Skip to content
Vendor questionnaire

A spreadsheet arrives from your biggest customer

Five questions about your IT. A deadline in two weeks. None of the questions are hard, but nobody in the building can answer them without spending a week on it first. Here is how you deal with it, once and for all.

You are not in scope. You are asked anyway

The questionnaires look alike across industries, because they build on the same frameworks. Here are the five questions that keep coming up, and the answer most owner-managers actually have to them today. To be returned within 14 days of receipt.

You may have seen the questions before, from the bank, the insurer or the board. They come from the same place.

NIS2 applies to medium and large companies within eighteen designated sectors, and a typical owner-managed company sits below the threshold. But Article 21 obliges the companies in scope to manage the security of their direct suppliers, and they meet that by passing the requirement down through contracts and questionnaires.

So the requirement reaches a subcontractor that is not itself covered by the law. Not as a fine, but as a condition for keeping the customer. It is an occasion with revenue at stake, and it rarely comes only once.

It is not a security problem. It is an overview problem. Most companies actually do the right thing. They just cannot document it, because nobody has ever had to write it down in one place.

Ejerblik is a register of the company's digital assets. Which systems you have, who owns them, who has access, which supplier is behind them, and when the agreement renews. That is exactly the list the questionnaire asks for. The questionnaire is the occasion. The register stays, and it keeps working for you afterwards.

Five questions nobody can answer

  • Attach an inventory of the IT systems that process or store data about us. It lives in three heads and a mailbox
  • State who at your company is responsible for each system. It was Bjarne who set it up, I think
  • Confirm that two-factor authentication is enabled on systems with access to our data. Probably, but not in writing
  • Explain how access is removed when an employee leaves. No written procedure
  • List your IT subcontractors and their role. Spread across twelve invoices

From two weeks of digging to an export

  1. Find

    More than 400 suggested assets you can tick off instead of having to remember them. If you want the thorough route, the account scanner reads through your bank statements and finds the subscriptions nobody remembers paying for.

  2. Name

    Responsible person, admin access, two-factor status, supplier and notice period. Those are the questionnaire's five questions, translated into fields.

  3. Link

    Who has access to what. When an employee leaves, you close all access from one place, and it is documented that it happened.

  4. Send

    Pull a report, or share a secure link with an expiry date and an optional password. The next time the form arrives, it takes minutes.

How it looks in Ejerblik

A signed document on a desk, a supplier statement and contract requirements
app.ejerblik.com
Ejerblik supplier overview with contract status and risk indicator, actual screenshot
What you get along with it

The list solves three other problems you already have

  • When someone leaves. Access is closed the same day, not three months later when someone happens to notice that the former sales manager can still log in to the CRM.
  • When agreements renew. Notice periods and renewal dates in one place, so no agreement is extended by a year because nobody looked in time.
  • When you sell one day. The buyer's adviser asks the same questions as your biggest customer, just more of them. If the list has been kept up, it costs nothing extra.

Why it takes a week

Nobody owns the list
An accounting program in 2014, a CRM in 2019, four tools marketing found on their own. The systems were bought over time, and nobody was tasked with keeping track of them together.
Access follows people
The account is in an employee's name and often on a personal email address. You typically discover it the day that person resigns.
The evidence does not exist
The customer is not asking for an assurance that you have it under control. The customer is asking for documentation, and what you have is a feeling.
The subcontractors are invisible
Hosting, agency, bookkeeper and the systems they each use. They sit spread across invoices, not in an inventory.

Ejerblik does not replace your IT supplier

The inventory and the securing are two different jobs. Ejerblik documents what you have, who owns it and who has access. Updates, backup, monitoring, incident response and the technical side of two-factor authentication still sit with your IT partner, and the inventory makes their work easier to prioritise.

Having the assets in Ejerblik does not in itself mean you comply with NIS2. We have set out exactly what we cover and do not cover, control by control, on the coverage page for NIS2 and CIS18.

Set aside an hour and get the list finished

Tick off the systems you can think of and put a name on them. Most people have the first thirty assets in place in under an hour. No card, and the account is ready straight away.

No lock-in · Data in the EU · Support in English