Fusion Prevent
← Resources

Compliance

What a client security questionnaire actually asks — and why 'we have an IT company' won't answer it

22 August 2026 · 2 min read · Fusion Prevent

It arrives as a spreadsheet. Forty to eighty questions, a deadline measured in days, and a managing partner who has to sign at the bottom.

The instinct is to forward it to the IT provider. That instinct is where most firms lose the tender.

The questions are about governance, not tools

Open one and look at what it actually asks:

  • Do you have a documented incident response plan? Who owns it? When was it last tested?
  • Do you assess the cyber risk of your suppliers? What is the process?
  • Who at board level is accountable for information security?
  • What is your data classification policy?
  • How do you evidence staff security awareness training?

Your IT provider can confirm the backups run and the firewall is patched. They cannot confirm an incident response plan exists if it doesn't. They cannot name a board-level owner. These are not IT questions. They are questions about whether anyone at the firm owns the risk.

The national data makes the gap plain: only 25% of UK businesses hold a formal incident response plan, and only 15% review the cyber risk of their immediate suppliers. Most firms answering these questionnaires are describing something that does not yet exist.

Why the deadline is the problem

None of this can be assembled in eleven days. A supplier risk process, an incident plan, a named owner, evidence of training — these are things that either exist and are maintained, or they are being invented under pressure to get a signature on a form. Clients can tell the difference, and increasingly they check.

What is changing

The Cyber Security and Resilience Bill entered the House of Lords on 25 June 2026. It requires regulated organisations to assess and manage cyber risk across their supply chain. In practice that reaches a 60-person law firm not as legislation but as a contract clause and a questionnaire from its largest client.

This is going to become more frequent, not less.

The honest answer

If you are staring at one of these now: the answers have to be true, because you are signing them. The right move is not to dress up what you have. It is to establish what is actually true about the firm's exposure — from the outside — and put a name against owning it.

That is the conversation. The questionnaire is just what forced it.

See it for your own firm

Run the free 60-second exposure scan.

The same outside-in view an attacker starts from. Public data only — nothing is probed.

Run the free scan