Cybersecurity
Our Biggest Customer Sent Us a Security Questionnaire and Nobody Here Can Answer It
The machine shop sits off Route 8 in Butler County, thirty four employees, second generation, and it has been shipping parts to the same large manufacturer for nineteen years. In August the customer's purchasing portal sent a document titled Supplier Information Security Assessment. Sixty one questions. Due in three weeks. A line near the top said completion was required to remain an approved supplier.
The owner forwarded it to the office manager, who forwarded it to the guy who set up their server in 2018 and still helps out when something breaks. Nobody in that building could answer question four, which asked whether the company maintains an inventory of assets that store or process customer data. Not because the answer is bad. Because nobody had ever been asked to write it down.
This is how most small businesses in Western Pennsylvania end up searching for cyber security audit services. Almost nobody wakes up wanting an audit. They get asked for one, and the asking comes from three directions: a cyber liability insurer at renewal, a large customer running a vendor security review, or a regulator or examiner. The question underneath all three is the same. Can you show us, in writing, what you have and how it is protected?
An honest answer to that question requires somebody to actually look. That is what an audit is.
What do cyber security audit services actually look at?
A useful audit is not a scan and it is not a sales pitch with a logo on it. It is a structured review of the environment you actually run, measured against a defined standard, producing a written record of the gap between the two.
In a 5 to 50 employee business, that review covers a fairly predictable set of ground.
Identity and access. Who has an account, who has administrator rights, and who left in 2023 and still has a working login. Over privileged accounts and dormant accounts are the two findings we see in nearly every first audit, and they are also two of the cheapest to fix.
The perimeter and the network. Firewall rules opened for a vendor project years ago and never closed, remote access paths, and whether the guest wifi is genuinely separated from the network holding your files.
Endpoints and patching. Which machines are missing updates, which are running an operating system that stopped receiving them, and whether anything is unmanaged and quietly on the network anyway.
Email. Which is where the actual attacks arrive. Multi factor authentication status, mailbox forwarding rules nobody set up on purpose, and the domain records that determine whether somebody can send mail that looks like it came from you.
Backup and recovery. Not whether backups exist, which they usually do, but whether anybody has restored from one. A backup that has never been tested is a plan, not a protection. We wrote about what a real recovery test involves in our piece on building a disaster recovery plan for a small business.
Data and vendors. Where customer or patient or cardholder data lives, who else touches it, and what your cloud tenants are configured to allow.
Documentation and policy. The part small businesses skip, and the part questionnaires ask about relentlessly. An incident response contact list, a written access policy, evidence that employees receive training.
The deliverable matters as much as the review. What you want back is a prioritized list of findings with severity, effort, and a recommended order of operations, plus answers you can actually paste into that questionnaire. What you do not want is a two hundred page tool export nobody reads. Our own cybersecurity assessment is built around a remediation roadmap for that reason.
How is a security audit different from a vulnerability scan?
This is the question that separates providers, and it is worth understanding before you buy anything.
A vulnerability scan is automated. Software connects to your systems, compares what it finds against a database of known weaknesses, and produces a list. It is fast, repeatable, and should be running regularly rather than once. See vulnerability scanning for what that looks like on a monthly cadence.
An audit is broader and slower, because it includes the things software cannot see. A scanner cannot tell you that the owner's login is shared with the bookkeeper. It cannot tell you that the offsite backup drive goes home in somebody's truck on Fridays. It cannot tell you that your remote access is fine technically and terrible procedurally, because anybody who calls the office claiming to be a new employee gets set up the same afternoon.
The practical distinction: a scan tells you what is broken, an audit tells you what is unmanaged. Most small business breaches trace back to the second category.
Some providers market cyber security assessment services that are, on inspection, a scan with a cover page. The test is simple. Ask whether the engagement includes interviews with your staff and a review of your written policies. If not, you are buying a scan.
What is the difference between an audit and cyber security risk assessment services?
The words get used interchangeably in marketing, but there is a real difference and it changes what you get back.
An audit is a compliance question. It measures you against a standard, whether that standard is HIPAA, PCI-DSS, the NIST Cybersecurity Framework, CMMC, or your customer's own questionnaire. The output is conformity: here is the control, here is whether you meet it.
Cyber security risk assessment services ask a business question instead. What could realistically go wrong here, how likely is it, what would it cost this specific company if it happened, and what should we spend to reduce it. The output is a ranked set of risks with business impact attached, not a checklist.
Small businesses usually need both, in that order, and they cost less together than separately because the fieldwork overlaps almost entirely. The audit gives you the answers the insurer and the customer want. The risk assessment gives you the argument for what to fund next, which is the part an owner has to defend at a budget meeting. If somebody quotes you for one, ask what the other would add.
Why is everybody suddenly asking us for this?
Because the people who carry the financial risk stopped taking your word for it.
Cyber liability insurers used to sell policies on a one page application. After several years of paying claims, they now underwrite on controls, and the renewal questionnaire has become an audit in disguise. Multi factor authentication, endpoint detection, tested backups, and email filtering are common conditions rather than discounts. Answering incorrectly is worse than answering badly, because a misrepresented control is a coverage argument at exactly the wrong moment.
Large customers followed, because their own compliance obligations flow downhill. A supplier in Mercer or Lawrence County is now routinely assessed by the manufacturer it sells into, and a hospital system will assess the billing company it shares patient data with. If you serve a regulated industry, you are part of somebody's supply chain risk whether or not you signed up for it.
Regulators are the third source, and the one with the clearest teeth. A dental or medical practice under HIPAA is required to conduct a risk analysis; it is not optional and it is not a one time task. A business taking cards has PCI obligations that scale with how it processes them. An accounting firm or registered advisor has both regulatory expectations and client contracts that assume specific safeguards.
None of these three groups are impressed by the sentence we hear most often, which is that you have antivirus and a firewall. That describes 2011.
What happens when the audit finds something bad?
It will find something. That is not a failure of the audit or of your business, and the reaction to expect from a decent provider is boredom rather than alarm.
The findings sort into three buckets. There are quick fixes, which is most of the list: enabling multi factor authentication, disabling the accounts of four former employees, closing two firewall rules, turning on the security features already included in the Microsoft 365 licenses you are paying for. These usually take days and often cost nothing beyond labor, because you already own the tools.
There are funded projects: replacing an unsupported server, moving off a line of business application the vendor stopped patching, adding real endpoint detection. Those get scheduled against a budget and a calendar.
Then occasionally there is an active problem. A mailbox quietly forwarding copies of every message to an outside address. Credentials from your domain already circulating from somebody else's breach. When that shows up, the audit becomes an incident, and the response happens immediately rather than in the report.
The thing to negotiate before you sign is what happens after the findings. An audit that hands you a list and leaves is worth a fraction of one that helps you close the list and then re-tests to confirm it is actually closed. Re-testing is what turns a finding into evidence, and evidence is what the insurer and the customer want to see next year.
How long does it take and how disruptive is it?
For a business in this size range, expect three to five business days of fieldwork and about a week to the delivered report, longer if you have multiple sites or a complicated line of business system.
Disruption is minimal and falls on two or three people rather than the whole company. Passive scanning runs safely during business hours and anything intrusive gets scheduled off hours. The real time cost is interviews: somebody who knows how the business runs spends two or three hours answering questions about who does what, which is exactly the knowledge no scanner can extract.
The one thing that slows an audit down is access. Nobody knows the firewall password, the former IT provider will not hand over administrator credentials, the domain registrar login belongs to a web designer from 2016. Chasing those down is routinely the longest part of the engagement, and it is also, quietly, one of the findings.
How often does a small business actually need one?
A full audit annually, tied to your insurance renewal so the answers are current when the application arrives. Vulnerability scanning monthly, because the environment changes every week and an annual snapshot goes stale by February. A fresh look after anything structural: a new location, a server replacement, a change of IT provider, or a security incident of any size. Practices under HIPAA should treat the risk analysis as ongoing and documented rather than annual and filed, because if a regulator asks, the date on the document is the first thing they look at.
The businesses that handle this well are not the ones spending the most. They are the ones where somebody owns it. In most of our client relationships that is us, as part of ongoing managed IT support, which is also why their questionnaires get answered in an afternoon instead of a panicked three weeks. Where an audit uncovers that the underlying problem is that nobody owns security at all, the honest fix is usually structural, and we covered that decision in our piece on what outsourcing cyber security actually changes.
The machine shop in Butler County finished the questionnaire. Some answers were fine, a dozen needed work first, and the rest needed somebody to write down what was already true. The customer kept them on the approved list, and what surprised the owner was not the findings. It was that the whole exercise took less time than the three weeks spent dreading it.
MCR Business Tech Solutions provides cyber security audit and assessment services, vulnerability scanning, and ongoing managed IT for small and mid-sized businesses across Butler, Armstrong, Mercer, Lawrence, Crawford, Erie, and Allegheny counties (Butler, Kittanning, Ford City, Sharon, Hermitage, Grove City, New Castle, Meadville, Erie) plus bordering eastern Ohio and northern West Virginia. If a questionnaire, a renewal, or an examiner has put this in front of you, call 833-859-9021 or Request an IT assessment through our contact page, and we will start with the questions you have been asked rather than the ones we would like to sell you.