Another spreadsheet of questions
A client's cyber insurance renewal is due. The broker sends a long questionnaire. Is MFA enforced for all users? For remote access? Are backups offline or immutable? How quickly are critical patches applied? Is endpoint detection in place on every device? The client forwards it to you with a note: 'Can you fill this in?'
A week later, another client forwards a supplier questionnaire from their largest customer, asking similar questions in different words, plus a few about policies. An engineer answers each one from scratch, checking consoles as they go, often late in the evening because the deadline is tomorrow.
Why questionnaires eat so much time
The questions are similar across questionnaires, but never identical. The answers depend on the current state of the client's estate, which changes, and on the client's own policies, which you may not hold.
- Every insurer and customer words the same question differently.
- Answers need checking against current tool data, not memory.
- Some questions are about the client's policies, not your services.
- Previous answers are in old emails and spreadsheets.
- The deadline is always short.
Wording matters more than it seems. 'Is MFA enforced for all users' and 'is MFA enforced for all remote access' have different answers for many small businesses, and a quick yes to both can be wrong. Each question needs reading carefully against the actual configuration, which takes time nobody has scheduled.
What rushed answers cost
| Rushed answer | Risk |
|---|---|
| Answer based on memory | A statement that is no longer true |
| Inconsistent answers across questionnaires | Questions from the insurer or customer |
| Policy question answered by the MSP | Commitments made on the client's behalf |
| No record of what was said | No way to check later what was claimed |
| Engineer time at short notice | Other work delayed |
Answers are statements by your client to their insurer or customer. The client must review and own them. We never answer on a client's behalf without their sign-off, and we make no promise about insurance outcomes.
The answer library we build
- A library of standard questions and answers per client, grouped by topic (identity and MFA, patching, backups, endpoint protection, email security, incident response).
- Live evidence behind each technical answer, pulled from your tools: MFA and conditional access status from Microsoft 365, patch timing from the RMM, backup coverage and results, endpoint protection coverage.
- Matching of new questionnaire questions to library answers, using an AI model such as Anthropic Claude, to draft responses that a person checks and edits.
- Flags on questions that are about the client's own policies or decisions, marked for the client to answer.
- Warnings when live evidence contradicts a library answer, such as a user without MFA, so the answer is corrected or the gap is fixed before submission.
- A record of each completed questionnaire, who approved it and what was submitted.
A questionnaire, handled properly
The broker's questionnaire arrives. The account manager uploads it, and drafts appear against most questions, with evidence attached: MFA enforced for every user except one service account, listed as an exception; critical patches applied within the client's target, with the figures; backups include an immutable copy for the servers. Questions about the client's own incident response policy are flagged for the client.
The engineer spends time checking answers rather than writing them, and fixes the one MFA gap before the questionnaire goes back. The client reviews, approves and submits. Next time, the library is richer, and the record shows exactly what was said last year.
There is a commercial side as well. The gaps that questionnaires expose, such as a missing immutable backup copy or devices without endpoint detection, are exactly the projects a client is most willing to approve, because they have a renewal form in front of them. The library keeps a list of gaps found per client, which feeds straight into the recommendations register for the next quarterly review.
Checklist: questionnaire pressure at your MSP
- Clients forward security questionnaires to you with short deadlines.
- Engineers answer similar questions from scratch each time.
- You have no record of what was submitted for each client.
- Answers are written from memory rather than checked against tools.
- You are sometimes asked to answer questions about the client's own policies.