Inner Monologue

February 24, 2026

Answering the enterprise security questionnaire

Two hundred questions, a founder who had not slept, and one spreadsheet.

The call came in at eight in the evening, which is how I knew it was bad. A large customer had sent a security questionnaire, two hundred rows, and the contract was now waiting on it. He had been answering them in order since lunchtime and was on question thirty one.

The first thing I told him was to stop. Read the whole thing before answering any of it, then sort the rows into three piles: things you already do, things you could do this month, and things that are simply not true of a company with forty people. The first pile is always bigger than the founder expects. He had a password manager, enforced two factor, and backups he had actually restored from, which put him ahead of plenty of larger firms I have seen.

The third pile is where people lie, and it is the only place lying matters. Nobody buying from a company this size expects a security operations centre. What the questionnaire is testing is whether you know the difference between a control you have and one you do not. A clear no with a sentence about what you do instead reads as competence. A vague yes reads fine until the audit, and then it reads as fraud.

We finished it in two days. The part I made him promise was to keep the answers somewhere sensible, because the next customer will ask eighty percent of the same questions, and I would rather not take that call at eight in the evening again.

MMB

All articles