The Form Your Biggest Customer Is About to Send You
A client of ours was sent a form by one of their partners. Not a regulator, not an auditor. A partner they work with, doing a security review of everybody they buy from.
One question on it read: do you have a well-documented disaster recovery plan, with a clear owner, that is tested annually?
They did not. They asked whether we had one on their behalf, and for that client, at that moment, the honest answer was also no. That is not a comfortable sentence to write on a website. It is a common one, and pretending otherwise helps nobody.
What happened next is the useful part.
These forms are arriving more often
If you sell to schools, hospitals, local government, or any organisation large enough to have a procurement process, one of these is coming. Some have names you will see referenced. Education uses one called the HECVAT. Larger companies send their own spreadsheets. Some are twenty questions and some are three hundred.
They are all asking the same thing in different words. If something goes wrong at your end, how badly does it hurt us?
The reason they are multiplying is dull and reasonable. Large organisations have learned that the way they get hurt is usually through somebody smaller that they trusted. So they started asking. The questionnaire is not aimed at you personally. You are simply in the supply chain now, and everybody in it is being asked.
The questions that catch people out
They vary, but the ones that stop a small organisation dead are consistent.
Do you have a documented disaster recovery plan, with an owner, tested annually? Not backups. A written plan, a named person responsible for it, and evidence it was rehearsed.
Is multi-factor authentication enforced on all accounts? Not available. Enforced. On every account including the old shared ones.
Who has administrative access to your systems, and how is that reviewed? Most places have never written the list down.
What happens to our data if you go out of business, or if we end the relationship?
Do you carry cyber insurance, and what does it cover?
How quickly would you tell us if you had a breach?
None of those are unreasonable. Most are things you would want to know about a supplier of your own. They are just questions nobody had ever put in writing before.
The mistake is answering yes
Here is the trap, and it is an understandable one. The form arrives, a deal or a relationship appears to depend on it, and a column of "no" looks like losing. So somebody ticks yes to the things that feel nearly true.
That is the worst available option, for two reasons.
You may be signing something. Many of these forms are attached to a contract, or referenced by one. A yes is a representation. If the thing you claimed turns out not to exist on the day it matters, you are in a much worse position than if you had said no at the start.
And a yes ends the conversation. A no starts one.
What reviewers actually accept
People who read these forms for a living are not expecting a small organisation to look like a bank. They are looking for two things: that you know where you stand, and that you are honest about it.
"No, and here is what we are doing about it, by this date" is an answer they see constantly and accept routinely. It reads as an organisation that understands its own position.
"Yes" with nothing behind it reads as an organisation that does not, and it is usually found out later, in the worst possible circumstances, with the form in somebody's hand.
That answer went back as a no, with a plan and a date attached. Better than a tick, and true.
What a real answer looks like
Around the same time, another client of ours was sent a security confirmation by a financial counterparty, under rules their industry takes seriously. Same shape of questions, higher stakes.
So we helped them build the documents. A written information security program as the parent. An incident response plan saying who decides and how fast anyone gets told. A business continuity and recovery plan. A procedure for how they assess their own suppliers. A policy on staff use of AI, which is now being asked about and which almost nobody has.
We draft, and the client decides. That distinction matters more than it sounds. These are their policies, approved and signed by a named person inside their business, because a policy nobody in the organisation has agreed to is just a document we wrote. The recovery targets in particular are theirs: how long each function can be down is a business decision, not a technical one, and we are not the ones who get to make it.
The recovery plan is worth describing, because it is the one the questions keep circling. It names a person who owns it. It lists the functions the business cannot operate without, and against each one how long it can be down and how much data could be lost, agreed rather than assumed. It says where the copies are and that the credentials protecting them are separate. It says containment happens before restoring, so an attacker does not get restored along with the data. And it has a testing schedule: restores tested quarterly, a full recovery test and a walkthrough annually, with results written down.
None of that is exotic. It is a handful of pages. But it is the difference between a yes you can support and a yes you are hoping nobody checks.
Getting ahead of it
You do not need a filing cabinet. For most small organisations, four things cover the bulk of what gets asked.
A written recovery plan. What gets restored first, who decides, roughly how long it takes, and whose name is on it. Two pages is enough if the two pages are real.
An access list. Who has administrative rights to your systems, reviewed at some stated interval.
Evidence that multi-factor authentication is on, everywhere, including the accounts nobody uses.
A note of what your insurance actually covers, which is frequently not what people assume.
Every one of those is worth having whether anybody asks or not. The questionnaire only sets the deadline.
If one of your customers sent you that form on Monday, which questions could you answer today without guessing?
Get the next one by email
A new post most Tuesdays, written for the person who runs the business. One email per post, unsubscribe any time.