CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
      • IT Help Desk
      • 24/7 Emergency Support
      • Co-Managed IT
      • Remote IT Support
      • Onsite IT Support
      • Proactive Monitoring
      • Patch Management
      • Network Monitoring
      • Mobile Device Management
      • IT Procurement
      • IT Documentation
      • Server Management
      • Mac Support
      • Employee Onboarding & Offboarding
    • Cybersecurity
      • Endpoint Security
      • Network Security
      • Managed Firewall
      • Email Security
      • Phishing Protection
      • Security Awareness Training
      • Dark Web Monitoring
      • Penetration Testing
      • Multi-Factor Authentication
      • Zero Trust
      • Vulnerability Scanning
      • SIEM Services
      • Managed SOC
      • Virtual CISO (vCISO)
      • Password Management
      • Managed Detection & Response
    • Business Continuity & Disaster Recovery (BCDR)
      • Backup & Disaster Recovery
      • Microsoft 365 Backup
      • Cloud Disaster Recovery
      • Backup & DR Audit
      • Backup as a Service
      • Tabletop Exercises
    • Cloud Services
      • Microsoft 365
      • Microsoft Azure
      • Cloud Migration
      • SharePoint
      • Virtual Desktop
      • Azure Managed Services
      • Cloud Monitoring & Management
      • Microsoft Entra ID
      • Microsoft Teams
      • Microsoft Exchange
      • OneDrive for Business
      • Amazon Web Services (AWS)
    • AI Services
      • AI Policy & Governance
      • AI Security & Risk
      • AI Readiness Assessment
      • AI Strategy
      • AI Assistant Platforms
      • AI Training & Adoption
      • AI Workflow Automation
      • AI Development
      • Agentic AI
      • Business Intelligence
      • Business Process Automation
      • Data Analytics
    • Compliance
      • SOC 2
      • HIPAA
      • CMMC
      • NIST CSF
      • PCI DSS
      • FTC Safeguards
      • CIS Controls
      • Cyber Insurance
      • Compliance Audit
    • Network, Voice & Strategy
      • Software Defined Wide Area Networks (SD-WAN)
      • Voice Over IP (VoIP)
      • Virtual CTO & CIO Services
      • Teams Phones & Conferencing
      • Network Assessment
      • IT Consulting
      • IT Cost Assessment
      • Digital Transformation Strategy
      • Legacy System Assessment
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise
    • Architecture
    • Banking & Credit Unions
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Healthcare
    • Law Firms
    • Manufacturing
    • Non-Profit
    • Oil & Gas Services
    • Real Estate & Property Management
    • Transportation & Logistics
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Texas Breach Notice Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Reviews
  • Contact
I Need IT Support Now
A document clipped to a screenshot and a calendar page, representing a dated evidence pack for a vendor security questionnaire
Shane Stevens
Shane Stevens October 6th, 2026

9 Things to Do After a Customer or Bank Sends You a Security Questionnaire

From Inbox To Signed: A Security Questionnaire Walkthrough – Vendor Security Questionnaire Help For Houston Businesses

After the Questionnaire Arrives
Got a Vendor Security Questionnaire From a Customer or Your Bank? Do These 9 Things Before You Sign It.

An ordered checklist for Houston businesses with 10 to 200 employees and a form due back this month.

TL;DR
A vendor security questionnaire is a signed statement about your IT. Find out what it decides, sort the questions, give each an owner, attach proof to every yes, write honest no answers with dates, have the signer read it, and keep the pack for next time.
🔎 Who Is Asking 🗂️ Sort the Questions ✅ Answers You Can Show 📤 Send and Keep 💵 What It Costs 🚀 How CinchOps Helps

A vendor security questionnaire lands when a customer's procurement team or your bank wants written answers about your IT controls before a contract, a renewal or an account review moves forward. The 9 steps below get a Houston business to answers it can prove, an honest plan for the gaps, and a shorter form next year.

Picture the moment. Your biggest customer's procurement team wants 40 answers about multi-factor authentication, backups and incident response, and the contract renewal is waiting on it. There is a signature line at the bottom with your name under it.

3 options present themselves. Fill it in optimistically tonight. Forward it to whoever handles IT and hope. Ask for an extension and lose a week. Each one skips the same step, which is finding out what you can show before you decide what to say.

THE 9 STEPSFrom Inbox to Signed and FiledIn the order to do themStep 1Know what it decidesStep 2Learn your tierStep 3Sort into 3 pilesStep 4Name an owner per lineStep 5Attach proof to each yesStep 6Read the scope wordStep 7Write the honest noStep 8Have the signer read itStep 9File the answer packCinchOps · cinchops.com
The short version: answer nothing until every question sits in one of 3 piles: yes with proof, yes without proof, or no. If the form came from an insurer instead, use the cyber insurance renewal questionnaire steps.

Find Out Who Is Asking and What the Answers Decide

Steps 1 and 2: a 15-minute call that changes how long the form takes.

A vendor security questionnaire exists because the sender has to show someone else that its suppliers were checked. Before answering, a business should learn what decision the answers feed, who reads them, and which risk tier the sender has placed it in, because the tier sets how much proof is expected.

WHY THE FORM EXISTSThe Question Flows DownhillEach party is asked by the one before itA regulator or auditorasks them for proofYour customer or bankhas to check vendorsYour businessgets the questionnaireYour IT providerholds half the answersThe form is how the sender documents that it checked youCinchOps · cinchops.com

1. Know what the answers decide before you write one

The same form can gate a bid, a contract renewal, or nothing more than a yearly file update, and the right amount of effort is different for each. A general contractor's prequalification form decides whether a subcontractor can bid at all. A renewal form from an existing customer usually wants to see progress since last year. Owners who do not ask tend to treat every form as pass or fail and answer accordingly.

  • Call or email the sender and ask what the questionnaire is for: new work, renewal, or annual review.
  • Get the real deadline, and find out whether partial answers with dates are accepted.
  • Find out who scores it: procurement, a security team, or an outside assessor.
  • Request any scoring guide or minimum requirements in writing.

2. Learn which tier you are in, because the tier sets the length

Federal bank regulators issued joint guidance on third-party risk on June 6, 2023, and it applies to all banks with third-party relationships. The OCC, the Federal Reserve and the FDIC wrote in that guidance that "not all third-party relationships present the same level of risk or criticality to a bank's operations." Large customers sort vendors the same way. A firm that never touches the customer's systems or sensitive data belongs in a lower tier, and a lower tier means fewer questions.

  • Describe in 2 sentences what you access: their network, their data, their site, or none of these.
  • Say so plainly when a whole section does not apply, and name the reason.
  • Check whether a shorter form exists for your tier before starting the long one.

The 2026 Travelers Risk Index found that fewer than 6 in 10 businesses formally assess their supply chain partners and vendors. A customer that sends you a questionnaire is in the group that does, and 53% of businesses in the same survey said they worry about lost income from a vendor or supplier incident.

Sort Every Question Before Anyone Starts Typing

Steps 3 and 4: the sort takes an hour and prevents the guessed yes.

Most vendor security questionnaires ask about the same 8 topics in different words. Sorting each question into yes with proof, yes without proof, or no, and naming one owner per question, shows a business exactly how much work stands between it and an answer it can sign.

3. Sort the questions into 3 piles so the real workload is visible

A 40-line vendor security questionnaire usually comes down to about 8 topics, each asked several ways. We see the same list on forms from contractors, operators, law-firm clients and banks. Once the questions are grouped, the form stops looking like 40 problems.

  • Multi-factor authentication: on email only, or on remote access and admin accounts too.
  • Endpoint protection on every computer, including shared and field machines.
  • Backups: where the second copy lives and when a restore was last tested.
  • Email authentication, so nobody can send mail that appears to come from your domain.
  • Administrator access: who has it and how it is removed when someone leaves.
  • A written incident response plan with a named person who declares an incident.
  • Staff training on phishing and payment fraud, with dates.
  • Evidence for all of the above, dated before today.
BEFORE ANYONE TYPESEvery Question Goes in 1 of 3 PilesThe middle pile is the one that causes troubleYes, with proofA document or screenshotexists todayAnswer and attachYes, without proofBelieved true,cannot be shown yetProve it or change itNoNot in placeAnswer with a dateCinchOps · cinchops.com

Mark each question with one of 3 labels. "Yes with proof" means a document or screenshot exists now. "Yes without proof" means you believe it is true and cannot show it yet. "No" means it is not in place. The middle pile is the dangerous one, and it is usually the biggest.

4. Give every question one owner so nothing gets answered by assumption

A 2022 joint advisory from CISA, the NSA and the FBI says a contract with an IT provider should specify "whether the MSP or the customer owns specific responsibilities, such as hardening, detection, and incident response." A questionnaire tests whether that split was ever written down. In a company without an IT department, questions default to the owner or the office manager, who then answers for systems an outside provider or a software vendor runs.

  • Put a name beside each question: you, your IT provider, or the vendor of a specific system.
  • Send each owner only their questions, with the deadline and the proof you need back.
  • Keep policy questions yourself. Nobody outside can attest to what your staff are told to do.

Write Answers You Can Show, Including the No Answers

Steps 5, 6 and 7: proof, scope, and the honest no.

Every yes on a vendor security questionnaire should have a dated document behind it, every answer should match the scope word in the question, and every no should carry a date for when it changes. A customer's assessor can ask for evidence at any time, and a guessed yes is a written misstatement to a customer.

5. Attach a dated artifact to every yes so the answer survives a follow-up

In 2022 a cyber insurance policy was declared null and void from its inception after the insurer alleged the insured's MFA attestation did not match what was running. That case, Travelers v. International Control Services, involved an insurance application, and the same test applies to a customer form: someone can check the answer later. A control you cannot document is, for the customer's purposes, a control you do not have.

ANATOMY OF A YESA Yes Has 4 PartsQuestion, answer, artifact, date1The question"Is MFA enforced onall remote access?"2The answerYes, for all userson VPN and email3The artifactPolicy screenshotshowing who is covered4The dateCaptured this month,before the form went backAn answer is finished when all 4 parts existCinchOps · cinchops.com
  • Capture a screenshot of the MFA policy showing who it covers, with the date visible.
  • Export the latest backup report and the record of the last test restore.
  • Save the incident response plan and the security policy as dated PDFs.
  • Pull the training completion report for the last 12 months.

6. Read the scope word in each question so a true answer does not become a wrong one

94% of businesses say they are familiar with MFA, and only 60% use it to validate administrative users, according to the 2026 Travelers Risk Index. That gap is where questionnaires go wrong. The form asks whether MFA is on "all remote access" or "all privileged accounts," the owner knows it is on email, and the box gets a yes.

Scope words to watch are all, every, any and always. For a Houston oil and gas service company or a construction subcontractor, "all devices" includes the laptops in trucks, the shared PC in the yard office and the tablets on the jobsite. If endpoint protection covers the office and not the field, the accurate answer is a partial one with a date.

7. Write the honest no with a date so the gap reads as a plan

An honest no has 3 parts: what is missing, who owns the fix, and the date it will be in place. In our experience, customer security teams are closing their own audit findings and want vendors who know where they stand. A no with a date gives them something to file. A yes they later disprove gives them a reason to drop a vendor.

What an honest no looks like: "Not yet in place. MFA is enforced on Microsoft 365 for all users today. MFA on the remote-access VPN is scheduled, owned by our IT provider, and will be enforced by March 31. Evidence will be sent on completion."
  • Close the cheap gaps before the deadline when you can: MFA on remote access, email authentication records, one real test restore.
  • Give a realistic date for the rest. A missed date is worse than a later one.
  • Never soften a no into "in progress" unless work has started and you can say what was done.
"Do not answer a security questionnaire the night it arrives. Sort it first. The pile that hurts people is the middle one, the things you believe are true and cannot show. Prove those or change the answer, and write the no answers with a date. A customer can work with a date."
Shane Stevens, CEO, CinchOps - LinkedIn

Send It Back Once, Then Keep What You Built

Steps 8 and 9: the signature, and the pack that shortens the next form.

The person who signs a vendor security questionnaire should read every answer before it goes back, and the finished answers and evidence should be filed as one dated pack. The same pack answers the next customer, the bank, the cyber insurer, and the written-program standard in Texas SB 2610.

8. Have the signer read every line so the signature means something

The signature on a questionnaire belongs to the business, even when an IT provider wrote half the answers. In 35+ years doing this, the forms that caused trouble later were rarely the ones with a no on them. They were the ones nobody senior had read. A 30-minute sitting with the owner, the person who filled it in and whoever runs IT is enough.

  • Walk the yes-without-proof pile one last time. Each item is now proven, changed to a no with a date, or marked not applicable.
  • Return the form with the evidence attached and one named contact for follow-up questions.
  • Send it through the channel the customer asked for, and avoid emailing passwords or full network diagrams.

9. File the answer pack so the next questionnaire takes an afternoon

Texas SB 2610 protects a business with fewer than 250 employees from exemplary damages if it maintained a conforming cybersecurity program at the time of a breach. The documents that satisfy a customer questionnaire are most of that program. For a business with 20 to 99 employees the standard is the CIS Controls Implementation Group 1, and the questionnaire topics in step 3 overlap it heavily.

BUILD IT ONCEThe Same Pack Answers 4 AskersRefresh it on a schedule and reuse itOne datedanswer packNext customer formYour bank's reviewCyber insurance renewalTexas SB 2610 programCinchOps · cinchops.com
  • Store the completed form, every attachment and the list of promised dates in one folder with the year on it.
  • Put the promised dates on a calendar with an owner, and send the customer the evidence when each one closes.
  • Refresh the screenshots and reports on a schedule you will keep.
  • Offer the pack up front next year. A customer who already holds current evidence often sends fewer questions.

One pack answers the customer, the bank and the insurer

The same controls sit behind all 3 forms. See how CinchOps cybersecurity services keep the evidence current for Houston businesses.

See what is covered →

What Does Answering a Vendor Security Questionnaire Cost in Houston?

Mostly hours, and the hours depend on what already exists.

Answering a vendor security questionnaire costs time rather than a fee: an afternoon when a dated evidence pack already exists, and a week of evenings when it does not. Managed IT in Houston typically runs $100 to $250 per user per month, and the reports a questionnaire asks for should come out of that service.

The published CinchOps rate is a flat $100 to $250 per user per month, so a 25-person Houston firm budgets $2,500 to $6,250 a month for managed IT, with no long-term contract, no hidden fees and no cancellation penalty. Ask any provider whether answering questionnaires with you is inside the rate or billed as a project.

WHERE THE GAP WORK COMES FROMWhat Businesses Told Travelers in 2026The same items a questionnaire asks about60%use MFA to validateadministrative users40%have no writtenincident response plan53%worry about income lostto a vendor incidentSource: 2026 Travelers Risk IndexCinchOps · cinchops.com

The larger cost is the gap work the form exposes. In the 2026 Travelers Risk Index, 40% of businesses had no written incident response plan. A firm in that group meets the question for the first time on a customer's form, with a deadline attached. If the questionnaire turned up more than a few no answers, put the fixes in next year's plan with the 2027 small business IT budget guide.

How CinchOps Can Help a Houston Business Answer a Security Questionnaire

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.

For questionnaire season, CinchOps provides managed IT and cybersecurity specifically for 10 to 200 employee businesses in Houston, with help desk requests answered in under 15 minutes by a named engineer who knows the network being asked about.

WHO HOLDS THE EVIDENCEQuestionnaire Topics by CinchOps ServiceWhere each report comes fromThe questionnaire asks aboutThe CinchOps service behind the answerMFA, accounts and devicesManaged IT supportMonitoring and endpoint protectionCybersecurity servicesBackups and restoresBusiness continuity and disaster recoveryWritten policy and incident planCTO and CIO servicesCinchOps · cinchops.com
  • Through managed IT support, the patch, account and device reports a questionnaire asks for come from the tools already running your network.
  • With cybersecurity services, threat monitoring runs 24/7, and the help desk is staffed Monday through Friday, 8 to 6.
  • Top-tier plans under business continuity and disaster recovery include immutable, offsite, verified backups kept outside the Gulf Coast flood zone.
  • CTO and CIO services cover the written policy and the incident response plan, drafted once and kept current.
  • CinchOps serves Houston, Katy, Sugar Land and Cypress, and works with construction, oil and gas and law firms.

A questionnaire on your desk is a deadline, and the worst answer to it is a confident guess. Sort it, prove what you can, date what you cannot, and keep the pack. If you want someone to go through the form with you line by line, talk to CinchOps and bring the last one you signed.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What is a vendor security questionnaire?

A vendor security questionnaire is a form a customer, bank or partner sends to a supplier asking for written answers about its IT security controls, such as multi-factor authentication, backups, incident response and staff training. The sender uses the answers to decide whether to start or continue the relationship, and usually keeps them on file.

Why did my bank send my business a security questionnaire?

Federal regulators expect banks to manage the risk of their third-party relationships. Joint guidance from the OCC, the Federal Reserve and the FDIC, issued June 6, 2023, applies to all banks with third-party relationships. If your business provides a service to the bank, the questionnaire is how the bank documents that it checked.

Can I answer no on a security questionnaire and still keep the customer?

Often, yes. A no that states what is missing, who owns the fix and the date it will be in place gives the customer's security team something it can accept and track. A yes that cannot be supported with evidence when the customer asks is the answer that puts the relationship at risk.

Who should fill out a vendor security questionnaire for a small business?

Whoever runs the technology should draft the technical answers, and the owner or an officer should read every line before signing. Policy questions stay with the business. Questions about systems run by an outside IT provider or a software vendor go to that provider, with a deadline and a request for proof.

What does it cost to answer a security questionnaire in Houston?

The form itself costs time, usually an afternoon when dated evidence already exists. Managed IT in Houston typically runs $100 to $250 per user per month, and the published CinchOps rate is a flat $100 to $250 per user per month. Ask whether questionnaire help is included in that rate or billed separately.

How long should a business keep its questionnaire answers?

Keep the completed form, every attachment and the list of promised dates together for at least as long as the customer relationship lasts. The pack is the starting point for next year's form, the bank's review and the cyber insurance renewal, and it is evidence that a security program existed on a given date.

Discover More

Cyber Insurance Renewal Questionnaire: 9 Steps
What Does Texas SB 2610 Require for the Cybersecurity Safe Harbor?
2026 Travelers Risk Index: What It Means for Houston SMBs
How to Run a Cybersecurity Tabletop Exercise at a Houston Business
What Does a Managed IT Provider Actually Do Day to Day?
Small Business IT Budget 2027: What to Plan Beyond the Quote

Resource

Infographic: 9 things to do after a customer or bank sends a security questionnaire, in two phases, with 2026 Travelers Risk Index figures on MFA and incident response plans
9 Things to Do After a Security Questionnaire Open Full Size

Sources

  • OCC Bulletin 2023-17, Third-Party Relationships: Interagency Guidance on Risk Management - issued June 6, 2023 by the OCC, the Federal Reserve and the FDIC.
  • Travelers, 2026 Risk Index: cyber - vendor assessment, vendor income-loss concern, MFA use for administrative users, and incident response plan figures.
  • CISA, NSA, FBI and partner agencies, Cybersecurity Advisory AA22-131A - contracts should specify which party owns hardening, detection and incident response.
  • Insurance Journal, Travelers v. International Control Services - policy declared null and void after the MFA attestation dispute.
  • Texas SB 2610, enrolled text - under 250 employees, headcount tiers, program in place at the time of the breach.
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

June 3rd, 2025
Managed Service Provider Houston
Microsoft and CrowdStrike Unite to Solve Threat Actor Naming Confusion

Industry Giants Unite to Create “Rosetta Stone” for Cybersecurity Intelligence – Microsoft and CrowdStrike Announce Threat Actor Naming Alignment Initiative

March 18th, 2026
Proactive IT Houston
Proactive Managed IT Support: What Houston SMBs Actually Need

Stop Paying for Faster Firefighting and Start Preventing Fires – A Practical Guide to Proactive IT Support for Houston Businesses

April 3rd, 2026
Claude Code Leak
Claude Code Source Code Leak: What Houston Businesses Must Learn About Supply Chain Security

The Claude Code Leak Is a Blueprint for How Supply Chain Attacks Escalate – Software Dependency Risks Every Houston Business Should Audit

July 22nd, 2026
Managed IT Houston
5 Ways to Spot a Self-Serving “Top Managed IT” Article

Five Quick Checks Before You Trust Any “Top MSP” Ranking

March 9th, 2026
Coffe Shop Network
Coffee Shop Networking: What It Is and Why Your Business Security Depends on Understanding It

How Managed IT Support Closes the Remote Worker Security Gap – Understanding the Coffee Shop Networking Model and Its Business Impact

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Business Continuity & Disaster Recovery
  • Cloud Services
  • Compliance
  • Virtual CTO & CIO
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy