Market Entry
Five Information Security Controls for New Sri Lanka Teams Facing Client Reviews
When an overseas client asks for information security evidence, a new Sri Lanka team will usually benefit more from establishing five verifiable controls than from immediately buying a certificate: asset and software records, account access management, endpoint protection, access and incident records, and backup and third-party arrangements. These controls may not replace a client-required certification, but they create evidence for questionnaires, audit discussions and remediation plans.
A project may be close to delivery when a client suddenly sends a security questionnaire. The team then discovers that employees bought their own laptops, shared email accounts are still in use, former employees' accounts were never centrally removed, and nobody can clearly identify where key files are stored. This does not necessarily mean the team lacks technical capability. More often, basic security administration was left out while a new office, new hires and remote working arrangements were being set up at the same time.
Does a client request for “security evidence” mean you must buy a certification immediately?
A common assumption is: If a client asks about security policies, device management or data backups, you must obtain an international certification immediately or the engagement cannot continue.
In practice: Start by identifying what the client is actually requesting. Is it a certification threshold, a supplier security questionnaire, audit cooperation, or a remediation commitment? Some clients do require a specified certification. Others are primarily looking for a clear explanation of your current controls, responsible owners, operating records and improvement plan. Without consistent controls, even purchased tools will not help you answer basic questions such as who can access data or how accounts are disabled when someone leaves.
The cost of this misunderstanding: Your whole budget may go into certificates or software while no evidence is created for day-to-day operation. When the client asks follow-up questions, you may still be unable to provide an asset register, access approval records or backup recovery arrangements. The review then returns to the starting point.

Why should an asset and software register come first?
A common assumption is: If employees' computers work properly, it does not matter who purchased them or which software is installed.
In practice: You need to know, at a minimum, which laptops, mobile devices, servers, cloud accounts and key applications handle client information; who holds each device; and how devices and data are returned, wiped or handed over when an employee leaves, a device is lost or a project ends. If your team uses bring-your-own-device arrangements, define what business information may be stored, whether local downloads are allowed, and who handles an incident.
The cost of this misunderstanding: Client information may end up across unidentified personal devices, private email accounts or unapproved applications. After staffing changes, you may not even be able to confirm which information remains accessible.
Maintain the asset register as a working document, not as a one-time purchasing record. It does not need to be complex. It should, however, link each item to an asset ID, user, purpose, location, key software, return status and most recent review date.

What should account and access management solve first?
A common assumption is: For a small team, sharing a project mailbox, cloud-storage account or meeting account is more convenient. Individual accounts can be introduced later as headcount grows.
In practice: Shared accounts blur accountability. Client security questionnaires often ask whether individual identities can be traced, who approves access, who holds administrator privileges, and how access is changed promptly when someone moves roles or leaves. A new team can begin with a basic account register and joiner, mover and leaver process. Identify who requests access, who approves it, who provisions it and who reviews it.
The cost of this misunderstanding: If a file is sent to the wrong person, an unusual login occurs, or a former employee continues accessing materials, it becomes difficult to establish where the action came from or explain the response taken.
Arrangements for managing employee onboarding, departures and employment records should reflect your employment model. Refer to the latest requirements published by Sri Lanka's Department of Labour and the advice of appropriately engaged professional advisers.
Can endpoint protection, activity records and backups wait until an audit?
A common assumption is: If the team is small and the project is short, basic protection tools and backup rules can wait until the client schedules a formal audit.
In practice: Endpoint protection, access records and backup recovery are three parts of the same risk chain. Endpoint protection addresses whether devices have basic updates, malware protection and screen-lock arrangements. Access records help you identify and investigate unusual activity. Backups determine whether the project can recover after accidental deletion, device damage or an affected account. If you use cloud storage, project-management platforms or outsourced technical support, also establish who acts as platform administrator, who is responsible for data storage and export, and how the project owner will be notified if a supplier's service is disrupted.
The cost of this misunderstanding: Once an issue occurs, the team may have to reconstruct events from chat messages and individual recollections. Clients will often ask about the scope of impact, actions already taken and measures to prevent recurrence. Those answers need records behind them.
How can you use this five-control checklist?
Use the table below as an internal review tool before responding to your first security questionnaire. The aim is not to make every control sophisticated in one step. Each item should have an owner, a description of the current position and evidence that can be produced if requested.
| Basic control | Questions to confirm | Basic evidence to retain |
|---|---|---|
| Asset and software register | Which devices, software and cloud services process client information? Who uses them? | Asset register, software list, device handover records |
| Accounts and access rights | Are individual accounts used? Who holds administrator rights? How is access removed when someone leaves? | Account register, access request or approval records, leaver handover checklist |
| Endpoint protection | Do devices have updates, screen locks, basic protection and lost-device reporting arrangements? | Configuration notes, device review records, internal user guidance |
| Access and incident records | Can key systems identify logins and significant actions? Who receives and escalates unusual activity? | Log retention arrangement, incident register, escalation contact list |
| Backups and third-party arrangements | Can key information be restored? Are responsibilities of cloud providers or outsourced parties clear? | Backup list, recovery test records, supplier responsibility statement |
When completing a client questionnaire, do not describe a planned control as one that is already operating. Separate existing controls from remediation items in progress, and identify the owner and expected review point for each. If a client requires a specific certification, penetration testing, data-processing terms or cross-border data arrangements, qualified legal, information security or technical professionals should assess the requirement in light of the project.
This content is for general information only and does not constitute legal, tax or immigration advice. Specific requirements should be confirmed against the latest guidance from the relevant Sri Lankan authorities and appropriately engaged licensed professional advisers.
FAQ
- Our overseas client's security questionnaire does not require a certification. Do we still need to prepare documents?
- Yes. Even where no certification is explicitly requested, questionnaires commonly ask about device management, account permissions, backups, incident handling and third-party services. Basic registers and records can prevent a last-minute exercise of asking employees for information one by one.
- Can a small team use a shared project mailbox?
- Whether it is acceptable depends on the client's requirements, the sensitivity of project information and your internal arrangements. A shared mailbox weakens activity traceability and access removal when people leave. At a minimum, define the administrator, permitted use, authorised users and change records, then assess whether individual accounts with a shared inbox would be more suitable.
- How should we answer device-management questions if employees use their own computers?
- Do not simply say that employees are responsible for their own devices. Identify which personal devices access client information, then define where business information may be stored, access restrictions, basic protection, leaver handovers and how lost devices must be reported. If the client has specific technical standards, assess the arrangement against those requirements.
- Where do the main costs of basic information security controls arise?
- Costs commonly arise from device-management or endpoint-protection tools, account and cloud-service licences, backup storage, technical support, training and possible professional assessments. Before requesting quotations, explain your team size, device types, remote-working arrangements, types of client data, existing systems and questionnaire requirements. Ask providers to separate implementation fees, subscription fees, support scope and excluded items.
Related reading
Need this applied to your case?
Tell us your team size, industry and timeline — we will map the actual path for your project.
Contact us