Skip to content

Why your customers are starting to ask about your IT security

Why your customers are starting to ask about your IT security

If you have renewed a contract with a larger customer recently, you may have noticed the paperwork getting longer. Somewhere between the pricing schedule and the signature page there is now a security questionnaire, and the questions are getting harder to wave through.

This is not a passing fashion. It is the early effect of a change in the law, and it is worth understanding before it lands on your desk.

What is actually changing

The Cyber Security and Resilience Bill completed its stages in the House of Commons on 25 June 2026 and is now working its way through the House of Lords. Among other things, it brings managed IT providers under direct regulation for the first time. Around a thousand providers across the UK fall into scope.

We are one of them.

We would rather say that plainly than let it arrive as a surprise later. It means our own security, our reporting and our record keeping come under formal oversight, and it means we have been preparing for it since the Bill was published.

Why it reaches businesses that are not regulated

The Bill does not apply directly to most small and medium sized businesses. What it does is oblige regulated organisations to take proper account of the risk sitting in their supply chains.

In practice that pushes the requirement downhill. A hospital trust asks its suppliers. Those suppliers ask theirs. Within a couple of steps the question reaches a twelve person firm in Cramlington that has never thought of itself as part of anyone’s critical infrastructure.

The government’s own research suggests most businesses are not ready for this conversation. Only around 15 per cent currently review the cyber risk of their immediate suppliers at all.

What customers are likely to ask for

The questions vary, but the same handful come up again and again:

  • Do you hold Cyber Essentials or an equivalent certification
  • Do all staff use two step login on email and cloud systems
  • How quickly do you apply security updates
  • Who do you use for IT support, and are they accredited
  • What happens if you are breached, and how quickly would we be told

None of these are difficult if the groundwork is done. All of them are awkward if you are answering them for the first time with a deadline attached.

Questions worth asking your own IT provider

The flip side is that you are somebody else’s supply chain risk, and your IT provider is yours. It is entirely reasonable to ask them:

  1. Are you in scope of the Cyber Security and Resilience Bill, and what are you doing about it
  2. How quickly would you tell us if you had an incident that affected our data
  3. Do you hold Cyber Essentials, and when was it last renewed
  4. Which of our systems are you actually monitoring, and which are you not
  5. If a customer sends us a security questionnaire, will you help us complete it

That last one matters more than it looks. Most of the answers a questionnaire asks for sit with your IT provider rather than with you, and a good one will fill it in alongside you rather than sending you a link to a knowledge base article.

Where we sit

We have supported businesses across the North East for over 20 years, including sectors where this scrutiny arrives soonest. Legal firms, social care providers and manufacturers are already seeing it in tenders.

Our job is to make sure that when the questionnaire arrives, the answers are already true. That is what our IT service management and business IT solutions work is for.

If you would like us to look over a questionnaire you have been sent, or simply to tell you honestly where you stand, get in touch or call the team on 0191 296 0111.

Back To Top