Thirty-five years inside a bank's security function, on both sides of the assessment. I now do one thing: complete the vendor security questionnaires that stall enterprise deals, and tell you the truth about what is in them.
I spent my career as a senior network security analyst inside a bank — firewalls, access control, F5, SIEM, and the audit cycle across a six-country Caribbean footprint, under continuous regulator scrutiny. Not a consultancy engagement that ended when the report shipped. The same estate, year after year, with the consequences of every answer landing back on my desk.
That means two things for you. I have completed these assessments as the vendor, under a deadline someone else set. And I have run them from the other side, reading a supplier's answers and deciding whether to believe them. I know which sentences a reviewer stops on, because I stopped on them.
CISSP and CCSP certified. Based in Port of Spain, Trinidad & Tobago; I work in English with companies anywhere.
Not when it would be faster. Not when you ask me to. A confident wrong answer is what turns a compliance exercise into a legal problem eighteen months later, and keeping that off your desk is the entire job.
So when your evidence does not reach, you get the honest answer, the smallest fix that would close the gap, and a realistic estimate of the effort. That is worth more than a spreadsheet of yeses, and it is the reason the work is defensible when someone reads it back to you at renewal.
What I do not do.
I do not issue certifications or audit opinions — I am not an audit firm and no one should represent my work as an attestation. I do not draft contractual, insurance or indemnification language; breach-notification windows, right-to-audit clauses and liability limits go to your counsel, and I mark them clearly rather than guessing. And I do not answer questions about your environment from imagination. If it is not in your evidence and you cannot confirm it, it gets flagged.
Buyers rarely explain what they have sent you. Here is the short version.
| Format | Who publishes it | What to expect |
|---|---|---|
| SIG | Shared Assessments | A scoping tool, not a fixed document. In the 2025 release the Lite, Core and Detail presets held 128, 627 and 1,936 questions; the current release is SIG 2026 and counts are not published. Twenty-one risk domains, including a dedicated Artificial Intelligence domain. A “SIG” can be almost any length — which is why I price on the question count, not the name. |
| CAIQ | Cloud Security Alliance | v4.1 (January 2026) is current at 283 questions mapped to CCM v4.1's 207 controls across 17 domains. CAIQ-Lite is 138. CSA also publishes a separate AI Controls Matrix. |
| HECVAT | EDUCAUSE | The higher-education standard. Since version 4 the former Full, Lite and On-Premise editions are consolidated into a single conditional workbook, so the length depends on your answers. |
| Their own spreadsheet | The buyer's procurement or security team | The most common thing I receive. Usually a hybrid assembled from the above plus whatever the last incident taught them. Answered the same way, in their format, keyed to their numbering. |
Version details as published by each body and current as of 26 August 2026. These move; I check before quoting.
Yes, before you send anything. Send me yours, or I will use a straightforward mutual one.
No — that is the normal starting point at five to fifty people, and it is exactly what the security profile step is for. We do a short call, I write down what is actually true about your environment, and every answer comes from that.
No. That is the one thing I will not do, and it is the reason to hire me rather than someone who will. A flagged gap with a date attached tends to clear procurement; an overstated yes fails late, in the follow-up call, after the reviewer has stopped trusting the rest of the document.
Three days for most documents, five for a full CAIQ, and a 48-hour rush is available. If your deadline is not achievable I will say so before you order rather than take it and miss it.
Your evidence stays yours. I keep nothing beyond what is needed to finish the work and honour the revision window, and I delete it on request.
Not from scratch. The security profile is the reusable asset — the second questionnaire is a fraction of the first, which is what the retainer is for.
Reply the same day, with a fixed price and a delivery date — not an estimate.