---
title: "Security and client questionnaires"
description: "We answer client questionnaires and prepare you for a cyber policy, SOC 2, CMMC and HIPAA. From $26 per seat, $1,350 per questionnaire, $2,500 for the role."
locale: en
canonical: https://finleadgen.com/en/services/cybersecurity
source: https://finleadgen.com/en/services/cybersecurity.md
price_reviewed: 2026-08-06
---

# Security and client questionnaires

A requirement with a date — closed before that date.

**From $26 per seat, from $1,350 per questionnaire, from $2,500 per role.**

## Who answers for security at your company when the question comes in writing?

Nobody. That becomes clear the day a client questionnaire arrives, or an insurer's application form, or a clause in a contract. The owner answers, from memory. The deadline is set by whoever sent the paper. A missed deadline costs a contract, not a reprimand.

## The requirement is closed by whoever read it

You hand us the paper you were sent and get it back filled in. The questionnaire comes from your client's procurement office, the policy application from the insurer, the clause in a defence contract from the prime contractor. We answer in writing and point by point.

The price is known before the start, not after: the volume is set by the document you were sent. You pay for a result — a completed questionnaire, closed "no" answers, a report the auditor accepted. You do not pay for the hours spent hunting for answers.

Between such papers there is ongoing watch: we monitor attacks, keep the documents and configuration snapshots ready. And there is a person to go to beforehand.

## What we do and from what price

| What | State | Price |
| --- | --- | --- |
| We fill in the questionnaire your client sent | not included | from $1,350 per questionnaire |
| Preparing for a cyber policy renewal | not included | $2,250 one-off |
| We watch for attacks around the clock and respond | not included | $18 per endpoint a month |
| External penetration test of network and applications | not included | from $4,480 per perimeter |
| SOC 2 readiness and keeping Type 2 | not included | from $2,250 per sprint |
| CMMC readiness for defense contractors | not included | from $3,360 for Level 1 |
| Qualified individual under FTC Safeguards | not included | $2,500 a month |
| Fractional chief information security officer | not included | from $2,500 a month |
| If you are breached, we investigate — monthly | not included | $670 a month |
| Patient records kept protected | not included | +$40 per seat a month |

## What we do and from what price

- [Completing security questionnaires](https://finleadgen.com/en/services/security-questionnaires) — $1,350 per questionnaire
- [Preparing for a cyber policy renewal](https://finleadgen.com/en/services/cyber-insurance-readiness) — $2,250 one-off
- [Attack monitoring and response](https://finleadgen.com/en/services/managed-detection) — $26 per seat per month: $18 endpoint and $8 account
- [External penetration test of network and applications](https://finleadgen.com/en/services/penetration-testing) — $4,480 per network
- [SOC 2 readiness](https://finleadgen.com/en/services/soc-2) — $2,250 per readiness sprint
- [CMMC readiness](https://finleadgen.com/en/services/cmmc) — Level 1 — $3,360 one-off
- [Qualified individual under FTC Safeguards](https://finleadgen.com/en/services/ftc-safeguards) — $2,500 a month for the company
- [Fractional chief information security officer](https://finleadgen.com/en/services/fractional-ciso) — From $2,500 a month
- [Breach response and readiness](https://finleadgen.com/en/services/incident-response) — $670 a month for readiness, with hours credited
- [Patient records kept protected](https://finleadgen.com/en/services/hipaa-compliance) — $168 per seat per month on an annual contract

### There are four of us. Do they ask this of us too?

Yes. The client usually asks first. A questionnaire is sent to a supplier of any size, and an insurer puts its questions to everyone renewing a policy. The size of the company decides the amount of work, not whether you get asked.

### Where do we start if several requirements land at once?

With the one whose date is nearest and whose sender is clear. The rest are closed by the same things: logs, written rules, a restore from backup that has been tested. We name the order in the first conversation, before any invoice.

### Do you carry out the audit itself or prepare us for it?

We prepare you and see it through to the report. The report itself is issued by an outside auditor — you choose and pay the auditor, the C3PAO assessor and the insurer yourself. Their fee is never part of our price, and we write that on every page where it comes up.

### We already have an IT contractor. Is this instead of them?

No. They hold the computers and the access; we answer for the paperwork and for what is asked from outside. Who is responsible for what is written down before the work starts — so that "not my job" does not surface a week before the deadline.

## Where to send the quote

Name the requirement and the date — we will send a quote by email and call if that is easier.
