PS ProTech(305) 699-5652
← All posts

Consultancies

Your client's security team will ask about yours

· PS ProTech · 2 min read

You've won the engagement. Then procurement sends a form: forty questions about encryption, access controls and incident response, due before the work can start. For a ten-person consultancy this can feel absurd. From the client's side it makes complete sense.

Why they ask

Attackers who can't get into a large company directly go through the firms it trusts. Verizon's 2026 breach report found a third party involved in 48% of breaches, up 60% in a year (Verizon 2026 summary).

A consultancy is an attractive route in. You hold the client's strategy, financials and personnel data. You may have logins to their systems. And you're assumed to have less protection than they do.

So their security team now assesses you the way they'd assess a software supplier. Passing that assessment is becoming a condition of the work.

What they'll ask

  • Is multi-factor authentication enforced on your email and wherever their data is stored?
  • Are your laptops encrypted and managed? Can you wipe one that's lost?
  • Where is our data kept, who can reach it, and when is it deleted?
  • Do you train your staff?
  • How would you detect a breach, and how fast would you tell us?
  • Do you use AI tools on our information? This is the newest question, and many contracts now restrict it.
  • Which of your own suppliers can see our data?

The consultancy-specific risks

Laptops that travel. Your team works from client sites, hotels and airports. Every one of those laptops carries client data. See what RMM is for how they're kept managed wherever they are.

Leftover access. Logins to a client's systems that nobody closed when the project ended.

Shared links. Documents shared by open link stay reachable long after the engagement.

Staff and AI tools. A consultant pasting a client's data into a chatbot to draft a slide may have broken the contract. See a policy for staff using AI tools.

How to get ready

  1. Put the basics in place: multi-factor authentication, encrypted and managed laptops, email security, backup. Our 15-point checklist covers them.
  2. Write it down. A short security policy answers a third of most questionnaires on its own.
  3. Build an answer library so the second form takes an hour, not a week. See how to answer a client security questionnaire.
  4. Close out engagements properly: return or delete data, remove access, and record that you did.

Turn it into an advantage

Most small consultancies answer these forms badly. One that replies quickly, with evidence, looks like a safer choice than a larger competitor who takes three weeks. Security has become part of how you win work.

Our page for consultancies covers the threats in more detail. To find your gaps before a client does, book a free IT and cybersecurity review.

See what it costs for your firm.

Build a plan in two minutes. No call required.