A decade ago, an enterprise brand hired an agency on the work and the relationship. Today, before the contract is signed — or renewed — their procurement, security, and legal teams want proof that your agency won't be the weak link that leaks their data or their unreleased campaign. That proof is the security review. This guide explains what it really tests, and how a small agency becomes "review-ready" without turning into an IT department.
Why this is happening to agencies now
It's not personal, and it's not about your size. Three forces converged:
- Enterprises got burned by vendors. A large share of breaches now start with a third party. So big companies vet every supplier who touches their systems, data, or brand — and agencies touch all three.
- Compliance rolled downhill. When your client has to meet SOC 2, ISO 27001, or a privacy law, they're contractually required to push those same expectations onto their vendors. You inherit their homework.
- Cyber insurance tightened. Insurers now require specific controls and will deny claims if an attestation turns out to be false — so your clients ask you to attest, too.
The result: a 20-person creative shop now gets the same security questionnaire a 2,000-person software vendor does. Fair or not, the deal waits until you answer it.
The three forms a review takes
"Security review" is a catch-all. In practice you'll meet one of three, and they're often confused:
- A security questionnaire — a list of questions (custom, or a standard format like SIG or CAIQ) about your controls. The most common, and usually the first. We cover it in depth in what to do when a client sends a questionnaire.
- A request for a SOC 2 report — a formal, audited attestation. Expensive and time-consuming. Most agencies are asked for the questionnaire long before anyone truly needs SOC 2 — don't buy the audit until a real deal requires it.
- A cyber-insurance attestation — you confirm specific controls are in place so your client (or you) can bind coverage. Getting this wrong has real legal weight.
Knowing which one you're facing tells you how much work is actually in front of you. Nine times out of ten, it's the questionnaire.
What every review is really checking
Strip away the hundreds of questions and every review probes the same five areas. Get these genuinely in place and you can answer almost anything truthfully.
1. Access — who can get in
Multi-factor authentication on everything, unique accounts per person, no shared logins, and prompt removal of access when someone leaves. This is the single most-asked area, and the one insurers care about most.
2. Devices — the laptops doing the work
Every machine that touches client data is managed: up to date, protected against malware, encrypted, and remotely wipeable if lost. For Mac-heavy creative shops this is a real gap area, because most security advice assumes Windows.
3. Detection & response — catching a bad day
Something malicious will eventually land in an inbox or on a device. Reviewers want to know you'd detect it and act — not discover it months later. This is monitoring plus a plan.
4. Data & backup — where their work lives
Where client data is stored, who can see it, how it's shared with freelancers, and whether you could recover it after ransomware or a mistake. "It's all in email and a shared drive nobody manages" fails here.
5. Process & policy — proof it's real
Written policies (acceptable use, access, incident response, data handling) and evidence you follow them. Many questions map straight to "attach your [X] policy." No policies means whole sections fail by default.
How to become review-ready (in order)
You don't fix all five overnight, and you don't need to. Work in this sequence:
- Start with access. Turn on MFA everywhere and clean up accounts. Highest impact, lowest cost, and it answers the most questions.
- Get every device managed. One system that enforces updates, encryption, and protection across your Macs (and any PCs).
- Add monitoring and a response plan. So "we'd catch it" is a true answer.
- Sort out data and backup. Know where client work lives and prove you can recover it.
- Write the policies last — once the controls behind them are real, so the documents are true.
Do this and the questionnaire stops being a fire drill: you're just describing what's already in place, with evidence attached.
The honest part: what not to do
The fastest way to lose an account isn't failing a question — it's getting caught overstating. Never claim a control you don't have. A truthful "not yet, here's our timeline" builds trust; a bluffed "yes" that surfaces during an incident becomes a legal problem. Security teams expect a few gaps from a small vendor. What they're really scoring is whether you know your own posture and take it seriously.
Where a partner fits
If you have the controls and just need to translate them into reviewer language, you can do it yourself. Bring in help when the review is high-stakes, you're unsure which answers are true, or you have gaps you don't know how to close — and you'd rather not build an IT function to solve a client requirement.