CISOs: how to take back control of your strategic agenda when questionnaires eat up your time
In brief.
The CISO’s paradox: hired to manage risk, they spend their days filling in questionnaires. Three structural projects are waiting for their agenda to free up. The cost of manual handling is not measured in hours, but in security projects that do not move forward.
Jérôme Emin has the profile every IT services company dreams of hiring. An experienced CISO, with a solid command of the frameworks and a clear view of the security stakes. When he joins Sully Group, an IT services company with 900 employees, the mission is ambitious: structure the security policy, prepare for ISO 27001 certification, deploy an in-house SOC, make progress on NIS2.
Six months later, he comes to a harsh conclusion: he spends most of his time answering customers’ security questionnaires. Not securing the company. Not steering the projects he was hired for. Filling in Excel cells.
“Two days per questionnaire. Sometimes three. I was hunting for documents in four different tools, checking certification dates, answering the same questions in different formats for each customer. It was exhausting, and above all, it was not my job.”
This is not an exceptional situation. It is the daily reality of most CISOs in 2026.
The paradox of the overstretched CISO
The CISO role has never been so strategic. NIS2 has come into force. Clients’ security requirements have tightened. Supply chain security incidents have soared. Boards are asking for quarterly reporting. Key account customers are making security maturity a condition for getting onto their supplier panel.
And yet, in most organisations, the CISO spends 40% of their time handling incoming questionnaires, audits and compliance requests, according to measurements taken at Optivalue.ai customers.
40%. Out of 220 working days, that is 88 days a year spent compiling answers rather than securing the company.
Meanwhile, the NIS2 plan is moving slowly. The SOC has not yet been deployed. The overhaul of the IAM policy is on hold. And every new incoming questionnaire pushes these projects back by another week.
This is the paradox of the overstretched CISO: the more your reputation for rigour grows, the more questionnaires customers send you. The more of them you handle, the less time you have to maintain the level of security that justifies that reputation.
Three projects your agenda will not let you tackle
NIS2: the compliance that cannot wait
The NIS2 directive sets precise requirements for risk management, supply chain security, incident notification and business continuity. For essential and important entities, non-compliance carries penalties of up to €10 million or 2% of worldwide turnover.
Preparing properly for NIS2 takes time: mapping critical assets, gap analysis, updating policies, training teams, continuity testing. This work cannot be handed to a service provider without strong internal steering. It requires the presence and attention of a CISO who knows the organisation’s context.
But if that CISO spends Mondays and Tuesdays answering customer questionnaires, NIS2 will progress in degraded mode. And the auditor, for one, will not wait.
The SOC: the investment you are not steering
Deploying an in-house SOC (or overseeing the integration of an outsourced SOC) is a project that demands daily attention for 3 to 6 months. Choosing use cases, integrating log sources, qualifying detection rules, training level-1 analysts, load testing.
Every interruption is costly. A CISO who comes back to this project after two days of questionnaires loses the thread. Decisions are delayed. Teams wait for answers. The schedule slips.
IAM: the building block everyone postpones
Identity and access management is one of the most frequent sources of incidents, and one of the most postponed projects. Not for lack of will, but for lack of availability. A proper IAM overhaul requires workshops with business teams, a map of existing rights, and a least-privilege policy to be defined and approved.
This work cannot be done in fragmented meetings squeezed between two questionnaires. It requires continuous blocks of time, a presence and a capacity to make decisions that the CISO cannot offer if they are permanently in reactive mode.
What handling questionnaires manually costs structurally
The problem is not only the time spent. It is the quality of the attention it takes.
Answering a 200-question security questionnaire means tracking down dozens of documents across different systems (SharePoint, document management, email, network folders), checking the validity of the certifications cited, cross-checking information between internal policies that sometimes contradict each other, and writing consistent answers in the format imposed by the customer.
It is work that is both tedious and demanding. It takes high-quality attention: exactly the kind of attention you need to steer NIS2, the SOC or IAM.
And it generates errors. A certification cited after its expiry date. A subcontracting policy that no longer matches the version in force. An inconsistency between the technical and organisational sections. These errors are not due to negligence on your team’s part. They are due to a volume that is incompatible with rigorous manual handling.
The solution Jérôme Emin tested
Faced with this, Jérôme Emin decided to test Optivalue.ai on a typical customer security questionnaire: 247 questions, Excel format, 48-hour deadline.
The usual process would have taken two full days. With Optivalue.ai:
Step 1. The questionnaire is loaded into the platform. The reference documents (security policies, ISO certifications, audit reports, internal procedures) are connected to Sully Group’s dedicated instance: hosted in France, with no data shared between customers.
Step 2. The platform generates a first draft of the answers in 47 minutes. Every answer is sourced: original document, page number, validity date. Expired certifications are flagged automatically.
Step 3. Jérôme reviews, adjusts two phrasings on sensitive points specific to the customer relationship, and approves. Review time: 45 minutes.
Total time: 1 h 32 min instead of 2 days.
“It is the first time an AI has really saved me time on something concrete. Not a demonstration, not a POC: a real customer questionnaire, with our real documents, in production. The next day, I was free to make progress on NIS2.”
Sully Group now handles all of its security questionnaires through Optivalue.ai. The time freed up has been reassigned to deploying the SOC and preparing the ISO 27001 certification renewal.
Three concrete use cases for taking back control
NIS2: preparing the documentation. Optivalue.ai lets you answer incoming NIS2 questionnaires (clients, partners, auditors) by drawing directly on your existing document base. Risk management policies, incident notification procedures, continuity measures: everything is sourced from your own documents, with the associated evidence. The auditor gets verifiable answers. You spend less time producing them.
SOC: answering integration questionnaires. When a SOC is deployed, security teams are asked about their detection architecture, their use cases and their escalation procedures. These questions arrive as structured questionnaires. Optivalue.ai handles them by drawing on your existing architecture documents and runbooks, without interrupting the steering of the project.
IAM: supplier and customer assessments. IAM policy is one of the most frequent topics in security questionnaires. Access rights, the principle of least privilege, privileged account management, multi-factor authentication. Optivalue.ai extracts the relevant elements from your internal policies and structures them in the requested format, without you having to find and rephrase them every time.
What it really changes for your agenda
The question is not whether AI can answer your questionnaires. It can, with rigour and traceability.
The question is what you do with the time freed up.
If your team handles 8 questionnaires a month at 2 days each, you have 16 person-days tied up on this task every month. With Optivalue.ai, that volume drops to less than 2 days. You get back 14 person-days a month: the equivalent of one full-time person on your strategic projects.
14 days a month to make progress on NIS2.
To steer the SOC.
To complete the IAM overhaul.
To prepare the ISO audit with the rigour it deserves.
Not a promise. A calculation. With your own figures.
Optivalue.ai is up and running in under 7 minutes. Dedicated private instance, hosting in France, no data shared between customers. Jérôme Emin processed his first questionnaire on the day of deployment. Request a personalised demo →
Back to topOn the same topic