Your customer requires proof of cybersecurity?
A security questionnaire to fill in, a clause added to the contract, a request from your insurer. Here is how to answer with evidence, without a security team.
Behind every questionnaire, the same four questions
Who is in charge on your side?
A security policy approved by management, and a named person to keep it alive.
How do you protect their data?
Multi-factor authentication, access limited to what is needed, encryption, and where the data is stored.
What do you do when things go wrong?
An incident response plan, a deadline to warn them, isolated and tested backups.
Who do you rely on?
Your own subcontractors, what they see of the customer's data and what your contracts require of them.
Answer in four steps
- 1
Take stock
Go through the basic questions of the self-assessment: yes, partly or not yet. You know where you stand before you answer.
- 2
Answer without overpromising
The answer template offers wording for each case. A “not yet” with a date is better than a “yes” without evidence.
- 3
Attach evidence seen from the outside
The free exposure report shows what your customer, or an attacker, sees of you from the Internet. Fix what is visible, then attach it to your answer.
- 4
Keep the evidence up to date
Requests come back, from one year and one customer to the next. On the platform, your controls and your evidence stay in one place and are reused for each request.
The response kit
A PDF to answer your customer's questionnaire yourself, built from the questions that come up most often.
In the kit
- Self-assessment: the 11 basic questions every supplier should be able to answer.
- Answer template: wording for “yes”, “partly” and “not yet”, with the evidence to attach.
- The 20 more advanced questions, grouped by theme, with what to prepare.
- The mistakes to avoid when answering.
9 pages · PDF
What the platform adds to your answers
What can be seen of you from the outside
Forta Exposure monitors your domains, services and exposed equipment, and gives you a grade from A+ to F that you can explain.
See the moduleYour controls and evidence in one place
Forta Compliance maps your controls to 40+ frameworks: evidence gathered once serves several requirements.
See the moduleA short action plan
Forta Actions brings the gaps down to a short list of prioritized actions, each with an owner and a date.
See the module
Are you the one sending the questionnaire?
Generate a questionnaire suited to each supplier's criticality, or monitor your suppliers continuously with Forta Suppliers.
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities.
Frequently asked questions
My customer sent me a long questionnaire. Where do I start?
With the basic questions: who is responsible, how access and data are protected, what happens in an incident. The kit's self-assessment brings them together. Answer those first, then work through the more advanced questions theme by theme.
Do we need a certification to answer?
Not necessarily. Most questions ask you to describe your practices and attach evidence. A certification such as ISO 27001 or SOC 2 answers several of them at once, but it is only required if your customer or your contract says so.
What do we answer when the answer is no?
Say so, with what you plan to do and by when. An honest, dated answer can be defended. A false answer becomes a problem the day of an incident or an audit.
Can the free exposure report serve as evidence?
It shows your external exposure at a given date: domains, services, certificates, leaked credentials. You can attach it to your answer. It does not cover your internal practices, which the questionnaire addresses separately.
Is the kit legal advice?
No. It is a starting template, provided for guidance. Adapt it to your context and your contract.