Reduce risk
Answer the questionnaire honestly, and mean it
Client security questionnaires, insurer renewals and certification schemes all ask roughly the same things. The difficulty is rarely the requirement itself — it's finding the evidence, and knowing which answers are true. We help organisations work out what's genuinely needed and what they can already prove.
Why compliance feels heavier than it is
Compliance work usually lands on someone who already has a full job. A prospect sends a forty-question security form with a deadline, or an insurer renewal arrives with terms that weren't there last year, and suddenly somebody is trying to establish whether every device is encrypted while also doing their day job.
The frustrating part is that most of the answers exist somewhere. They're just spread across a portal, a spreadsheet, a supplier's inbox and one person's memory. Gathering them takes far longer than the underlying control took to put in place, and it happens again from scratch the next time.
There's also a temptation to answer optimistically to get the deal through. That's worth resisting. An answer that isn't quite true is a problem you've scheduled for later, usually at the worst possible moment — a claim, an audit, or the day something actually goes wrong.
- Evidence scattered everywhere
- The controls exist, but proving it means a week of hunting through portals and old emails.
- Answers nobody can stand behind
- Forms filled in from memory or optimism, with no way to check whether they're still true.
- Starting over each time
- Every new client form and renewal repeats the same work because nothing was kept.
What usually moves the needle
Not everything at once, and not in the order a sales pitch would suggest. This is the sequence most organisations get the most from.
- 01
Work out what actually applies
Separate the genuine obligations from the things that only feel obligatory.
Contractual requirements, regulatory duties, insurer conditions and certifications you've chosen to pursue are four different things. Sorting them makes the list much shorter than it first appeared.
- 02
Check the answers against reality
For each requirement, establish what's true today rather than what should be.
This is the step people skip. It's also the one that turns compliance from a paperwork exercise into something that reduces actual risk, because the gaps it finds are usually real.
- 03
Close the gaps in priority order
Fix what's both required and genuinely risky first.
Some gaps are one-line settings changes; others need a process and an owner. Knowing which is which stops the whole programme being blocked by the hardest item on the list.
- 04
Keep the evidence in one place
Policies, screenshots, reports and dates, filed as you go.
This is what makes the second questionnaire take an afternoon instead of a fortnight. It doesn't need a platform — a well-organised folder with a review date on each item is enough for most organisations.
- 05
Give it an owner and a rhythm
A named person, a calendar reminder and a short review before renewals.
Compliance decays. Staff change, settings drift and a control that was true in March may not be in November. A brief scheduled review keeps your answers honest without anyone having to redo the whole exercise.
The goal isn't a tidy folder of certificates. It's being able to answer any question about your security and know the answer is true.
What good looks like
Compliance stops being a scramble when the evidence is current, owned and easy to find. That's most of the work.
- You know which requirements genuinely apply and where they come from.
- Every answer on a questionnaire can be backed up with something.
- Evidence lives in one place with dates and an owner.
- Gaps are on a list with a plan, not a surprise at renewal.
- Client forms take hours rather than weeks.
- Certifications like Cyber Essentials renew without a panic.
How we help
We help organisations get from a stack of questions to an honest position: what applies, what's already true, what isn't, and what it would take to close the difference. Much of it usually turns out to be in place already — it just hasn't been written down anywhere someone could point to.
Where there are real gaps, we'll say plainly which ones matter and which are box-ticking. Not every requirement carries the same risk, and pretending otherwise makes the work larger than it needs to be.
We'll also point you towards the right specialist when a question is genuinely legal or regulatory rather than technical. Data protection advice in particular is worth getting from someone qualified to give it.
Questions people ask us
For most organisations, yes. The controls it asks for are ones you'd want anyway, and increasingly clients and public sector buyers expect the certificate. Cyber Essentials Plus adds an independent check, which is worth it if your customers ask for it.
Start with a conversation, not a proposal
Get an IT health check that reviews your support, security and Microsoft setup, then gives you a short, prioritised list of what's worth doing.