Frontrow Technology
← All insights & guides
Guide

Cyber Security · Mining & Resources

Mining supplier cyber security questionnaire: the checklist

The security questions mining principals keep asking suppliers before awarding work, mapped to the Microsoft 365 Business Premium controls and evidence that answer them.

Sam Williams · 28 August 2026 · 12 min read

The email arrives from the principal's procurement team, usually late in a tender or right before contract award: a supplier security questionnaire, sometimes 40 questions, sometimes 200, due back in 10 business days. For a 20-person maintenance contractor, a labour-hire firm or an engineering consultancy chasing work in the Bowen Basin, it is often the first time anyone in the business has been asked to describe their cyber security posture in writing. The managing director forwards it to whoever looks after IT, and the honest first reaction is that nobody knows what half the questions mean, let alone whether the answers will cost the business the contract.

Frontrow has helped METS businesses through this exercise from its Mackay office, and the useful news is that the questionnaires are more alike than they look. The wording varies by principal and by platform, but the underlying question set recurs, and a business running Microsoft 365 Business Premium properly can answer most of it with controls it already pays for. This guide describes the recurring themes, maps each one to the M365 control that answers it, and lists the evidence worth attaching so the response reads as demonstrated rather than claimed.

Why the questionnaire exists

Mining principals treat supplier cyber security as supply chain risk, and they are following government guidance in doing so. The Australian Cyber Security Centre publishes specific advice on cyber supply chain risk management that tells large organisations to identify their suppliers, assess their security posture and manage the residual risk. Major principals also publish their supplier expectations openly: Rio Tinto, for example, maintains a public supplier area covering its Supplier Code of Conduct, procurement processes and supplier portals. Contractors connect to principals in ways that matter, through emailed invoices and purchase orders, shared project documents, site access systems and sometimes direct network or application access, and a compromised supplier mailbox is a well-worn path into a larger target.

The practical consequence is that prequalification now runs through procurement portals and standing questionnaires, and the security section is no longer optional. A supplier that cannot answer it credibly does not usually get told the security response lost the work. It simply scores lower, gets asked for remediation commitments, or waits longer while a competitor with a cleaner response is onboarded first.

The question categories that recur

Individual questionnaires are usually confidential to the principal, so this guide does not quote any company's wording. What can be said with confidence, from the assessments Frontrow has worked through and from the public frameworks the questionnaires borrow from, is that the same categories keep appearing:

  • Multi-factor authentication: whether MFA is enforced for all users, for administrators, and for remote access, not merely available.
  • Patching: how quickly operating systems and applications receive security updates, and whether the process is managed or left to individual machines.
  • Access control: who holds administrative privileges, how leavers are removed, and whether access to the principal's data is limited to the people who need it.
  • Backups and recovery: whether business data is backed up, how often restores are tested, and how long recovery would take after ransomware.
  • Malware defence and monitoring: what endpoint protection runs on the fleet, and whether anyone would notice a compromise in progress.
  • Email security: protections against phishing and payment redirection fraud, the compromise pattern that actually hits contractors most often.
  • Incident response: whether a written plan exists, who is notified, and how quickly the principal would hear about an incident affecting its data.
  • Data handling: where the principal's information is stored, who can access it, whether it is encrypted, and what happens to it when the contract ends.
  • Framework alignment and certification: whether the business aligns to the Essential Eight, holds ISO 27001 certification, or can point to an equivalent structured program.
  • Cyber insurance: whether a current policy exists, and for what cover.

The Essential Eight deserves a sentence of context, because it anchors many of the Australian questionnaires. It is the Australian Signals Directorate's set of eight baseline mitigation strategies, patching applications and operating systems, MFA, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening and regular backups, with an accompanying maturity model that defines levels from zero to three. When a questionnaire asks about E8 alignment it is asking where the business honestly sits on that scale. Frontrow's mapping of Maturity Level 2 to specific Microsoft 365 settings is at /insights/essential-eight-ml2-microsoft-365-implementation-map and is the natural companion to this guide.

The checklist: mapping each theme to Microsoft 365 Business Premium

Microsoft 365 Business Premium is the licence most METS businesses of this size either hold or should hold, because it bundles the security workloads the questionnaire is really asking about: Microsoft Entra ID P1 for Conditional Access, Microsoft Intune for device management, Microsoft Defender for Business for endpoint detection and response, and Defender for Office 365 for email protection. The mapping below takes each recurring theme and states the control that answers it and the evidence to attach.

Identity and access

  • MFA for all users. Control: Conditional Access policies requiring MFA on every sign-in, or at minimum outside trusted locations, with no standing exclusions beyond documented break-glass accounts. Evidence: a screenshot of the enabled CA policies and the authentication methods activity report showing registration coverage.
  • Administrative privilege restriction. Control: named, separate admin accounts, no daily-driver accounts holding Global Administrator, and role assignments reviewed on a schedule. Evidence: an export of Entra ID role assignments with a one-line justification per admin.
  • Leaver removal. Control: a documented offboarding step that disables the account, revokes sessions and reclaims the licence on the leaver's last day. Evidence: the written procedure plus a recent example with identifying details removed.

Devices, patching and protection

  • Managed patching. Control: Windows Update policies deployed through Intune with defined deferral and deadline settings, so updates install on a schedule rather than by goodwill. Evidence: a screenshot of the update ring configuration and the Intune device compliance summary.
  • Endpoint detection and response. Control: Microsoft Defender for Business onboarded across the fleet, which gives the business genuine EDR rather than plain antivirus. Evidence: the device onboarding list from the Defender portal.
  • Email protection. Control: Defender for Office 365 anti-phishing policies, plus SPF, DKIM and DMARC configured on the sending domain, which is what actually blunts payment redirection fraud. Evidence: policy screenshots and a DMARC record lookup.
  • Device compliance for site and workshop hardware. Control: Intune compliance policies requiring disk encryption, screen lock and a supported OS version before a device touches company data, which matters for the ute laptop as much as the office desktop. Evidence: the compliance policy and the percentage of compliant devices.

Data, backups and response

  • Data handling. Control: the principal's documents held in a dedicated SharePoint site per client or per contract, with access scoped to the delivery team, plus sensitivity labels on commercially confidential material. Evidence: a screenshot of the site permission structure, and a written line on data location, Australian-region tenancy for most AU businesses, and end-of-contract handling.
  • Backups. Control: this is the honest gap, covered in the next section, because Business Premium retention settings are not a backup product on their own. Evidence: the backup solution's coverage report and the date of the last successful test restore.
  • Incident response. Control: a short written plan naming who declares an incident, who calls the IT provider, who notifies affected principals and what the Notifiable Data Breaches scheme obliges the business to do. Evidence: the plan itself; two pages that exist beat 20 that do not.
  • Monitoring and audit. Control: Microsoft 365 audit logging left enabled, Defender alerts routed to a monitored mailbox or a managed provider, and sign-in logs reviewed when something looks wrong. Evidence: a sample alert notification and a line describing who monitors it.

Try it

Check the data handling answer before the principal does

The data handling questions assume the principal's files are only visible to the people delivering its work. Run the oversharing check to find out whether the tenant's sharing settings actually support that answer.

Score each dimension · 4 options

Is your tenant ready for Microsoft 365 Copilot?

Copilot is as smart as your tenant is tidy. Twelve quick questions — each mapped to a Microsoft-native capability that closes the gap. Takes about ten minutes.

  • 01

    Anonymous "anyone with the link" shares

    External access

    How does your tenant handle anonymous sharing links?

  • 02

    Tenant-wide / "Everyone except external" site sharing

    Permissions hygiene

    Do you have sites shared with "Everyone" or "Everyone except external users"?

  • 03

    External guest access hygiene

    External access

    How do you manage external guest users in Entra ID?

  • 04

    Site collection admin sprawl

    Identity & privileged access

    How tightly is SharePoint site collection admin access controlled?

  • 05

    Broken permission inheritance

    Permissions hygiene

    How much unique (non-inherited) permissioning exists across your sites?

  • 06

    Orphaned sites with no active owner

    Permissions hygiene

    How do you handle sites whose owner has left or gone inactive?

  • 07

    OneDrive personal sharing patterns

    External access

    Do staff share sensitive documents (HR, finance, contracts) from OneDrive?

  • 08

    Sensitivity label coverage

    Content classification

    How much of your content is classified with Microsoft Purview sensitivity labels?

  • 09

    Restricted SharePoint Search / content discovery controls

    Content classification

    Have you enabled Restricted SharePoint Search or equivalent discovery controls for sensitive sites?

  • 10

    Microsoft Teams / Groups public vs private hygiene

    Permissions hygiene

    How strict is the hygiene on Team / Microsoft 365 Group privacy settings?

  • 11

    Legacy classic SharePoint sites

    Permissions hygiene

    Do you still have classic (pre-modern) SharePoint sites in the tenant?

  • 12

    Access review cadence for sensitive sites + external access

    Identity & privileged access

    How often do you review access to sensitive sites and external user lists?

What Business Premium does not answer

A credible questionnaire response also knows its own edges, and three recur. First, backups: the Essential Eight expects regular backups of important data with tested restoration, and native M365 retention is not that. Frontrow's standing position is that a third-party backup service covering Exchange, SharePoint and OneDrive closes this line item for a few dollars per user per month, and the tested restore date is the evidence that matters. Second, application control: the E8 strategy of allowing only approved applications to execute is achievable on Business Premium through Intune and Windows Defender Application Control, but it is real engineering work, not a checkbox, and it is honest to answer 'in progress' with a date rather than overclaim. Third, certification: ISO 27001 is a certified management system, not a product feature, and no licence purchase confers it. Most 20-person suppliers do not need it; where a principal genuinely requires certification, that is a separate program with a realistic timeline measured in months.

Cyber insurance sits alongside rather than inside the tenant. Insurers now ask many of the same questions the principal does, MFA and EDR and backups above all, so the control work in this checklist typically serves both answers at once. Attach the current certificate of insurance to the response; a lapsed or absent policy is better disclosed than discovered.

Assembling the evidence pack once, reusing it every time

The questionnaire will come again, from the next principal, from the insurer at renewal, and from the same principal's annual reassessment. The businesses that handle this well stop treating each one as an emergency and maintain a standing evidence pack:

  1. 1A Microsoft Secure Score export from the Defender portal, which gives an independent, dated measurement of tenant posture and shows trend over time.
  2. 2Screenshots of the Conditional Access policies, Intune compliance and update policies, and Defender for Office 365 settings, refreshed whenever the policies change.
  3. 3The written incident response plan and offboarding procedure.
  4. 4The backup coverage report and last test restore date.
  5. 5The current cyber insurance certificate.
  6. 6A one-page security summary in plain language that a procurement officer can read without an IT translator.

Reviewed quarterly, the pack turns a 10-day scramble into a half-day response, and the same tenant hygiene underwrites everything else the business wants to do next. The AI conversation is the obvious example: the permissions, labelling and access work above is precisely the readiness work described from the operator's side in /insights/copilot-for-mining-australia, and a supplier that has done it for prequalification has quietly done most of its Copilot groundwork too.

Common questions

Frequently asked

Do we need ISO 27001 to win work with a mining principal?
Usually not at the 20-to-50-person supplier scale. Most questionnaires ask whether you hold it, and accept a structured alternative such as demonstrated Essential Eight alignment with evidence. Where a specific principal contract genuinely mandates certification, treat it as a separate months-long program and price it into the work, because no software licence confers it.
What happens if we have to answer no to some questions?
Answer honestly and attach a dated remediation plan. Assessors read thousands of these and a candid 'not yet, planned for October' with a named owner scores better than an overclaim that falls apart at audit or after an incident. A false answer can also void the exact insurance and contract protections the questionnaire exists to check.
Does Microsoft 365 Business Premium make us Essential Eight Maturity Level 2?
No licence does by itself. Business Premium supplies the tooling for most of the eight strategies, MFA through Conditional Access, patching through Intune, EDR through Defender for Business, but application control takes deliberate engineering, backups need a third-party product, and maturity is assessed on what is actually configured and evidenced, not what is licensed.
What evidence should we attach to a supplier security questionnaire?
A dated Microsoft Secure Score export, screenshots of Conditional Access, Intune compliance and email protection policies, the written incident response plan, the backup coverage and last test restore date, and the current cyber insurance certificate. Keep them in one standing pack and refresh quarterly rather than rebuilding per request.
How long does mining supplier prequalification take?
The security response itself is typically due back within one to two weeks, but the full prequalification cycle, questionnaire, clarifications, remediation commitments and onboarding, commonly runs one to three months. Suppliers with a maintained evidence pack move through fastest because the clarification round shrinks.
Is cyber insurance mandatory to work for mining companies?
It is increasingly requested in questionnaires and in contract schedules, alongside the familiar public liability and professional indemnity lines, though requirements vary by principal and by contract. Expect the insurer to ask for MFA, EDR and tested backups before quoting, which is the same control set the principal wants, so the work pays twice.

The matched next step

Find out where your own tenant would have failed

Most incidents start with a control Frontrow checks in week one: MFA coverage, legacy authentication, admin sprawl, unpatched servers. A security baseline review scores your Microsoft 365 tenant against the Essential Eight and hands you a prioritised fix list — whether or not Frontrow does the fixing.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.