Incident response questions in a security questionnaire
Incident response questions ask for a written plan, a notification time, your breach history and a contact. The notification time is the one clients check hardest.
What the client wants to know
The client is judging what happens to them on the worst day: how quickly they hear about a breach, who decides what to do, and whether you have been through one. They also ask for a 24/7 contact, which a small vendor usually does not have.
The 5 questions as clients phrase them
The kit covers 5 questions in this area. The wording varies between questionnaires, the control behind it does not.
- Do you have an incident response plan?
- How quickly will you notify us of a security incident or data breach?
- Have you had a security breach in the last 3 years?
- Who is the contact for security incidents?
- Do you have a 24/7 security contact?
What a good answer contains
- Plan: a written incident response plan that names the decision maker and covers detection, containment, recovery, client notification and a review afterwards.
- Notification: affected clients are told without undue delay and within 72 hours of you becoming aware of a breach affecting their data.
- History: answer truthfully. If there was a breach, describe it briefly and say what changed after it.
- Contact: a named person and an email address.
- 24/7: say you do not run a 24/7 security operations centre, name the acknowledgement time for reports and say an incident affecting the client's data is escalated at once.
Watch out for
Write the 72-hour commitment into the plan and your contracts before you promise it to a client. Never answer the breach history question from memory of a template.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- Incidents: A written incident response plan exists, with a named contact. If not yet: Write a one-page incident plan: who decides, who to call, how to contain, how to tell clients.
- Incidents: Affected clients are told about a personal data breach within 72 hours. If not yet: Commit in writing to notify affected clients within 72 hours, and add it to your incident plan and contracts.
Example: how a prepared answer opens
Question: How quickly will you notify us of a security incident or data breach?
Affected clients are notified without undue delay and within 72 hours of [your company] becoming aware of a breach affecting their data.
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.