We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Reputation and business risk

Reputation and business risk

The Enterprise Security Questionnaire: How to Answer 212 Questions Without Lying or Losing the Deal

How to answer a security questionnaire from a big customer without lying or losing the deal: the 212-question workbook, what 'yes' commits you to, a method.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The workbook with 212 rows

The founder of a 15-person data-analytics consultancy has just won her biggest client: a regional bank, a three-year engagement, enough to hire two more analysts. Then procurement sends the workbook. Twelve tabs, 212 questions, due in ten business days. "Do you maintain a formal information security policy approved by senior management?" "Are privileged accounts reviewed at least quarterly?" "Is audit logging enabled on all systems processing client data, and are logs retained for a minimum of twelve months?" "Do you perform annual security assessments of your subcontractors?"

She starts on a Sunday evening. The first thirty questions she answers from memory. The next fifty she answers by asking herself whether the thing is probably true. "Do you enforce multi-factor authentication for all users?" Mostly, she thinks. The two contractors in Manila, she is less sure about. Yes. "Are user access rights removed within 24 hours of termination?" The analyst who left in March still had a login in June, but that was fixed. Yes. "Are backups tested at least annually?" She has never seen a restore. Yes.

By Tuesday night the workbook is green. The bank signs. Eleven months later, after an incident at the consultancy that starts with one of the Manila contractors' accounts, the bank's counsel sends the workbook back with three rows highlighted and a question about what "yes" meant.

What the heck does this mean

A security questionnaire is the document a larger customer uses to decide whether your business is safe to connect to theirs. It is not a formality. The answers become part of the contract, and in a dispute they are read as representations you made.

Vendor security assessment, third-party risk management, supplier due diligence: different names for the same process on the customer's side. Their regulator asks them about their vendors, so they ask you.

A SIG is the standardized version of the questionnaire many banks use, in a short and a long form. A control is one specific safeguard the question is asking about: MFA on all accounts, quarterly access review, twelve-month log retention.

Evidence is what turns "yes" into a fact: a screenshot of the MFA policy, the last access-review spreadsheet, the log retention setting. A questionnaire answered without evidence is a wish list.

Here is the position I take with every founder who asks. A truthful "partially, and here is the date it will be done" wins more deals than a false "yes," because procurement teams have read thousands of workbooks and know what a wish list looks like. And it protects you on the day the workbook comes back highlighted.

The numbers that matter

Ninety-eight percent of organizations have a relationship with a third party that has been breached (SecurityScorecard, 2025). The bank knows this, which is why it sent the workbook.

Third parties were involved in 48% of breaches (Verizon 2026 DBIR). Nearly half the time, the way in was a vendor. From the bank's side of the table, you are the vendor.

Sixty-nine percent of monitored SaaS accounts in small-business tenants were unmanaged guest accounts (Kaseya 2026 SaaS Security Report). Every questionnaire now has a row about that, and in most small businesses the true answer is "we have not looked."

What to do this week

  1. Answer the access questions with a list, not a feeling. Export every user and guest account from your cloud tenant, mark who each one is, disable the ones nobody can name, and confirm MFA is on for every human, including contractors. Now "yes" has a date and a file behind it. (CIS 5 Account Management)
  2. Check the log settings on the systems that hold client data: is audit logging on, and how long is it kept? If the answer is 90 days, change it to twelve months this week and write down the date you did it. (CIS 8 Audit Log Management)
  3. List your own subcontractors and cloud providers, with what client data each touches. The bank's question about your vendors is the same question it is asking you, one step down the chain. (CIS 15 Service Provider Management)
  4. Build the evidence folder as you go: one file per question you answered "yes," named by question number. Next year's questionnaire from the next customer takes two days instead of ten. (CIS 15 Service Provider Management)
  5. For every "no," write a one-line remediation with a month. "Access reviews: not yet quarterly; first review completed 15 September, next scheduled 15 December." That sentence has won more deals than any green cell. (CIS 5 Account Management)
  6. Have someone other than the founder read the finished workbook and challenge every "yes" with "show me." If it cannot be shown, it is not yes. (CIS 8 Audit Log Management)

Where AccuSights fits

Our assessment answers the questionnaire the way the bank's reviewer will read it: we test each control the workbook asks about, tell you which "yes" answers are true today, and give you the evidence folder and a dated plan for the rest. The Cyber Hygiene Test takes three minutes and gives you a score you can quote. A 15-minute call with an engineer usually closes a third of the red rows.

We map the assessment to your regulators and to the questionnaire itself, and our read-only compliance agent shows which controls are in place and which have drifted, so you prioritize the right things and keep an eye on them. We have no access and do not remediate; you or your IT partner fix, and we show you where.

Questions people ask

What is a SIG questionnaire? The Standardized Information Gathering questionnaire is an industry-standard set of vendor security questions, published by Shared Assessments and used heavily by banks and insurers. It comes in a short Lite version and a long Core version with several hundred questions across domains like access control, incident management and business continuity. If a customer sends you a SIG, the good news is that the questions are the same ones every other customer will ask, so answering it once, truthfully, builds an answer library you will reuse.

Can I refuse to answer a security questionnaire? You can, and you will usually lose the deal. What you can do instead is negotiate the scope: ask which questions apply to the service you actually provide, offer an existing assessment report or certification in place of the sections it covers, and mark the rest "not applicable" with a one-line reason. Procurement teams accept a shorter, truthful answer set far more readily than a long one with gaps.

Does SOC 2 replace questionnaires? It shortens them. Most enterprise buyers will accept a current SOC 2 report in place of the sections it covers, which is often half the workbook. It does not remove the questions about your specific service, your subcontractors or the data flows unique to their deal. The practical value is that the report answers the same 80 questions for every customer, once, with an auditor's signature instead of your hopeful yes.

A questionnaire is a promise with your signature on it; make it one you would be comfortable reading aloud to the bank's lawyer.

Questions people ask

What is a SIG questionnaire?

The Standardized Information Gathering questionnaire is an industry-standard set of vendor security questions, published by Shared Assessments and used heavily by banks and insurers. It comes in a short Lite version and a long Core version with several hundred questions across domains like access control, incident management and business continuity. If a customer sends you a SIG, the good news is that the questions are the same ones every other customer will ask, so answering it once, truthfully, builds an answer library you will reuse.

Can I refuse to answer a security questionnaire?

You can, and you will usually lose the deal. What you can do instead is negotiate the scope: ask which questions apply to the service you actually provide, offer an existing assessment report or certification in place of the sections it covers, and mark the rest 'not applicable' with a one-line reason. Procurement teams accept a shorter, truthful answer set far more readily than a long one with gaps.

Does SOC 2 replace questionnaires?

It shortens them. Most enterprise buyers will accept a current SOC 2 report in place of the sections it covers, which is often half the workbook. It does not remove the questions about your specific service, your subcontractors or the data flows unique to their deal. The practical value is that the report answers the same 80 questions for every customer, once, with an auditor's signature instead of your hopeful yes.

Controls this post maps to

CIS 5 Account ManagementCIS 8 Audit Log ManagementCIS 15 Service Provider Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.