Security and client questionnaires

A requirement with a date — closed before that date.

From $26 per seat, from $1,350 per questionnaire, from $2,500 per role.

Get a quote

Who answers for security at your company when the question comes in writing?

Nobody. That becomes clear the day a client questionnaire arrives, or an insurer's application form, or a clause in a contract. The owner answers, from memory. The deadline is set by whoever sent the paper. A missed deadline costs a contract, not a reprimand.

The requirement is closed by whoever read it

You hand us the paper you were sent and get it back filled in. The questionnaire comes from your client's procurement office, the policy application from the insurer, the clause in a defence contract from the prime contractor. We answer in writing and point by point.

The price is known before the start, not after: the volume is set by the document you were sent. You pay for a result — a completed questionnaire, closed "no" answers, a report the auditor accepted. You do not pay for the hours spent hunting for answers.

Between such papers there is ongoing watch: we monitor attacks, keep the documents and configuration snapshots ready. And there is a person to go to beforehand.

What we do and from what price

  • not included: We fill in the questionnaire your client sentfrom $1,350 per questionnaire
  • not included: Preparing for a cyber policy renewal$2,250 one-off
  • not included: We watch for attacks around the clock and respond$18 per endpoint a month
  • not included: External penetration test of network and applicationsfrom $4,480 per perimeter
  • not included: SOC 2 readiness and keeping Type 2from $2,250 per sprint
  • not included: CMMC readiness for defense contractorsfrom $3,360 for Level 1
  • not included: Qualified individual under FTC Safeguards$2,500 a month
  • not included: Fractional chief information security officerfrom $2,500 a month
  • not included: If you are breached, we investigate — monthly$670 a month
  • not included: Patient records kept protected+$40 per seat a month

What we do and from what price

Questions

There are four of us. Do they ask this of us too?

Yes. The client usually asks first. A questionnaire is sent to a supplier of any size, and an insurer puts its questions to everyone renewing a policy. The size of the company decides the amount of work, not whether you get asked.

Where do we start if several requirements land at once?

With the one whose date is nearest and whose sender is clear. The rest are closed by the same things: logs, written rules, a restore from backup that has been tested. We name the order in the first conversation, before any invoice.

Do you carry out the audit itself or prepare us for it?

We prepare you and see it through to the report. The report itself is issued by an outside auditor — you choose and pay the auditor, the C3PAO assessor and the insurer yourself. Their fee is never part of our price, and we write that on every page where it comes up.

We already have an IT contractor. Is this instead of them?

No. They hold the computers and the access; we answer for the paperwork and for what is asked from outside. Who is responsible for what is written down before the work starts — so that "not my job" does not surface a week before the deadline.

Where to send the quote

Name the requirement and the date — we will send a quote by email and call if that is easier.

When to start
What is required of you and by when