customer #1 sent a 92-question security questionnaire and i am one person with a laptop
Forty person company, the deal is 79 a month, and their IT person has sent me a spreadsheet with 92 rows. It asks about background check policy for staff, physical access logs for our data centre, and the rota for our incident response team.
I have no staff, no data centre and no rota. I have a managed database, a hosting provider and a very boring backup script.
Do I answer honestly and watch the deal evaporate, do I answer the way they clearly want to hear, or do I tell them politely that this is not proportionate for 79 a month. Genuinely unsure which of those is the professional move.
@warranty_wes · 2mo ago · 2 replies
Answer honestly, and answer in the language of the control rather than the question.
For the staff questions, "sole proprietor, no employees, therefore no background check programme; access to production is limited to one named individual with hardware backed two factor" is a complete and truthful answer. For the data centre ones, you name your hosting provider and point at their compliance page, because that is literally the control. Their auditor is used to that answer, it is how every small vendor answers it.
Write four things once and reuse them forever: a one page security overview, a subprocessor list with what data each one sees, your data retention and deletion behaviour, and how someone reports a vulnerability to you. That pack answers most of the spreadsheet.
Then email their security contact and ask which items are blocking versus informational. On mine it was six.
Reply
Report
@zigbee_zoe · 2mo ago
Asking which ones are blocking took mine from ninety two to nine. The person who sent it is usually more annoyed by the spreadsheet than you are, they inherited it, and they will happily tell you which rows their boss actually reads.
Reply
Report