Blog / Reputation and business risk
Reputation and business risk
The Enterprise Security Questionnaire: How to Answer 212 Questions Without Lying or Losing the Deal
How to answer a security questionnaire from a big customer without lying or losing the deal: the 212-question workbook, what 'yes' commits you to, a method.
The workbook with 212 rows
The founder of a 15-person data-analytics consultancy has just won her biggest client: a regional bank, a three-year engagement, enough to hire two more analysts. Then procurement sends the workbook. Twelve tabs, 212 questions, due in ten business days. "Do you maintain a formal information security policy approved by senior management?" "Are privileged accounts reviewed at least quarterly?" "Is audit logging enabled on all systems processing client data, and are logs retained for a minimum of twelve months?" "Do you perform annual security assessments of your subcontractors?"
She starts on a Sunday evening. The first thirty questions she answers from memory. The next fifty she answers by asking herself whether the thing is probably true. "Do you enforce multi-factor authentication for all users?" Mostly, she thinks. The two contractors in Manila, she is less sure about. Yes. "Are user access rights removed within 24 hours of termination?" The analyst who left in March still had a login in June, but that was fixed. Yes. "Are backups tested at least annually?" She has never seen a restore. Yes.
By Tuesday night the workbook is green. The bank signs. Eleven months later, after an incident at the consultancy that starts with one of the Manila contractors' accounts, the bank's counsel sends the workbook back with three rows highlighted and a question about what "yes" meant.
What the heck does this mean
A security questionnaire is the document a larger customer uses to decide whether your business is safe to connect to theirs. It is not a formality. The answers become part of the contract, and in a dispute they are read as representations you made.
Vendor security assessment, third-party risk management, supplier due diligence: different names for the same process on the customer's side. Their regulator asks them about their vendors, so they ask you.
A SIG is the standardized version of the questionnaire many banks use, in a short and a long form. A control is one specific safeguard the question is asking about: MFA on all accounts, quarterly access review, twelve-month log retention.
Evidence is what turns "yes" into a fact: a screenshot of the MFA policy, the last access-review spreadsheet, the log retention setting. A questionnaire answered without evidence is a wish list.
Here is the position I take with every founder who asks. A truthful "partially, and here is the date it will be done" wins more deals than a false "yes," because procurement teams have read thousands of workbooks and know what a wish list looks like. And it protects you on the day the workbook comes back highlighted.
The numbers that matter
Ninety-eight percent of organizations have a relationship with a third party that has been breached (SecurityScorecard, 2025). The bank knows this, which is why it sent the workbook.
Third parties were involved in 48% of breaches (Verizon 2026 DBIR). Nearly half the time, the way in was a vendor. From the bank's side of the table, you are the vendor.
Sixty-nine percent of monitored SaaS accounts in small-business tenants were unmanaged guest accounts (Kaseya 2026 SaaS Security Report). Every questionnaire now has a row about that, and in most small businesses the true answer is "we have not looked."
What to do this week
- Answer the access questions with a list, not a feeling. Export every user and guest account from your cloud tenant, mark who each one is, disable the ones nobody can name, and confirm MFA is on for every human, including contractors. Now "yes" has a date and a file behind it. (CIS 5 Account Management)
- Check the log settings on the systems that hold client data: is audit logging on, and how long is it kept? If the answer is 90 days, change it to twelve months this week and write down the date you did it. (CIS 8 Audit Log Management)
- List your own subcontractors and cloud providers, with what client data each touches. The bank's question about your vendors is the same question it is asking you, one step down the chain. (CIS 15 Service Provider Management)
- Build the evidence folder as you go: one file per question you answered "yes," named by question number. Next year's questionnaire from the next customer takes two days instead of ten. (CIS 15 Service Provider Management)
- For every "no," write a one-line remediation with a month. "Access reviews: not yet quarterly; first review completed 15 September, next scheduled 15 December." That sentence has won more deals than any green cell. (CIS 5 Account Management)
- Have someone other than the founder read the finished workbook and challenge every "yes" with "show me." If it cannot be shown, it is not yes. (CIS 8 Audit Log Management)
Where AccuSights fits
Our assessment answers the questionnaire the way the bank's reviewer will read it: we test each control the workbook asks about, tell you which "yes" answers are true today, and give you the evidence folder and a dated plan for the rest. The Cyber Hygiene Test takes three minutes and gives you a score you can quote. A 15-minute call with an engineer usually closes a third of the red rows.
We map the assessment to your regulators and to the questionnaire itself, and our read-only compliance agent shows which controls are in place and which have drifted, so you prioritize the right things and keep an eye on them. We have no access and do not remediate; you or your IT partner fix, and we show you where.
Questions people ask
What is a SIG questionnaire? The Standardized Information Gathering questionnaire is an industry-standard set of vendor security questions, published by Shared Assessments and used heavily by banks and insurers. It comes in a short Lite version and a long Core version with several hundred questions across domains like access control, incident management and business continuity. If a customer sends you a SIG, the good news is that the questions are the same ones every other customer will ask, so answering it once, truthfully, builds an answer library you will reuse.
Can I refuse to answer a security questionnaire? You can, and you will usually lose the deal. What you can do instead is negotiate the scope: ask which questions apply to the service you actually provide, offer an existing assessment report or certification in place of the sections it covers, and mark the rest "not applicable" with a one-line reason. Procurement teams accept a shorter, truthful answer set far more readily than a long one with gaps.
Does SOC 2 replace questionnaires? It shortens them. Most enterprise buyers will accept a current SOC 2 report in place of the sections it covers, which is often half the workbook. It does not remove the questions about your specific service, your subcontractors or the data flows unique to their deal. The practical value is that the report answers the same 80 questions for every customer, once, with an auditor's signature instead of your hopeful yes.
A questionnaire is a promise with your signature on it; make it one you would be comfortable reading aloud to the bank's lawyer.
Questions people ask
What is a SIG questionnaire?
The Standardized Information Gathering questionnaire is an industry-standard set of vendor security questions, published by Shared Assessments and used heavily by banks and insurers. It comes in a short Lite version and a long Core version with several hundred questions across domains like access control, incident management and business continuity. If a customer sends you a SIG, the good news is that the questions are the same ones every other customer will ask, so answering it once, truthfully, builds an answer library you will reuse.
Can I refuse to answer a security questionnaire?
You can, and you will usually lose the deal. What you can do instead is negotiate the scope: ask which questions apply to the service you actually provide, offer an existing assessment report or certification in place of the sections it covers, and mark the rest 'not applicable' with a one-line reason. Procurement teams accept a shorter, truthful answer set far more readily than a long one with gaps.
Does SOC 2 replace questionnaires?
It shortens them. Most enterprise buyers will accept a current SOC 2 report in place of the sections it covers, which is often half the workbook. It does not remove the questions about your specific service, your subcontractors or the data flows unique to their deal. The practical value is that the report answers the same 80 questions for every customer, once, with an auditor's signature instead of your hopeful yes.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
CBUAE Cyber Rules for Fintechs and the Suppliers Who Serve Banks
CBUAE cybersecurity framework explained for a small fintech or bank supplier: which regulations reach you, why the bank's questionnaire exists, and what to fix.
UAE complianceDIFC, ADGM or Federal PDPL: Which Data Rules Apply to Your Free-Zone Company
DIFC Data Protection Law, ADGM regulations or federal PDPL: how to tell which one governs your data, what changes at the free-zone boundary, and what to fix.
ThreatsInsider Risk in 2026: The Disgruntled Admin, the Careless Contractor and the Remote Hire Who Is Not Who You Think
Insider threat now includes the remote developer whose laptop lives in a stranger's house. How to verify hires, cut access on exit day, and watch the logs.
