Customers send security questionnaires to check that working with you won't put their data or systems at risk. Start by listing what you already do: multi-factor authentication, admin accounts, updates, backups, approved software, Office macros and an incident plan. Answer honestly, say what you're improving, and keep evidence for each answer.
Reviewed by Ben Webster
When a business shares its data or systems with a supplier, a weakness at the supplier becomes its weakness too. A security questionnaire is how it checks, before or during the relationship, that working with you won't put it at risk. Larger customers, and those with their own obligations to regulators or clients, are the most likely to ask.
A CertIQ report looks at your business from the outside, the way an attacker would first see it: whether your email can be spoofed, whether services are exposed to the internet, the health of your website certificate, forgotten subdomains and staff addresses in known breaches. That can support answers about your external exposure.
It can't see inside your business. Questions about policies, staff training, access reviews or how you handle a breach need your own answers. The report doesn't complete a questionnaire for you.
These are the seven topics CertIQ's self-assessment asks about. Most questionnaires cover them in some form, so writing down where you stand on each is a good first draft.
To see what your business looks like from the outside first, run a free CertIQ check.
No. A CertIQ report shows what can be seen of your business from the internet, such as email authentication, exposed services, website certificates and known breaches. Most questionnaires also ask about internal practices, policies and people, which an outside scan can't see. The report can support some answers; it doesn't replace them.
Say so, and say what you plan to do and by when. A clear answer with a plan is more useful to the customer than a vague yes, and a yes you can't back up can cause problems later if the customer relies on it.
Whoever knows how your systems are actually run, often with your IT provider. If an outside provider manages your email, devices or backups, ask them to confirm the answers that depend on their work.
Often. Many questionnaires ask about controls that match the Essential Eight, the baseline the Australian Signals Directorate recommends, such as multi-factor authentication, patching and backups. It is a sensible framework to describe what you do, but no questionnaire answer should claim a maturity level you haven't checked.
General information only, not financial or insurance advice. Talk to a licensed broker about your situation.
Enter your website and CertIQ scores your cyber health out of 100 in under 10 seconds, with a short Essential Eight self-assessment. Free, no account needed.
More answers: What is the Essential Eight? · Do I need cyber insurance? · How much does cyber insurance cost in Australia? · Can someone send email pretending to be my business?