Skip to content
Coverwright
← Notes
August 1, 2026 · 6 min read

A client sent you a security questionnaire. Now what?

A spreadsheet of security questions from your biggest customer is a procurement step, not an exam. What it is really testing, why “no” beats a generous “yes”, and how to answer it once and reuse it.

It usually arrives from the biggest client you have, forwarded by someone you have never spoken to, with a deadline attached. Eighty rows of questions about encryption at rest, offboarding procedures and sub-processors, aimed at a firm of eleven people who have never had a reason to use the phrase “sub-processor”.

Two things make this less alarming. It is not personal — you almost certainly landed in a vendor category that triggers a review automatically, and everyone in that category got the same spreadsheet. And it is not an exam with a pass mark. It is a risk assessment, and the reviewer’s job is to work out what could go wrong through you and whether anyone is managing it.

What the reviewer is actually looking for

Reviewers see hundreds of these. Experienced ones are reading for three signals, none of which is a perfect score:

  • Do they know what they hold? A vendor who cannot say what client data they have, where it lives, or who can reach it is a risk regardless of how many controls they claim.
  • Is someone accountable? A named person responsible for security, even part-time and even if it is the owner, changes how the whole response reads.
  • Are the answers consistent and plausible? A small firm claiming every control at enterprise maturity is a less credible respondent than one with a few honest gaps and a date against each.

The size of your firm is not itself a problem. Nobody expects eleven people to run a 24/7 security operations centre. What raises concern is a mismatch between what you claim and what your size makes plausible.

Why a generous “yes” is the worst answer

The temptation is to answer as the business you intend to be by the end of the quarter. Resist it, for a reason that is entirely self-interested rather than moral.

Your answers do not disappear once the deal closes. They typically get attached to the contract, referenced by a security addendum, or reproduced as warranties — so an overstated control becomes a contractual representation. If an incident later traces back to the thing you said you had, the conversation is not about security any more; it is about what you told them in writing. That is a materially worse position than having disclosed a gap and been asked to close it by a date.

In practice, honest gaps rarely lose the deal on their own. What loses deals is non-response, evasion, or answers that fall apart under one follow-up question.

How to answer the questions you cannot answer

Three specific moves handle most of the difficult rows:

  • Distinguish “no” from “not applicable”. If a question asks about the security of your data centre and you have no data centre, the answer is not “no” — it is that you use a named cloud provider and here is who is responsible for what. Answering “no” to controls that were never yours to hold makes an otherwise reasonable response look alarming.
  • Say who does hold it. Most controls at a small firm are inherited from a vendor — your email provider, your cloud storage, your payroll system. Naming the provider and the boundary is a complete answer, and it demonstrates you understand the split, which is itself one of the things being assessed.
  • Pair a “no” with a date and an owner. “Not currently enabled on administrator accounts; scheduled by the end of next month, owned by the managing director” is a fundamentally different answer from a bare “no”, and reviewers read it that way.

Answer it once

The mistake that costs the most time is treating each questionnaire as a fresh writing project. The second one arrives four months later from a different client in a different format, and everything gets rebuilt from memory — which is also how two clients end up holding two inconsistent answers to the same question about your business.

Build the underlying material once and map it to each new form:

  • A written security policy — the document most questionnaires ask to be attached, and which answers a surprising share of the rows on its own.
  • An incident response plan, including how and when you would notify an affected client.
  • A list of the vendors that touch client data, and who secures what between you and them.
  • An honest inventory of the controls you have and the gaps you are working on, with owners and dates.

With those in hand, a new questionnaire is an afternoon of mapping rather than a week of drafting, and every client gets the same story because there is only one.

This is the situation Coverwright was built for. The same answers produce the policy and the plan a questionnaire asks to be attached, a vendor responsibility matrix showing where your obligations stop and a provider’s begin, and a readiness summary listing the controls in place and the gaps as gaps — with a first step against each, so a “no” arrives with a date rather than on its own.