Heights Consulting Group

You have received a third-party cybersecurity assessment

A customer has sent an assessment of your security, and it has a deadline. What the document is, what your answers commit you to, and what to establish before you reply.

What to do first

What it is
Your customer applying their vendor risk process to your organization.
What it needs
Answers that are accurate within a stated scope, and evidence behind them.
Who owns it
One accountable person, working from what the systems actually do.

The short answer

What you are holding

A third-party cybersecurity assessment is your customer applying their vendor risk process to you. The answers you return are representations rather than opinions, so the work before replying is establishing what is actually true, who is entitled to say so, and where the gaps are.

The document

What it is, plainly

It arrives under several names: a third-party risk assessment, a vendor security assessment, a security questionnaire, a due diligence request, or a standardized form such as a SIG or a CAIQ. The format varies and the purpose does not. Your customer has an obligation to understand the security of the organizations that hold or reach their data, and you are one of those organizations.

It is usually not an audit. Nobody is coming to inspect a system. It is a set of questions you answer about yourself, sometimes with evidence attached, and the answers are taken at face value unless something later contradicts them.

The request generally comes from procurement, a vendor risk function or the customer's security team, and it is frequently attached to a renewal, a new order, or an expansion of what you already do for them. The deadline is usually the deal's, not the security team's.

Consequence

What your answers commit you to

  • The answers become representations

    They may be referenced in the contract, kept in the customer's vendor file, and read again after an incident. An answer given quickly by whoever had the document open is still an answer the organization gave.

  • The exposure is visibility, not dishonesty

    It is rarely deliberate misstatement. It is a yes about encryption that is true of one system and not another, or a policy named that exists as a draft, given by somebody without a full view.

  • A gap found honestly is a negotiation

    Customers accept qualified answers with a plan far more readily than the alternative. What they do not accept is discovering that an unqualified answer was not accurate.

Before you reply

What to establish first

In this order. Each one narrows what the next has to decide.

  1. Establish the deadline and name an owner

    Find the real date, and put one accountable person on it. These responses fail most often because the document was treated as administrative and passed between people, none of whom owned the answer.

  2. Read all of it before answering any of it

    Questions depend on each other. A scope stated narrowly in question four constrains what is accurate in question forty, and a document answered in order is a document answered twice.

  3. Decide what is in scope

    Which systems, environments, staff and locations the answers cover. Most answers are only true within a boundary, and stating the boundary is legitimate, expected, and much safer than leaving it to be assumed.

  4. Answer from evidence, not memory

    For each answer, identify what would substantiate it if asked: the policy, the configuration, the report, the contract with the provider who performs it. Where nothing substantiates it, it is not yet a yes.

  5. Keep the gaps in a separate list

    Everything that could not be answered cleanly belongs in an internal record. That list is the start of a remediation plan, and it is what stops the next assessment costing the same effort again.

  6. Reply, with qualifications where they are true

    A qualified answer with a stated plan and a date is ordinary and is generally accepted. The unqualified answer that turns out to be inaccurate is the one that creates a problem worth avoiding.

Failure modes

Where responses go wrong

Answering to pass
The document is treated as an obstacle to the deal rather than a description of the organization. Answers drift optimistic under deadline pressure, and the drift is recorded nowhere.
The wrong person answering
It is routed to whoever has capacity, often in sales or operations, who answers what they sincerely believe to be true. The sincerity is real and the visibility is partial.
Assuming the provider covers it
Questions about patching, monitoring, backup and offboarding get answered on the assumption that a managed provider handles them. Whether they do, and to what standard, is in the contract, and the contract is rarely reread first.
Keeping no copy of what was said
The completed document goes back and is not retained. The next assessment is answered from scratch, and now two customers hold two different accounts of the same organization.
Treating the deadline as the objective
Returning it on time and inaccurately is worse than returning it slightly late and correctly. Customers routinely grant extensions when asked; they do not retract a vendor file.

Referenced

What the questions usually cite

  • SOC 2 Technology and service companies whose enterprise customers require evidence of a controlled environment.
  • ISO 27001 Organizations whose customers or markets expect a certified management system, often alongside or instead of SOC 2.
  • NIST CSF Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.

After

Where this leads

  • Answered accurately, it settles into a rhythm: reassessment on a defined cycle, a shorter update each time, and a known set of evidence to refresh rather than reconstruct.
  • Organizations that maintain their answers centrally stop treating each request as an event. The second and third customers cost a fraction of the first, because the underlying work has already been done once and written down.
  • Where it exposes real gaps, the useful outcome is a prioritized plan with an owner and dates. That is generally what a customer wants to see, and it is a more credible position than a clean sheet nobody can evidence.

Where Heights fits

If you would rather not work it out alone

Heights works on your side of an assessment: establishing what is actually true across the environment, separating what depends on a provider from what depends on you, and turning the gaps into a plan with an owner and a date. It is the accountable security voice the questions assume you already have.

Schedule a Confidential Consultation Read about vCISO leadership

FAQ

Questions this raises

Broader questions about executive security leadership are answered on the vCISO page.

Who should sign off on the answers we return?

Somebody with authority to commit the organization, on the basis of work done by whoever can actually see the systems. Those are usually two different people, and the failure mode is when they are the same person by default because nobody assigned it.

The practical test is whether the signer could explain any given answer to the customer six months later. If the answer is that they would have to go and ask, the review has not happened yet.

Can we answer no to a question without losing the deal?

Usually, yes. Vendor risk teams expect a distribution of answers and are generally assessing whether the organization understands its own position, not whether it is perfect. A no with a stated compensating measure, or with a plan and a date, is a normal outcome.

What tends to end badly is a yes that later turns out to be a no. That is a question about accuracy rather than about security posture, and it is judged differently.

The assessment asks about controls our provider operates. Who answers those?

You do, because the customer is assessing you and the obligation stays with you. What the provider supplies is the evidence behind the answer.

This is the point where organizations discover that the split of responsibilities was never written down, and that both sides assumed the other held something. Establishing the boundary is worth doing on its own terms, not only for the document in front of you.

Do we need a SOC 2 report to satisfy this?

Not necessarily. Many assessments accept a completed questionnaire with supporting evidence, and an attestation report is one way to shorten that rather than the only acceptable response. Whether one is expected is worth asking the customer directly.

Where a report is genuinely required, that is a longer piece of work with its own timeline and it will not be finished inside the deadline of the document you are holding. Those are two separate conversations and it helps to keep them separate.

Insights

Related reading

  • Governance

    Vendor, MSP and Third-Party Oversight: What Leadership Must Decide

    Vendor and third-party oversight is now a regulatory and operational requirement that leaves executives accountable for outcomes they cannot see clearly. This article explains what the obligation entails, who should own it, and how to establish effective governance without replacing existing technical controls.