Tickbox Draft your answers free
Guide

Common security questionnaire questions, decoded (with example answers)

Most security questionnaires ask the same core questions in different words. Here are the ones that come up again and again, what each is really getting at, and how to answer.

Last updated: July 2026

Security questionnaires look intimidating because they are long and use formal language, but underneath they repeat a small set of concerns. Once you can see what each question is really asking, they get much easier.

Below are the questions that turn up in almost every questionnaire. For each, we explain what the customer wants to know and how to answer it well. Example answers follow at the end.

Draft your answers free →

"Do you enforce multi-factor authentication (MFA)?"

They want to know that a stolen password alone cannot get someone into your systems. MFA (a second step such as a code or app approval) is one of the highest-impact controls, so it is asked almost every time.

Answer with where MFA is switched on, especially email, file storage, and admin accounts. If it is not everywhere yet, say where it is and what you are rolling out.

"How is data encrypted in transit and at rest?"

This asks whether data is scrambled while moving over the internet (in transit) and while stored (at rest), so it is useless if intercepted or a device is lost.

Most small businesses can answer yes on the strength of their cloud providers: connections use HTTPS/TLS, and reputable cloud storage encrypts data at rest by default. Say that, and add that you avoid storing data on unencrypted local devices.

"What is your process for reporting a data breach?"

They want confidence that if something goes wrong, you will notice, act, and tell the right people, including them and, where required, the ICO within 72 hours.

Describe how you would spot and log an incident, assess the risk, and who you would notify. A short, clear process is fine.

"How do you control access to systems and data?"

This is about least privilege: people should only reach what their job needs, and access should be removed when they leave.

Explain that access is through individual accounts, granted by role, with admin rights limited and a joiner/leaver process to add and remove access.

"Do you take regular backups?"

They are checking you could recover from ransomware, an accident, or a failure.

Say what is backed up, how often (often automatically via your cloud providers), and that you can restore it. It helps to note you have checked a restore works.

"Do you use subcontractors or sub-processors?"

If you rely on other suppliers (for example cloud or email providers) to handle the customer’s data, they want to know those parties are trustworthy and under contract.

List the main providers you use, and note that they are reputable and bound by their own data protection terms.

"How long do you keep data, and how is it deleted?"

This is a UK GDPR concern: you should not keep personal data forever, and you should delete it securely when it is no longer needed.

State your retention approach (keep only while needed, or as contractually or legally required) and that deletion is secure.

"Do you provide security awareness training to staff?"

People are the most common way in, so they want to know your team knows the basics: phishing, passwords, and handling data.

Even informal training counts. Say what you do, for example a briefing at onboarding and periodic reminders about phishing and safe handling of data.

"Do you have information security or data protection policies?"

They want to see that your approach is written down, not just in your head.

If you have policies, say which. If they are brief, that is still fine to say. If you do not have them yet, describe your practices and note that you are documenting them.

Example answers you can adapt

Do you enforce multi-factor authentication?
Yes. MFA is enforced on our email, file storage, and administrator accounts, and on any cloud service that supports it.
How long do you retain personal data and how is it deleted?
We keep personal data only for as long as it is needed for the purpose it was collected, or as required by law or contract. When it is no longer needed it is securely deleted from our systems.
Do you provide security awareness training?
Yes. Staff receive security guidance when they join, covering phishing, strong passwords and MFA, and safe handling of customer data, with periodic reminders.
Do you rely on any sub-processors to handle customer data?
Yes. We use reputable cloud providers for email, file storage, and hosting. Each is bound by its own data protection terms, and we can provide our list of sub-processors on request.

These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.

Frequently asked questions

Why do the same questions appear in every questionnaire?

Because they map to the same underlying risks: access, data protection, and resilience. Different customers word them differently, but the substance is largely shared, which is why saved answers can be reused.

What if a question uses jargon I do not understand?

Focus on what it is really asking. Most questions reduce to "how do you protect this?". If you are unsure, answer plainly about what you do and flag anything you need to confirm.

Can I reuse my answers across different questionnaires?

Yes, and you should. The core questions repeat, so a good answer can be adapted each time. Tickbox saves your approved answers and reuses them to draft future questionnaires faster.

More guides

Answer your questionnaire in minutes

Drop it in and Tickbox drafts every answer for you to review. Your first few are free.

Try it free