There is a particular conversation I have had enough times to recognise the shape of it before it starts.
An organisation has a security questionnaire from a client, or an insurance renewal, or a board that has read something alarming. They want to be able to answer the questions. What they are buying, whether they realise it or not, is the ability to say yes. Whether the yes is true is a secondary concern that surfaces only after an incident.
This is compliance theatre, and our industry is complicit in it.
How the theatre works
The mechanism is simple. Security questionnaires ask closed questions. Closed questions have binary answers. Binary answers erase every detail that determines whether a control actually functions.
“Do you enforce multi-factor authentication?” Yes. The questionnaire does not ask whether it covers the VPN, whether four service accounts are exempt, whether SMS is still permitted as a factor, or whether the CFO has a permanent bypass because he travels.
“Do you have documented incident response procedures?” Yes. The questionnaire does not ask whether anyone has read them since they were written, whether the phone numbers still work, or whether the procedure assumes access to a system that would be unavailable during the incident it describes.
“Are backups performed daily?” Yes. Nobody asks when a restore was last tested.
Every one of those yeses is technically defensible and practically meaningless.
Why providers go along with it
I want to be fair here, because the incentives are genuinely difficult rather than simply cynical.
A provider who says “you can answer yes to fourteen of these twenty questions today, and here is a plan for the other six” is competing against a provider who says “we’ll get you fully covered”. The second answer is more appealing, faster to sell, and cheaper to deliver, because delivering the appearance of a control is far less work than delivering the control.
There is also a genuine difficulty: many controls are partially true. MFA covering 94% of accounts is a real, substantial improvement. Writing “no” understates it badly. Writing “yes” overstates it. The questionnaire has no box for the truth.
The specific lies I see most often
Not deliberate lies, mostly. Just answers that have drifted from reality without anyone noticing.
- “We have endpoint protection on all devices.” All managed devices. The three machines the directors bought themselves are not enrolled.
- “Access is reviewed regularly.” It was reviewed once, thoroughly, in 2023, during the last audit.
- “Offboarding revokes access within 24 hours.” For accounts IT is told about. The SaaS tool marketing bought on a credit card is not in the process.
- “Logs are retained for twelve months.” Retained, yes. Reviewed by anybody, no. Retained somewhere an attacker with domain admin couldn’t delete them, also no.
- “We conduct security awareness training.” Once, at induction, as a video people click through while doing something else.
Why it matters more than it seems
The obvious harm is that you are less secure than you believe. The subtler harm is worse: theatre consumes the security budget that would have bought real controls.
An organisation that has spent its available money and attention on documentation, policy templates and a dashboard has spent it. When something happens, there is no appetite and no budget for the second round, and there is now an organisational belief that security was addressed.
There is also a liability dimension worth taking seriously. Answering yes to a control you do not have, on a document that forms part of an insurance application or a client contract, is a materially different act from having weak security. I am not a lawyer and this is not legal advice, but it is worth asking yours what an inaccurate questionnaire answer does to a claim.
What honest looks like
The alternative is not brutal self-flagellation on every form. It is precision.
Where a questionnaire allows commentary, use it. “Yes, enforced for all user accounts across email, VPN and remote desktop. Three service accounts are exempt and compensating controls are documented.” That answer is stronger than a bare yes, not weaker. It tells a competent assessor that you know your own environment, which is itself a signal about your security maturity.
Internally, the discipline is to maintain one honest document that nobody outside sees: what is actually true, where the gaps are, and what it would cost to close them. Every organisation should have this. Very few do, because writing it down makes the gaps undeniable, and undeniable gaps demand decisions.
That discomfort is the point. A security posture nobody is uncomfortable about is usually a security posture nobody has looked at properly.
One question to ask your provider
“Which of the yeses on our last security questionnaire would you not be comfortable defending in an incident review?”
If the answer is “none of them”, either you are in unusually good shape, or nobody has looked properly. It is worth finding out which.