What a security questionnaire really asks: a line-by-line translation
Insights · Key IT · By Sam Triantis, Business Development Manager ·
Client and insurer security questionnaires ask the same ten things in disguise. What each question really means, what a strong answer looks like, and what to do when you can't tick the box.
It arrives as an attachment: "Please complete the attached security assessment before we can proceed." A big client, a tender, an insurance renewal — and suddenly forty rows of spreadsheet stand between you and the revenue. Here's what each question is actually asking, and what a strong answer looks like.
Security questionnaires have quietly become one of the most commercially important documents a small business fills in. Big companies now vet their suppliers' security because a supplier's breach is their breach; insurers ask because the answers set your premium — and whether you're covered at all. The frustrating part is the language: forty questions that sound like they were written by a lawyer and an engineer having an argument. The good news is that underneath the jargon, almost every questionnaire asks the same ten things.
The ten questions, translated
1. "Is multi-factor authentication enforced on all user accounts, including remote access?"
What they're really asking: can one stolen password sink you? Strong answer: MFA on everything — email, remote access, admin accounts, cloud apps — with no exemptions for directors. "Most accounts" is the answer they're trained to probe, because the exempted account is always the one that gets phished.
2. "Do you have a documented patch management process?"
Really asking: when a vulnerability is announced, how long are you exposed? The word doing the work is documented — "our IT guy keeps things updated" scores zero. Strong answer: defined patch windows with a fast lane for critical, actively exploited flaws — the Essential Eight expects those closed within 48 hours.
3. "Is endpoint detection and response (EDR) deployed on all devices?"
Really asking: if a machine is compromised, does anything notice? Old-style antivirus waits for known bad files; EDR watches behaviour. "All devices" includes the laptop of the person who works from home on Fridays.
4. "Are backups encrypted, kept offsite, and regularly tested?"
Really asking: if ransomware hits, do you pay? One word matters more than the rest: tested. An untested backup is a hope, not a control. Strong answer: immutable copies an attacker can't delete, restores actually performed and verified on a schedule you can name.
5. "Do you have a documented and tested incident response plan?"
Really asking: at 2am on the worst day, does everyone know their job — or do you improvise? Strong answer: a written plan naming who isolates systems, who calls the insurer and lawyer, who talks to clients — and evidence it's been walked through, not just written. Our incident response page covers what a real first hour looks like.
Really asking: will your people click the link? "We sent an email about phishing once" is not a program. Strong answer: recurring training with simulated phishing, and completion records you can produce.
7. "Are administrative privileges restricted and reviewed?"
Really asking: when an account is compromised, how much does the attacker get? If everyone's an admin, one phished bookkeeper owns the company. Strong answer: admin rights limited to the few who need them, separate from daily-use accounts, reviewed on a schedule.
8. "Have you experienced a security incident in the past 3–5 years?"
Really asking: will you tell us the truth? Counterintuitively, a disclosed incident with a mature response can read better than a suspicious clean sheet. What actually kills deals — and insurance claims — is the undisclosed incident that surfaces later. Answer honestly, always.
9. "Do you have 24/7 security monitoring or a Security Operations Centre?"
Really asking: is anyone watching between 6pm and 8am, when most attacks run? This is the question most small businesses answer "no" to — and one of the few where Key IT clients tick the strongest box available: monitoring by an in-house Melbourne SOC, not an outsourced feed nobody reads.
10. "Which security framework do you align with?"
Really asking: is your security a system or a pile of products? For Australian SMBs the expected answer is the ACSC Essential Eight — named maturity level, evidence available. Our ten-minute self-assessment tells you today what you'd currently have to write in that box.
The two answers that get businesses in real trouble
The aspirational yes. Ticking "yes" to MFA-everywhere because it's mostly true, or to "tested backups" because the backups exist. On a client questionnaire that's a contract breach waiting to be discovered; on an insurance proposal it's misrepresentation — the classic ground for a denied claim, discovered at the exact moment you need the policy to pay.
The unprovable yes. The control genuinely exists, but there's no evidence — no policy document, no training records, no restore logs. Questionnaires increasingly come with a follow-up: "please attach evidence." A yes you can't prove is treated as a no, just slower.
What to do when you can't tick the box
Answer honestly, with a date: "Not currently in place — being implemented, complete by [month]." Clients and insurers deal with hundreds of these; a credible roadmap keeps deals and policies alive, because what they're screening for isn't perfection — it's whether you take the question seriously. What kills you is the false yes, or a "no" with no plan attached. And the gaps a questionnaire finds are rarely exotic: they're MFA coverage, backup testing, admin sprawl — exactly the controls a competent provider closes in weeks, not years.
Turn the questionnaire from threat into weapon
Here's the reframe worth taking away: every one of your competitors bidding for that client or renewing that policy gets the same spreadsheet. Most will fumble it. A business that answers fast, honestly, with evidence attached, stands out in exactly the way that wins tenders and better premiums. Our clients forward us the questionnaire and get back completed answers with the evidence pack — because we run the controls, the documentation already exists.
FAQ
Frequently asked questions
Can we answer "yes" now and fix it afterwards?
Don't. On an insurance proposal a false answer is grounds for a denied claim; on a client questionnaire it can be a breach of contract discovered during their audit. An honest "no, with a remediation date" keeps both alive — a discovered false yes ends them.
Who should fill in a security questionnaire?
Whoever runs your IT and security, reviewed by an owner or director who understands the legal weight of the answers. If your IT provider can't fill it in from documentation they already hold, that's a finding in itself.
A tender gave us two weeks. Can gaps be closed that fast?
Some, yes — MFA enforcement, admin-privilege cleanup and backup configuration move in days. Others (training history, tested-restore records) take longer to have honest evidence for, which is why a dated roadmap is the right answer for those rows.
Do questionnaires from clients and insurers ask different things?
They overlap heavily — the ten questions above cover most of both. Insurers push harder on backups, EDR and incident history; big clients push harder on frameworks, data handling and your own suppliers. Same controls underneath.
The next step
If a questionnaire is sitting in your inbox right now, don't guess your way through it. Call 1300 053 948 and we'll go through it with you — or find out what you'd currently have to answer with our Essential 8 self-assessment or a free cybersecurity health check.