How to answer
Have you experienced a security breach or data incident in the last 24 months?
The dangerous answer is not yes. It is a confident no from a company with no logging, which is a claim about something it has no way of knowing.
No incidents meeting our notification threshold have occurred in the last 24 months. Our incident response plan defines that threshold as any confirmed unauthorised access to, or loss of, customer data, and commits us to notifying affected customers without undue delay and within 72 hours of confirmation.
FillTrust grades an answer like this not in your documents when your documents support it.
- Answered from
- Your incident register, and the notification clause in your incident response plan.
- Evidence to attach
- Rarely the incident record itself. Usually a statement, with the register available under NDA if they push.
- Where it is asked
- CAIQ v4.0 · SEF-07SIG LiteISO 27001 Annex A · A.5.26
This is the question people most want to answer quickly, and the one where speed does the most damage.
A "no" here is not the absence of a fact. It is a positive claim that you would have detected an incident if one had happened, and everything else on the questionnaire is being read as evidence for or against that claim. If two rows earlier you said logs are retained for thirty days and nothing monitors them, a reviewer now has a company asserting a clean record it has no instrument to observe. That is worse than disclosing something small.
Say what threshold you are answering against. Most incident response plans define a reportable incident, and most answers do not mention it. Without one, "breach" means whatever the reader assumes, and readers assume broadly: a phishing email somebody clicked, a laptop left on a train, a misconfigured bucket found by a researcher. With a threshold stated, your answer is checkable and narrow. Without it, you are making an unbounded promise about two years of history.
A disclosed incident handled well is not a lost deal. Security teams have all seen incidents; what they are reading for is whether you noticed, how fast you told people, and what changed. A company that says "yes, here is what happened and here is the control we added" is often in a better position than one asserting perfection, because the first is verifiable and the second cannot be.
Where this product will leave the box empty. If your documents contain an incident response plan but no register, this comes back as a gap rather than a "no". That is deliberate and it is the correct behaviour: nothing in a policy document is evidence about what did or did not happen, and answering from a policy alone would be inventing a fact about your history.
How this one goes wrong
Specific to this question, not general advice.
- Answering "no" when you mean "none that we noticed". If you have no logging and no alerting, you do not know the answer, and a reviewer who finds that out later treats every other answer as suspect.
- Answering "no" while your status page shows an outage that was caused by a compromised credential. These get cross-checked more often than people expect.
- Defining the threshold after the question is asked. If your plan does not say what counts as reportable, you are deciding it under pressure and in your own favour, which is exactly the appearance to avoid.
- Volunteering detail about an incident you did disclose. Confirm it happened, name what changed as a result, and stop. A narrative invites follow-ups that a one-line answer does not.
Asked in the same breath
Do you have a documented incident response plan, and what is your breach notification window?
Incident response
How quickly will you notify us of a data breach?
Incident response
Are background checks performed on employees with access to customer data?
People
Are backups tested by performing restores?
Resilience