Received a Security Questionnaire? We Will Help You Make Sense of It.
By Daniel Agyemang Prempeh, Founder, DefendVistaLast reviewed:
A customer, insurer or procurement team has sent you a cybersecurity questionnaire and it is full of terms nobody in the business uses. DefendVista helps UK SMEs understand what is being asked, identify the evidence you already have, spot what is missing, and prepare accurate responses.
We do not invent answers and we do not help anyone claim controls they do not have. The point of this service is a truthful, well evidenced response you can defend later, plus a clear view of anything worth fixing first.
- ✓Plain English translation of what each question is actually asking
- ✓Review of the controls and evidence you already hold
- ✓Honest identification of gaps and unsupported claims
- ✓Support preparing accurate responses within your deadline
Send it
share the questionnaire and any deadline
Review
we work out what the buyer is really asking for
Evidence
match questions to controls you can actually prove
Respond
prepare accurate, defensible answers
What is a supplier security questionnaire?
A supplier security questionnaire is a set of cybersecurity and data protection questions a customer, insurer or procurement team sends to a supplier during onboarding or due diligence. It typically asks about access control, data handling, backups, patching, staff training, incident response and supplier risk, and often asks for supporting evidence.
Supplier Security Questionnaire Support, from £495.
Questionnaires vary enormously, so we publish a starting price rather than a fixed one. Working to a procurement deadline? Tell us the submission date when you enquire.
Supplier Security Questionnaire Support
From £495
Final price confirmed after we have seen the questionnaire.
One-off support with a questionnaire, procurement cyber form or customer due diligence pack.
- ✓Questionnaire review and clarification of what each requirement means
- ✓Mapping questions to the evidence you already hold
- ✓Review of your draft responses
- ✓Identification of unsupported or weak answers
- ✓Gap identification where a control does not exist
- ✓Help preparing accurate, defensible responses
- ✓Remediation recommendations where controls are missing
Supplier Security Desk
From £199/month
Plans are scoped around questionnaire volume and support requirements.
Optional ongoing support for businesses facing recurring procurement and security-evidence requests: questionnaire assistance, evidence-pack maintenance, policy and evidence refresh support, Cyber Essentials renewal reminders and limited advisory time. This is not required after a one-off engagement.
Where the starting price moves depends on the number of questions, technical complexity, how much evidence is requested, the number of security domains involved, whether remediation is needed, and whether several questionnaires or frameworks are in play. We confirm the price before any work begins.
We never write or encourage false claims. If a requested control does not exist, we identify it as a gap and recommend how to close it rather than manufacturing an answer.
When UK SMEs usually come to us.
The paperwork arrives in different forms, but the underlying problem is the same: somebody outside your business wants structured proof of how you manage cyber risk.
Customer onboarding questionnaire
A new or growing customer sends a supplier onboarding pack with a cybersecurity section attached.
Procurement cyber questionnaire
A tender or framework includes security questions with a scoring weighting and a fixed deadline.
Security due diligence form
A larger organisation runs formal third party due diligence before signing or renewing.
Cyber insurance questionnaire
An insurer or broker asks detailed control questions that directly affect cover and premium.
Data security assessment
A customer needs assurance about how you handle personal or commercially sensitive data.
Third party security review
An annual reassessment of existing suppliers, often triggered by an incident elsewhere in the supply chain.
How Supplier Security Desk works.
- 01
Send us the questionnaire
Share the document and the deadline. We will tell you quickly whether this is a two hour job or something that needs remediation first.
- 02
We review the requirements
We work through every question and translate it into what the buyer is actually looking for, including where evidence will be expected.
- 03
We assess your controls and evidence
We check what you genuinely have in place today: configuration, policies, training records, backup and recovery, incident response and supplier management.
- 04
We identify gaps and weak answers
You get a clear list of anything missing, anything that cannot be evidenced, and anything you were about to claim that we would not sign off.
- 05
We support your response
We help you prepare accurate, well worded answers backed by real evidence, and flag anything better answered as a planned improvement.
- 06
Remediation, if you want it
Where gaps need closing, we scope that separately. There is no obligation to buy remediation work from us.
Why we will not write answers you cannot evidence.
Security questionnaires are contractual statements. If you claim monitored endpoint protection, tested backups or annual staff training and none of that exists, you have created a commercial and reputational problem that surfaces at the worst possible moment, usually during an incident.
We will help you present what you have in the best honest light, describe planned work as planned work, and give you the shortest route to being able to answer yes properly next time.
If the review shows more work than a single questionnaire needs, our Contract Ready programme covers the wider preparation and evidence work.
Questionnaire deadline already looming?
Send it over during a initial call. We will tell you what is realistic in the time you have and what should be answered as work in progress.
What you get from a questionnaire review.
- ✓A question by question view of what is being asked and why
- ✓A mapping of each question to controls and evidence you already hold
- ✓A written gap list with a recommended priority order
- ✓Draft response wording for you to review, adjust and submit
- ✓An evidence folder structure you can reuse for the next questionnaire
- ✓A short note on anything worth remediating before the next review cycle
Sectors we support most often.
We work across UK SMEs, with particular depth in transport, logistics and warehousing where supplier assurance requests from large customers and 3PL partners have become routine.
We also support professional services firms, manufacturers, education suppliers and care organisations facing the same due diligence pressure from larger buyers.
Transport and logistics operators can also read our sector guidance on supply chain cyber risk which covers the other side of the same conversation.
Supporting transport and logistics businesses right across the UK.
DefendVista works with hauliers, fleets, 3PLs and warehouse operators in every corner of the United Kingdom. Whether you run a single depot or a national network, we deliver the same hands on, plain English security support remotely and on site.
England
From the M25 hubs out to the North West, North East, Midlands, South West and East Anglia. Strong presence supporting London, Birmingham, Manchester, Leeds, Liverpool, Bristol and Sheffield based operators.
Scotland
Cybersecurity support for transport firms across Glasgow, Edinburgh, Aberdeen, Dundee and the central belt logistics corridor.
Wales
Helping hauliers and warehouse operators in Cardiff, Swansea, Newport and along the M4 corridor improve cyber resilience.
Northern Ireland
Practical security advice and incident response for logistics businesses in Belfast, Derry and across Northern Ireland.
Built by a logistics insider, not a generalist IT firm.
DefendVista was founded by a cybersecurity practitioner with a military logistics background, an MSc in Forensics and Cybersecurity, and Certified Ethical Hacker (CEH) credentials. We have spent years inside UK SME operations, which is why our advice is grounded in how your business actually runs, not theoretical frameworks.
Military logistics background
Lived experience of moving freight, managing risk and recovering from disruption under pressure.
MSc Forensics and Cybersecurity
Postgraduate technical depth across digital forensics, incident response and modern attacker tradecraft.
Certified Ethical Hacker (CEH)
We think like the people trying to break into your business, so we can stop them first.
UK SME cybersecurity experience
Year after year of helping transport, logistics and operational SMEs harden systems and recover from real incidents.
Built for UK transport, logistics and warehousing businesses.
DefendVista works exclusively with the operators, hauliers and logistics providers that keep British supply chains moving. We have lived inside transport businesses, run forensics on real incidents and know the cadence of a busy traffic office. That is why our advice lands very differently from a generalist IT firm.
- ✓Haulage Companies
- ✓Fleet Operators
- ✓Warehouse Operators
- ✓Freight Forwarders
- ✓Distribution Businesses
- ✓Third Party Logistics Providers
- ✓Transport SMEs
- ✓Courier Companies
- ✓Cold Chain Logistics Businesses
- ✓Logistics Technology Providers
From a single depot operator with a dozen vehicles through to multi site 3PLs running hundreds of staff and complex WMS estates, we size the work and the controls to the business. No upsell, no jargon, no surprises in the invoice.
Not sure where you stand right now?
Start with the online Cyber Readiness Check or talk to a specialist who has lived inside transport operations.
"We have heard this before, and here is what actually happens."
Every operator we speak to has a version of these objections. They are reasonable. They are also, in our experience, the exact reasons UK transport and logistics SMEs end up in trouble. Here is how we think about each one.
"We are too small to be targeted."+
Why this concern exists. Most attacks against UK SMEs are not targeted. They are automated. Criminal groups scan the internet for exposed Microsoft 365 logins, unpatched servers and weak email security, then attack whoever they find.
The real business risk. Hauliers and warehouses with five to fifty vehicles are now the bread and butter of ransomware crews. Smaller businesses lose proportionally more, because a single ransomware event can take 100 per cent of operations offline.
Illustrative scenario. A small haulier with a handful of vehicles loses several days of dispatch to a generic ransomware attack that was never aimed at them personally. This is a common industry pattern, not a client outcome.
How DefendVista addresses it. We size proportionate controls to the business. A small operator does not need an enterprise SIEM, but they absolutely need MFA, EDR and a tested backup. Those three controls alone neutralise most automated attacks.
"We already use Microsoft 365."+
Why this concern exists. Microsoft 365 is a powerful platform, but it ships with safe defaults disabled. Most UK SME tenants have no MFA enforcement, no conditional access, audit logging on a 30 day retention, and legacy authentication still enabled.
The real business risk. A default Microsoft 365 tenant is a soft target. Almost every reported business email compromise in this sector happens inside Microsoft 365 with the same handful of misconfigurations.
Illustrative scenario. A warehouse operator pays a supplier invoice with altered bank details after a finance mailbox is phished. The Microsoft 365 licence is usually capable of stopping the attack. It is simply not configured to.
How DefendVista addresses it. We harden your Microsoft 365 tenant to a Cyber Essentials Plus aligned baseline. MFA everywhere, conditional access, no legacy auth, 12 month audit logging and managed monitoring on top. Most clients keep their existing licences.
"Our IT provider handles cybersecurity."+
Why this concern exists. Most MSPs in the UK transport sector are excellent at break/fix support. Very few are staffed with security specialists, run a 24/7 SOC or have run a real incident in the last twelve months.
The real business risk. When ransomware hits at 19:00 on a Friday, you find out very quickly whether your IT provider is a security firm or a help desk. By then it is too late.
Illustrative scenario. A common pattern during a live ransomware attack is a well meaning reboot of an affected server, which can destroy the evidence and the recovery options a specialist would have relied on. This is an industry pattern, not a client outcome.
How DefendVista addresses it. We work alongside your MSP, not against them. They keep the lights on. We own risk assessment, hardening, incident response and the strategic security work that sits above day to day IT support.
"Cybersecurity is too expensive."+
Why this concern exists. Cybersecurity is often sold as enterprise licensing and consultancy retainers that genuinely are out of reach for an SME haulier. That picture is out of date.
The real business risk. The cost of doing nothing is rarely the headline ransom figure. It is lost margin, contractual penalties, churned customers, insurance excesses and a recovery bill that routinely runs into tens of thousands.
Illustrative scenario. A single ransomware event for a typical UK transport SME costs around £80,000 to £250,000 when you include downtime, recovery, legal and insurance excess. Most credible protection programmes cost a tiny fraction of that per year.
How DefendVista addresses it. We scope work to the business and the risk. A first engagement for an SME haulier is often a few thousand pounds for a risk assessment and roadmap, with proportionate managed services from there. We will tell you what you do not need.
"We have never had an incident before."+
Why this concern exists. Most operators have already had incidents. They just did not recognise them. A misdirected invoice, an odd login from abroad, a strange email from a director. These are often early signs of a compromise nobody investigated.
The real business risk. The longer an attacker sits inside a network undetected, the more they learn and the more damage they do when they finally act. Median dwell times before ransomware deployment are now days, not months.
Illustrative scenario. Business email compromise commonly runs for weeks before anyone in the business notices, because the attacker only reads and waits.
How DefendVista addresses it. A short, focused cyber readiness assessment will tell you in plain English whether you have early warning signs you have missed, and what to fix first. Often less expensive than a single missed delivery.
"We do not store sensitive information."+
Why this concern exists. Almost every transport and warehouse business holds driver licences, vehicle compliance records, customer contact data, supplier banking details and sometimes DBS results. All of this is personal data under UK GDPR.
The real business risk. Loss or exposure of this data carries ICO notification obligations within 72 hours, potential enforcement and a real risk of losing public sector or large customer contracts that require evidence of data protection controls.
Illustrative scenario. A transport operator exposes driver and customer documents through a misconfigured file share, and only discovers the exposure when someone outside the business mentions it.
How DefendVista addresses it. We build a lightweight, plain English data protection posture that fits how transport businesses actually run, including SharePoint hardening, privacy notices, RoPA and a usable breach response process.
Explore more transport and logistics cybersecurity resources.
Cybersecurity for Haulage Companies
Sector specific protection for UK haulage operators running TMS, telematics and lean back office teams.
Cybersecurity for Transport Companies
End to end cyber risk reduction for transport firms, from email and payroll through to vehicle tracking.
Cybersecurity for Warehouse Operators
Practical security for warehouses, 3PLs and distribution centres relying on WMS and handheld devices.
Ransomware Protection for Logistics Firms
Prevention, detection and rapid recovery designed for transport and logistics operations.
GDPR for Transport Companies
Pragmatic data protection support for hauliers, fleets and logistics SMEs across the UK.
Cybersecurity Risk Assessment for Hauliers
A structured, plain English assessment that shows you exactly where your business is exposed.
Or jump into our transport cyber resource centre, browse our full cybersecurity services, see the industries we specialise in, or book a cybersecurity consultation with our team.
Supplier security questionnaire support: your questions answered.
Will you complete the questionnaire for us?+
We prepare draft responses based on what we can verify, and you review and submit them. The answers must be yours because they are commitments made by your business.
What if we cannot answer yes to some questions?+
That is normal and it is rarely fatal. Buyers generally respond better to an honest no with a dated improvement plan than to a yes that cannot be evidenced.
How quickly can you turn a questionnaire around?+
It depends on length and how much evidence already exists. Short questionnaires are often handled within a few working days. Tell us your deadline at the first call.
Do we need Cyber Essentials before responding?+
Not necessarily. Some questionnaires ask for it, many do not. We will tell you whether certification is relevant to this specific requirement rather than assuming it is.
Is this ongoing or a one-off service?+
Both are available. Many SMEs start with a single questionnaire and then move to ongoing support once due diligence requests become regular.
Do you handle cyber insurance questionnaires too?+
Yes. Insurer questionnaires follow similar ground and the same rule applies: answers must be accurate, because inaccurate ones can affect cover at claim time.
What does questionnaire support cost?+
It is scoped to the complexity and length of the questionnaire and quoted before any work starts. There is no charge for the initial call.
Get questionnaire support before the deadline, not after it.
Book a initial call, share the questionnaire, and get a clear view of what you can evidence today.