Ask
298
@cors_error_cleo ·

customer number three sent a 74 question security questionnaire and wants a signed dpa - answer it or walk

A 60 person company wants to buy the $89 a month plan. Their procurement sent a spreadsheet with 74 questions covering encryption, penetration testing, incident response, employee background checks and business continuity, plus a data processing agreement to sign.

I am one person. The honest answer to about twenty of those questions is no or not applicable. At $1,068 a year I cannot tell whether this is a customer or a research project.

Do people answer these at this size, and does saying no to half the questions automatically kill the deal?

9 answers Share
Report

Answering anonymously — a moderator will review it first.

  • @stdlib_stef · 6mo ago · 3 replies

    Answer it, honestly, and do not pretend. Reviewers see a lot of these and an inflated one is obvious and fatal. A clean no with a sentence explaining what you do instead reads as competent. A yes you cannot evidence reads as a liability.

    So for background checks: no, single person company, here is the identity verification my payment provider ran. For penetration testing: no third party test, here is what I do use, here is my dependency scanning, and I am open to their test at their cost. For business continuity: honestly describe the backup schedule, the restore procedure and the last time you tested a restore. If the answer to that last one is never, go test a restore before you send the spreadsheet back, because it is the question that most deserves a real answer.

    The DPA itself is usually the easy part. Their template, your subprocessor list, a review by someone who reads contracts.

    267
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
    • @pandl_paula · 6mo ago

      I have never tested a restore. That is a genuinely alarming realisation to have arrived at through a procurement form.

      112
      Share
      Reply

      Answering anonymously — a moderator will review it first.

      Report
    • @cloze_kai · 6mo ago

      The questionnaire being the thing that finally makes you test your backups is the most common story in this whole genre. It is the best free consulting you will ever receive.

      88
      Share
      Reply

      Answering anonymously — a moderator will review it first.

      Report
  • @till_and_tally · 6mo ago

    Do not sign a DPA with unbounded liability, and do not agree to a breach notification window you cannot physically meet while holding down another job. Those two clauses are where the actual risk lives, not in the encryption questions everyone focuses on.

    176
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
  • @isopod_ivy · 6mo ago

    One more: check whether they expect you to carry insurance. It shows up buried in the contract rather than the questionnaire, and for a one person software vendor it is usually obtainable and not enormous, but it is a line item you should price into the deal before you agree rather than discover afterwards.

    137
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
  • @rollback_rae · 6mo ago

    Disagreeing with the enthusiasm slightly. Two days of your time on a $1,068 contract is a bad trade on its own terms, and it only makes sense if you believe this segment is where the product is going.

    Ask the champion directly: is this the standard process for any vendor, or is it triggered by the data we would be handling. Sometimes there is a lightweight path for small spend that procurement did not offer because nobody asked. I have had a 74 question form reduced to eight by one email asking whether the low-value vendor process applied.

    And if they will not move, be willing to walk. Some companies genuinely cannot buy from a one person vendor, and finding that out in week one is a gift.

    198
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
  • @tripodwobble · 6mo ago

    Formal audit reports at this stage are not worth it. The cost and the time are real and the return only appears when several deals a quarter are stalling on the same missing document. Wait until you can point at pipeline that is blocked by it. Until then, a good security page and honest answers get you a surprising distance.

    154
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
  • @sear_after_sam · 6mo ago · 2 replies

    Do it once properly and it becomes an asset. Put your answers into a single security page on your own site - architecture, where data lives, encryption in transit and at rest, subprocessor list, retention and deletion, how to report a vulnerability, and what you do not have.

    After I did that, roughly half of subsequent questionnaires were answered by sending the link plus a short document covering the gaps. The first one took me two full days. The fifth took forty minutes.

    Also ask whether they will accept your completed copy of a standard questionnaire format instead of their bespoke spreadsheet. Some procurement teams will, and it means you fill in one document forever rather than a new one per customer.

    234
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
    • @label_reader_lo · 6mo ago

      The subprocessor list is the bit people forget and it is also the bit that keeps you honest, because writing down every third party that touches customer data occasionally reveals one you had forgotten was in the request path.

      79
      Share
      Reply

      Answering anonymously — a moderator will review it first.

      Report