Security questionnaires look intimidating because they are long and use formal language, but underneath they repeat a small set of concerns. Once you can see what each question is really asking, they get much easier.
Below are the questions that turn up in almost every questionnaire. For each, we explain what the customer wants to know and how to answer it well. Example answers follow at the end.
Draft your answers free →"Do you enforce multi-factor authentication (MFA)?"
They want to know that a stolen password alone cannot get someone into your systems. MFA (a second step such as a code or app approval) is one of the highest-impact controls, so it is asked almost every time.
Answer with where MFA is switched on, especially email, file storage, and admin accounts. If it is not everywhere yet, say where it is and what you are rolling out.
"How is data encrypted in transit and at rest?"
This asks whether data is scrambled while moving over the internet (in transit) and while stored (at rest), so it is useless if intercepted or a device is lost.
Most small businesses can answer yes on the strength of their cloud providers: connections use HTTPS/TLS, and reputable cloud storage encrypts data at rest by default. Say that, and add that you avoid storing data on unencrypted local devices.
"What is your process for reporting a data breach?"
They want confidence that if something goes wrong, you will notice, act, and tell the right people, including them and, where required, the ICO within 72 hours.
Describe how you would spot and log an incident, assess the risk, and who you would notify. A short, clear process is fine.
"How do you control access to systems and data?"
This is about least privilege: people should only reach what their job needs, and access should be removed when they leave.
Explain that access is through individual accounts, granted by role, with admin rights limited and a joiner/leaver process to add and remove access.
"Do you take regular backups?"
They are checking you could recover from ransomware, an accident, or a failure.
Say what is backed up, how often (often automatically via your cloud providers), and that you can restore it. It helps to note you have checked a restore works.
"Do you use subcontractors or sub-processors?"
If you rely on other suppliers (for example cloud or email providers) to handle the customer’s data, they want to know those parties are trustworthy and under contract.
List the main providers you use, and note that they are reputable and bound by their own data protection terms.
"How long do you keep data, and how is it deleted?"
This is a UK GDPR concern: you should not keep personal data forever, and you should delete it securely when it is no longer needed.
State your retention approach (keep only while needed, or as contractually or legally required) and that deletion is secure.
"Do you provide security awareness training to staff?"
People are the most common way in, so they want to know your team knows the basics: phishing, passwords, and handling data.
Even informal training counts. Say what you do, for example a briefing at onboarding and periodic reminders about phishing and safe handling of data.
"Do you have information security or data protection policies?"
They want to see that your approach is written down, not just in your head.
If you have policies, say which. If they are brief, that is still fine to say. If you do not have them yet, describe your practices and note that you are documenting them.
Example answers you can adapt
These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.
Frequently asked questions
Why do the same questions appear in every questionnaire?
Because they map to the same underlying risks: access, data protection, and resilience. Different customers word them differently, but the substance is largely shared, which is why saved answers can be reused.
What if a question uses jargon I do not understand?
Focus on what it is really asking. Most questions reduce to "how do you protect this?". If you are unsure, answer plainly about what you do and flag anything you need to confirm.
Can I reuse my answers across different questionnaires?
Yes, and you should. The core questions repeat, so a good answer can be adapted each time. Tickbox saves your approved answers and reuses them to draft future questionnaires faster.
More guides
Answer your questionnaire in minutes
Drop it in and Tickbox drafts every answer for you to review. Your first few are free.
Try it free