Security Answer Kit

All guides

Incident response questions in a security questionnaire

Incident response questions ask for a written plan, a notification time, your breach history and a contact. The notification time is the one clients check hardest.

What the client wants to know

The client is judging what happens to them on the worst day: how quickly they hear about a breach, who decides what to do, and whether you have been through one. They also ask for a 24/7 contact, which a small vendor usually does not have.

The 5 questions as clients phrase them

The kit covers 5 questions in this area. The wording varies between questionnaires, the control behind it does not.

  1. Do you have an incident response plan?
  2. How quickly will you notify us of a security incident or data breach?
  3. Have you had a security breach in the last 3 years?
  4. Who is the contact for security incidents?
  5. Do you have a 24/7 security contact?

What a good answer contains

Watch out for

Write the 72-hour commitment into the plan and your contracts before you promise it to a client. Never answer the breach history question from memory of a template.

Controls behind these answers

These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.

Example: how a prepared answer opens

Question: How quickly will you notify us of a security incident or data breach?

Affected clients are notified without undue delay and within 72 hours of [your company] becoming aware of a breach affecting their data.

This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.

Back to all guides

Related: Logging and monitoring Privacy

Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.