PDRIGHT Book a fit call

Home / Insights / Passing a Fortune-500 security review

How a small agency passes a Fortune-500 client's security review

PDRight · New York · 6 min read

The email doesn't look like a threat. It usually comes from someone you've never met on your client's side — procurement, or a name with "security" in the title — and it's polite. "Before we can renew, we just need you to complete our vendor security assessment. Attached. We'd need it back by the 25th." Attached is a spreadsheet with eighty questions.

Here's what that email really is: your biggest client quietly asking you to prove you're safe to keep working with. Not because anything went wrong. Because their company got bigger, or got burned by a different vendor, or hired someone whose whole job is to check. The account isn't officially on the line. But if that form comes back late, or full of "we're not sure," you've handed them a reason to look elsewhere — and you'll never be told that's why.

I've watched good agencies nearly lose accounts they'd held for years over a form. Not over the work. Over the form. So let me tell you what's actually in it, why it trips up shops like yours, and how the agencies that sail through actually do it.

It's not an IT question. It's a "show your work" question.

The instinct is to forward the form to whoever helps with your computers and hope they handle it. That's where it stalls — because this isn't a fix-the-laptop job. It's a prove-how-you-operate job, and it needs evidence, not reassurance.

Strip away the jargon and almost every one of these reviews asks about the same seven things:

  1. Who can get in. Does your team sign in with more than just a password? Who has the keys to everything, and is that kept to the few who truly need it?
  2. The laptops and phones. Are the devices your people work on locked down, up to date, and encrypted — so a laptop left in a cab isn't a client emergency?
  3. Where the files live, and the backups. Where does the client's work actually sit, who can reach it, and could you get it all back if something broke?
  4. Email. Are you filtering the fake "please update the wire details" messages? Agencies get targeted because you touch valuable brands.
  5. People joining and leaving. When a freelancer rolls off, how fast does their access get shut off? The contractor who still has the login is the classic hole.
  6. When something goes wrong. If there's an incident, is there a plan — who's told, how fast, what happens next?
  7. The paperwork. Do you have actual written security policies, in your agency's name, that say all of the above is real?

None of those is hard on its own. The reason the form is brutal is that it asks all seven at once, on a deadline, and every "yes" needs proof you probably never gathered before. "We're careful" doesn't pass. A clear answer with evidence behind it does.

How the agencies that pass actually do it

The shops that breeze through a review have one thing in common: they were ready before the form arrived. They're not scrambling to become secure in nine days. They're forwarding proof they already had. Here's how you get there — and most of this you can start on today.

Get the basics genuinely in place first. Turn on multi-factor sign-in for everyone. Make sure company laptops are encrypted and updating themselves. Know where client files live and confirm they're actually backed up. Cut admin access down to the two or three people who truly need it. This is the part that's tempting to fake on the form — don't. Reviewers ask follow-up questions, and getting caught overstating is worse than a plain "not yet."

Write down what you do — in your agency's name. A reviewer will ask for your policies. "We all just know the rules" isn't an answer they can accept. You need short, real documents that describe how your shop actually handles access, devices, and incidents. Not a hundred pages. Real ones.

Build your evidence folder before you're asked. For each of the seven areas, keep one piece of proof on hand — a screenshot, a setting, a signed policy, a report. When the form comes, you're pulling from a folder, not inventing answers at 11pm.

Answer plainly, and never bluff. The winning tone isn't "we're an impenetrable fortress." It's calm and specific: here's what we do, here's the proof, and for the one thing we don't do yet, here's our plan and date. Security teams trust the honest, organized answer far more than the too-perfect one.

Handle the freelancer problem out loud. Your reviewer knows agencies run on contractors. The gap they're worried about is the person who left six months ago and can still open the drive. Having a simple joiner/leaver routine — and being able to show it — quietly answers half their fears.

Do those five things and the form stops being a threat. It becomes a formality.

What this should feel like

A security review should be a five-minute forward, not a fire drill. When the readiness is already in place and the evidence is already in a folder, the questionnaire is just a form you fill out and send back — and your client's security team signs off, and the account renews, and you never think about it again.

That readiness is the entire thing we do at PDRight. We get creative and advertising agencies through their enterprise clients' security reviews — with the proof standing behind every answer — so a questionnaire never quietly costs you the account you worked years to win. When the next one lands on your desk, the honest goal is simple: you forward it to us, and you keep the client.