If something has arrived, say what it is and when the answer is due. If nothing has and you would rather it never became a scramble, say that instead. Both are worth a conversation and the second one is cheaper.
If a deadline is too close for the work to be done properly I will say so rather than take it, and I can usually suggest how to answer honestly in the time you have. Your existing IT provider often has to implement part of the answer, and I would rather bring them in early than hand them a finding. Where you do not have one, I can cover that side as well.