~$ rebootworks
IT & security

can you help us pass a client security questionnaire?

yes. this comes up constantly when you start selling to larger companies. we'll answer the technical sections, write the policies you're missing, and fix the gaps the questionnaire exposes rather than wording around them.

the pattern is always the same. a bigger prospect is ready to sign, then procurement sends a long spreadsheet: do you encrypt data at rest, do you have an incident response plan, when was your last penetration test, attach your access control policy. the deal now depends on answers to questions nobody at your company has had to think about, and the person filling it in is usually a founder with a deadline.

how we handle it

  1. we answer the technical sections: hosting, encryption, backups, authentication, logging, dependency management. these are questions about how your systems actually work, and answering them well takes someone who can read the infrastructure rather than guess at it.
  2. where a policy doesn't exist, we write it. most questionnaires ask for documents: an information security policy, an access control policy, an incident response plan. ours are short, describe what you actually do, and are something you can keep to.
  3. we fix what the questionnaire exposes. a questionnaire is a free audit. when a row asks whether MFA is enforced on every admin account and the honest answer is no, turn it on this week and answer yes. a paragraph that sounds like yes is a commitment you've made, and a later audit or breach turns it into a much bigger problem than the original gap.

the row that always comes up

"date of your last penetration test" is the one most small companies can't fill in. if a questionnaire is coming, a test done first gives you that date, a report with the scope documented and, if we find nothing, a clean one to attach. a customer asking you a security question is one of the signs we list in what a technical partner does that it's time for someone to own this.

read it in context