Vendor Security Questions Worth Asking, and the Answers to Expect
Last updated:
Proportionate diligence
Enterprise vendor assessments run to hundreds of questions and are not appropriate for a business buying a £200-a-month tool. But asking nothing is how you end up dependent on a supplier who cannot answer basic questions.
Five questions is proportionate. Ask them in writing, and keep the answers.
1. Where is our data stored and processed?
Country and provider. This matters for data protection, and it is the question that reveals whether the supplier has thought about it.
A vague answer here — “in the cloud” — is itself informative about how much attention they have paid.
2. Who at your company can access it?
Some support access is normal and necessary. What you want to hear is that access is limited, logged and requires a reason, rather than that everyone in the company can read customer databases.
A good answer sounds like: “support engineers can access customer data with a ticket reference, it is logged, and access is reviewed quarterly.” A concerning answer is a reassurance without a mechanism.
3. What happens if you go out of business?
For anything business-critical, this deserves an answer. Options include escrow, an export you hold yourself, or simply a documented process for getting your data out quickly.
The practical protection for most small businesses is a regular export you keep, which also covers the less dramatic scenario of wanting to leave.
4. How do we get our data out?
- Full export, including attachments and history, not just the main tables
- In a usable format, not a proprietary one
- Available on demand rather than by request with a delay
- At no additional charge, ideally — exit fees are a warning sign
5. Have you had a security incident?
The answer “no, never” from an established supplier is less reassuring than a candid account of something that happened and what changed afterwards.
What you are assessing is whether they would tell you. A supplier who discusses a past incident openly is more likely to tell you about the next one promptly.
What to do with the answers
File them. If a supplier will not answer in writing, weigh that. And revisit for critical suppliers annually — companies get acquired, infrastructure moves, and policies change without customers being told.
Frequently asked questions
Do we need a signed data processing agreement?
What about certifications like ISO 27001?
How often should we review suppliers?
What if a critical supplier answers badly?
Buying software that will hold your customer data?
Send those five questions before you sign. We are happy to be asked them too.
Related services
What we build for problems like this one