CertIQ

A customer sent me a cyber security questionnaire. Where do I start?

Customers send security questionnaires to check that working with you won't put their data or systems at risk. Start by listing what you already do: multi-factor authentication, admin accounts, updates, backups, approved software, Office macros and an incident plan. Answer honestly, say what you're improving, and keep evidence for each answer.

Reviewed by Ben Webster

Why customers send them

When a business shares its data or systems with a supplier, a weakness at the supplier becomes its weakness too. A security questionnaire is how it checks, before or during the relationship, that working with you won't put it at risk. Larger customers, and those with their own obligations to regulators or clients, are the most likely to ask.

What a CertIQ report can show, and what it can't

A CertIQ report looks at your business from the outside, the way an attacker would first see it: whether your email can be spoofed, whether services are exposed to the internet, the health of your website certificate, forgotten subdomains and staff addresses in known breaches. That can support answers about your external exposure.

It can't see inside your business. Questions about policies, staff training, access reviews or how you handle a breach need your own answers. The report doesn't complete a questionnaire for you.

A starting checklist

These are the seven topics CertIQ's self-assessment asks about. Most questionnaires cover them in some form, so writing down where you stand on each is a good first draft.

  1. Multi-factor authentication. Is it required on every staff account, especially email and remote access?
  2. Admin accounts. Do people with admin access use a separate account for admin work?
  3. Updates. Are security updates installed promptly on computers, servers and apps?
  4. Backups. Are backups regular, kept where an attacker can't change them, and tested by restoring?
  5. Approved software. Can staff install anything, or only approved programs?
  6. Office macros. Are macros blocked, or limited to ones you trust?
  7. Incident plan. Is there a written plan for a cyber incident, and has anyone walked through it?

Answering well

To see what your business looks like from the outside first, run a free CertIQ check.

Common questions

Does a CertIQ report complete the questionnaire for me?

No. A CertIQ report shows what can be seen of your business from the internet, such as email authentication, exposed services, website certificates and known breaches. Most questionnaires also ask about internal practices, policies and people, which an outside scan can't see. The report can support some answers; it doesn't replace them.

What if the honest answer is no?

Say so, and say what you plan to do and by when. A clear answer with a plan is more useful to the customer than a vague yes, and a yes you can't back up can cause problems later if the customer relies on it.

Who should fill it in?

Whoever knows how your systems are actually run, often with your IT provider. If an outside provider manages your email, devices or backups, ask them to confirm the answers that depend on their work.

Is the Essential Eight relevant?

Often. Many questionnaires ask about controls that match the Essential Eight, the baseline the Australian Signals Directorate recommends, such as multi-factor authentication, patching and backups. It is a sensible framework to describe what you do, but no questionnaire answer should claim a maturity level you haven't checked.

Sources

General information only, not financial or insurance advice. Talk to a licensed broker about your situation.

See where your business stands.

Enter your website and CertIQ scores your cyber health out of 100 in under 10 seconds, with a short Essential Eight self-assessment. Free, no account needed.

More answers: What is the Essential Eight? · Do I need cyber insurance? · How much does cyber insurance cost in Australia? · Can someone send email pretending to be my business?