What's actually happening
Your customer's procurement team has to prove they checked their suppliers. Most of
the questions ask whether you have written things down — not whether you own expensive
software.
What we'd do
Read the questionnaire, tell you which answers you already have, write the ones you
don't, and put evidence behind each line.
What it isn't
It is not a penetration test. If someone quotes you one for this, ask them why.
Ask about this →
What's actually happening
Staff use whatever tool makes the day easier. Without a written rule, "don't paste
customer data into a chatbot" is a preference, not a policy — and nobody can point
to it.
What we'd do
Write an acceptable-use policy short enough that people actually follow it, review
where your data goes when those tools are used, and cover any AI system you build, buy
or expose to customers.
What it isn't
It isn't blocking AI. Blanket bans get routed around within a week.
Ask about this →
What's actually happening
An insurer or a large customer wants evidence that someone tried to break in and
wrote down what happened. A vulnerability scan is not that, though plenty of firms sell
one as if it were.
What we'd do
Test from outside your perimeter and from inside your network, then report what we
reached and how — with steps to reproduce. Nothing is scanned until you've signed a
scope naming the exact addresses, dates and limits.
What it isn't
It isn't a scanner report with the logo changed.
Ask about this →
What's actually happening
Nothing has gone wrong. Someone has asked you a question you've never had to answer,
and most small companies are in exactly the same position.
What we'd do
Start with a call, at no charge, to work out which of the three things above you
actually need. Often it's one, not all three.
What it isn't
It isn't a retainer. If one piece of work closes it out, we'll say so.
Ask about this →