1 min read
Cloud vs Server Security: Choosing the Best for Your Business
Businesses today rely heavily on digital infrastructure. With that comes the need to secure data, applications, and systems against cyber threats....
11 min read
Adrian Ghira
:
September 10, 2026
It arrives on a Thursday afternoon, usually from someone you have never dealt with before. The subject line references vendor risk assessment or supplier security review. Attached is a spreadsheet with somewhere between 40 and 300 questions across tabs labelled access control, business continuity, encryption, and sub-processors. The covering email asks for completion within ten business days and notes, politely, that the renewal is pending completion.
Your largest client has just audited your cybersecurity, and nobody at your company has ever seen the questions before.
This is now one of the most common conversations we have with Canadian businesses in the 20 to 200 user range, and it comes from every direction: a national retailer reviewing its logistics suppliers, a provincial health authority reviewing a service contractor, an energy company reviewing an engineering firm, a bank reviewing a marketing agency that touches customer lists. The questionnaire is not a formality. Deals are being delayed and occasionally lost on the answers.
The good news is that this is a solvable problem, and solving it once mostly solves it permanently. The questions are more consistent than they appear, the evidence you need is finite, and a supplier who answers well is in a materially better competitive position than one who scrambles. The bad news is that a badly handled questionnaire creates two distinct risks: losing the contract, and signing an attestation you cannot support.
Four forces converged, and they are not going to reverse.
Enterprise third-party risk programs became mandatory internally. Large organizations spent the last five years discovering that their own breaches frequently entered through a supplier. Third-party risk management moved from a procurement checkbox to a governed program with owners, tooling, and reporting obligations to a risk committee. Once that program exists, it has to be applied to every supplier, including the 30-person firm that has held the account for a decade.
Regulated sectors now have supply chain obligations in statute. Canada’s Critical Cyber Systems Protection Act, enacted in June 2026 under Bill C-8, requires designated operators in federally regulated sectors to identify and mitigate cybersecurity risks arising from their supply chains and third-party products and services on a continuing basis. The Act’s obligations attach only once the government designates operator classes, and no organization carried them as of mid-2026. But the direction is fixed, and the practical effect for an SMB is indirect rather than direct: when a bank, a telecom, a pipeline operator, or a federally regulated transport company has a statutory duty to manage supplier risk, that duty arrives at your inbox as a questionnaire.
Sector-specific certification programs are setting the template. In defence procurement, the Canadian Program for Cyber Security Certification now requires suppliers to attest to specified controls, with certification functioning as a condition of contract award rather than a nice-to-have. Most Canadian businesses will never bid on a defence contract, but procurement practices propagate. The language and structure of these programs are being reused by private-sector buyers who want a defensible standard to point at.
Cyber insurance made everyone fluent in the same vocabulary. Underwriters spent five years teaching Canadian businesses what MFA, EDR, immutable backups, and tested incident response plans mean. Those same businesses are now the buyers writing questionnaires, and they ask about what they were asked about.
Strip away the formatting and the question count, and almost every third-party security review is testing four things.
Can someone log in as your staff? Multi-factor authentication coverage, whether legacy authentication is disabled, how privileged accounts are handled, how access is granted and removed, and whether anyone shares credentials. This is the section where partial answers are most damaging, because MFA on 90% of accounts reads to a reviewer as MFA on none.
Would you notice a compromise? Endpoint detection and response coverage as a percentage of devices, log retention, who monitors alerts and during what hours, and how long it would take you to detect unusual activity. Traditional antivirus is now treated as a legacy answer.
Could you recover, and how fast? Backup frequency, whether backups are immutable or offline, the date of your last tested restore, and your documented recovery time objective. The last-tested-restore date is the single question that most often exposes a weak program, because plenty of businesses have backups running and no evidence that a restore works.
Is anyone accountable, and can you prove it? A named person responsible for security, written policies, an incident response plan with defined roles, employee training with recent records, vendor management for your own subcontractors, and breach notification procedures. This is the governance section, and it is where SMBs most commonly have the substance without the documentation.
Everything else in a 200-question spreadsheet is a variation, a sub-question, or a sector-specific overlay on those four themes.
The custom spreadsheet. Most common, and the most variable in quality. Often assembled internally by the buyer, sometimes containing questions that do not apply to your relationship at all. These are the ones where a well-written clarifying note adds real value.
Standardized assessments. The Standardized Information Gathering questionnaire and its shorter variants, or the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire, appear when the buyer has a mature program. They are long but predictable, and the answers are highly reusable across customers.
A contractual security schedule. Rather than asking questions, the buyer sends an exhibit to be signed committing you to specific controls, breach notification windows, audit rights, and liability terms. This is the highest-stakes format, because it converts your security posture into an enforceable contractual obligation, and it deserves legal review rather than IT review alone.
A request for a SOC 2 report or equivalent. Increasingly common, and covered in detail below.
A security rating from an external scanning service. Some buyers subscribe to a service that scores your external attack surface from outside and shares the report with you, occasionally with findings that are inaccurate or refer to infrastructure you do not own. These require a factual rebuttal rather than remediation.
Here is the part that gets handled badly, and it is worth being blunt about it.
A completed security questionnaire is a representation. When it is attached to a contract, or referenced in one, it becomes a representation with legal weight. If you answer yes to multi-factor authentication on all remote access, and an incident later reveals a VPN account without MFA, you have two problems: the incident, and a document in which you stated the control existed.
The parallel with cyber insurance is exact. Misrepresentation on the application, meaning a control described that did not exist at the time of the loss, is among the most common reasons Canadian cyber claims are denied. Buyers are beginning to apply the same logic to supplier attestations, particularly where a supplier incident caused them harm.
Two rules follow.
Do not let the person most eager to close the deal complete the questionnaire alone. The commercial incentive is to answer optimistically. Whoever completes it needs to be able to see the environment, or needs to be sitting with the person who can.
A qualified yes beats an unqualified one. “Yes, MFA is enforced on all user accounts including administrative accounts, with three documented service account exceptions that are compensated by conditional access restricting them to a single IP range” is a stronger answer than “Yes.” It demonstrates that you know your own environment, which is the thing the reviewer is genuinely assessing.
The single highest-return action here is to assemble a standing evidence package. Every questionnaire draws on the same underlying artifacts, and having them ready turns a two-week scramble into a two-hour exercise.
What belongs in it:
The remediation register is the item most businesses omit and the one that most improves outcomes. A buyer’s risk team is not looking for perfection. It is looking for evidence that you know where you stand and are managing it deliberately.
You will not be able to answer yes to everything, and pretending otherwise is the worse option. Three techniques.
Name the compensating control. If you do not have 24/7 security monitoring in-house, say so, and describe what you do have: managed detection through a named provider, alerting thresholds, and after-hours escalation. The reviewer’s question is about coverage of the risk, not about the specific mechanism.
Commit with a date. “Not currently in place. Scheduled for implementation by November 30, 2026, as part of a documented remediation plan.” A dated commitment is a legitimate and frequently accepted answer. An undated intention is not.
Distinguish not applicable from not implemented. If a question about cardholder data environments arrives and you never touch cardholder data, the answer is not applicable with a one-line explanation, not a blank cell. Blank cells read as evasion.
When the buyer sends terms rather than questions, five provisions deserve close attention before signature.
Breach notification windows. Some schedules require notification within 24 hours of becoming aware of an incident, and some define incident so broadly that it includes a single blocked phishing email. A 72-hour window tied to a reasonable definition of a security incident affecting the customer’s data is a defensible position to negotiate toward.
Audit and inspection rights. On-site audit rights on short notice are expensive to service. A common compromise is annual documentary review, with on-site inspection triggered only by a material incident.
Flow-down to your subcontractors. If you use a managed IT provider, a cloud platform, or offshore support, the schedule frequently requires you to impose equivalent terms on them. Confirm that you actually can before agreeing that you have.
Insurance minimums. Check the required limit against your current policy before signing. Increasing a cyber limit mid-term is possible but not free, and this clause is a real cost that belongs in your pricing.
Data location and residency. Where your systems store the customer’s data, and whether any of it leaves Canada. This is where a Quebec customer’s Law 25 obligations, or a public-sector customer’s residency requirements, flow through to you.
None of this is IT’s decision alone. A security schedule is a commercial document with technical content, which means the review needs both.
This request is increasingly common, and the instinctive response, to start a SOC 2 program immediately, is usually wrong for a 40-person company. A first SOC 2 Type II is a nine to eighteen month exercise with meaningful cost and ongoing operational overhead.
Three better opening moves.
Ask what the requirement actually is. Frequently the buyer’s policy says “SOC 2 or equivalent evidence of security controls,” and a well-assembled evidence pack plus a completed questionnaire satisfies it. Ask before you budget.
Point to your provider’s certifications where they legitimately apply. If your managed IT provider is SOC2 certified, that covers the controls the provider operates. It does not cover your own controls, and claiming otherwise will be caught. Say precisely what it covers.
Offer a credible alternative. An independent security assessment against a recognized framework, such as the CIS Controls, delivered as a report you can share, is a fraction of the cost of a SOC 2 and satisfies many buyers who asked for SOC 2 because it was the only term they knew.
If you sell to multiple enterprise buyers and the request keeps recurring, then SOC 2 becomes a revenue decision rather than a compliance one, and it should be evaluated as an investment with a pipeline attached.
The businesses that handle this well stop treating the questionnaire as a tax and start treating it as a differentiator, because their competitors are handling it badly.
A supplier who returns a complete, internally consistent, honestly qualified questionnaire within a week, with an evidence pack attached and a dated remediation register for the gaps, reads to a procurement team as a well-run company. That impression carries into the commercial conversation. We have watched clients win renewals partly on the strength of it, and we have watched competitors get dropped from a vendor list because a questionnaire came back with a third of the fields blank.
There is also a lead-generation angle worth naming for anyone selling into regulated sectors: being able to say yes quickly and credibly to a security review is a qualification advantage in tenders where other bidders will need three weeks and a consultant.
GAM Tech has supported Canadian businesses with 20 to 200 users since 2012, from nine markets across Alberta, British Columbia, Ontario, and Quebec, with bilingual support in Ottawa and Montreal.
On supplier security reviews specifically, our work with clients covers completing and reviewing customer questionnaires alongside your team rather than handing you a template, assembling and maintaining the standing evidence pack so it is current when a request arrives, technical review of contractual security schedules before signature so you understand what you are committing to, closing the specific gaps that questionnaires expose most often, and producing the documented remediation register that buyers accept.
We are SOC2 certified, B Corp certified, and Great Place to Work certified, with internal support staff who are never outsourced and a 5-minute response commitment delivered on 99%+ of tickets. Project packs are included in our managed services agreement, so the documentation and remediation work described here is not a separate scoping exercise every time a questionnaire lands.
Silver plans start at $110 per managed device per month with a $1,000 monthly minimum. Gold plans add the layered cybersecurity stack that most questionnaire responses depend on.
What is a vendor security questionnaire? A structured assessment sent by a customer to evaluate your cybersecurity controls before awarding or renewing a contract. It typically covers access control, endpoint protection, backup and recovery, incident response, employee training, and your use of subcontractors. Formats range from a short custom spreadsheet to standardized assessments running several hundred questions.
Do we legally have to complete one? There is no general legal obligation. It is a commercial condition. The consequence of declining is usually losing the contract, and increasingly the questionnaire or an equivalent security schedule is embedded in the agreement itself, which makes completion a contractual requirement.
Who should complete it, IT or the business? Both. Someone with visibility into the environment has to supply the technical facts, and someone accountable for the commercial relationship has to review what is being represented. Letting either do it alone produces answers that are optimistic, or answers that lose the deal unnecessarily.
What happens if we answer yes to something we do not actually have? You have created a documented misrepresentation. If an incident later exposes it, you face contractual exposure and potentially a claim, and the same logic that lets a cyber insurer deny a claim for misrepresentation can be applied by a customer who suffered harm. Answer accurately and qualify where needed.
How long does a security questionnaire take to complete? The first one, without preparation, commonly takes two to four weeks of elapsed time and several days of effort. With a standing evidence pack, subsequent ones typically take a few hours. That gap is the entire argument for building the pack.
What if the questionnaire asks about controls that do not apply to us? Answer not applicable with a one-line explanation of why. Never leave fields blank; a reviewer reads blanks as avoidance, and a clear not-applicable answer with reasoning demonstrates that you understood the question.
Our customer asked for a SOC 2 report and we do not have one. What now? Ask what their policy actually requires, because many accept equivalent evidence. Offer your completed questionnaire and evidence pack, your provider’s certifications for the controls your provider operates, and if needed an independent assessment against a recognized framework. Only start a SOC 2 program if multiple enterprise buyers are requiring it and the revenue justifies a nine to eighteen month project.
Does Bill C-8 mean our business now has cybersecurity obligations? Almost certainly not directly. The Critical Cyber Systems Protection Act applies to designated operators in six federally regulated sectors, and obligations attach only once the government designates operator classes. The realistic impact on a typical Canadian SMB is indirect: designated operators must manage supply chain risk, and that shows up as supplier security requirements.
What is the most common gap a questionnaire exposes? A tested restore. Many businesses have backups running and no documented evidence that a restore has been performed and verified. The second most common is partial endpoint protection coverage, where a percentage in the high eighties reads as a failure to a reviewer.
Should we push back on a customer’s security schedule? Yes, where the terms are disproportionate. Twenty-four hour notification windows, broad audit rights on short notice, and unlimited liability for security incidents are all commonly negotiated. Push back with an alternative rather than a refusal, and get legal review on liability and indemnity language.
What should we look for in an IT provider to support this? A provider that will sit with you on the questionnaire rather than emailing a generic template, that maintains your evidence pack proactively so it is current when a request arrives, that can speak to its own certifications precisely, and that will tell you plainly which answers are currently no and what closing them costs.
Third-party security reviews are not going away, and they are moving down-market fast. The businesses that treat the first one as a project, build the evidence pack, and keep it current spend an afternoon on each subsequent request. The businesses that treat each one as a fire drill spend two weeks, answer inconsistently across customers, and eventually put a signature on something they cannot support.
If a questionnaire is on your desk now, or you would like to know how your environment would answer one before a customer asks, GAM Tech offers a supplier readiness review across all nine of our Canadian markets. Contact us to arrange one.
1 min read
Businesses today rely heavily on digital infrastructure. With that comes the need to secure data, applications, and systems against cyber threats....
1 min read
Introduction: The Hidden Cost of "We'll Refresh When We Have To" Walk through the offices of most Canadian SMBs and you'll see a familiar pattern: a...
1 min read