Overview
The Cye Platform Questionnaire for Private Equity is a structured mechanism for collecting organizational information from subsidiaries/portfolio companies, such as internal security policies, manual processes, and operational practices, that cannot be discovered automatically.
Respondents access and complete the questionnaire in the Cye Platform. Once submitted, Cye's Delivery team receives the responses and evidence for review.
By bridging the gap between automated scanning and human-driven assessment, the questionnaire allows platform owners to:
Execute repeatable, consistent security assessments across multiple portfolios.
Convert external responses into standardized platform entities (findings, technologies, and processes).
Maintain an operational audit trail covering questionnaire distribution, submission, and due-date changes at both parent and subsidiary levels.
Note: The Cye Platform Questionnaire is a distinct feature from the Cost of Breach Questionnaire, which collects financial data inside the platform to estimate breach impact. For financial input, refer to [Inputting Cost of Breach Data].
The Questionnaire Sequential Pipeline
The Questionnaire Sequential Pipeline
The questionnaire moves through four distinct stages. Each stage is a prerequisite for the next:
Stage | Who | Primary Action |
Issuance | PE Administrators or the Cye Customer Success Team | Send the questionnaire to the relevant portfolio companies, with a due date. |
Filling Out | Portfolio Companies | Receive the secure link, answer questions collaboratively, attach evidence, and submit. |
Tracking & Oversight | PE Administrators | Track response progress across the portfolio via the Companies Questionnaires dashboard to ensure completion (e.g., "42 of 60 subsidiaries completed"). |
Review | Cye Delivery | Reviews the submitted answers and evidence to complete the assessment. |
Sending a Questionnaire
Sending a Questionnaire
PE administrators can distribute the questionnaire directly from the platform. The Cye Customer Success Team can send it on your behalf as well, with the same capabilities.
Choosing Recipients: Select one or more subsidiary/portfolio companies, then one or more registered users per company. Search and bulk selection are available.
Only registered platform users can be chosen as respondents.Setting the Due Date: A due date is mandatory for every send. Invited respondents can later extend it within a capped limit (one week beyond the original date by default).
One Questionnaire per Company: Sending to several companies at once gives each company its own separate questionnaire, with its own row and due date in the dashboard.
Sending New vs. Existing Questionnaires: Sending a questionnaire to a company that already received one creates a new, blank instance. It does not carry over or overwrite previous answers. To send an email reminder for an existing questionnaire instead, select Resend invitation from its row.
Adding Respondents Later: Use Add respondents on a questionnaire's row to attach more registered users to it. They join the existing questionnaire and its due date, and no new row is created. Available until the questionnaire is submitted.
Tracking & Managing the Questionnaires from the Dashboard
Tracking & Managing the Questionnaires from the Dashboard
Track every questionnaire from the Companies Questionnaires dashboard, one row per questionnaire sent.
Statuses:
Sent: Invitations were dispatched.
Received: A recipient opened the invitation.
In Progress: Answering has started.
Submitted: The questionnaire was submitted. Answers are locked and the results are handed to the Cye Delivery team.
Error: No invitation was delivered because every recipient's email failed.
Expired: The due date passed without a submission. Expired is informational only. The company can still answer, extend the due date, and submit.
Several Respondents, One Status: The row reflects the furthest progress any respondent has made. Email delivery is tracked per recipient: an address whose invitation failed is highlighted in the Sent To column and can be resent individually.
Row actions: Each row has a menu with the actions that fit its current status.
Resend invitation (Sent, Error): Sends the invitation again.
Remind (In Progress, Expired): Sends a reminder email to respondents who already have access.
Add respondents (until submission): Attaches more registered users to the existing questionnaire. They share its due date, and no new row is created.
View answers (Submitted): Opens the completed questionnaire read-only, with answers and evidence. Answers are never visible while the company is still filling.
Archive (Submitted): Moves the row to the Archived tab. Archiving is reversible.
Delete (Sent, Error, Submitted): Permanently removes the questionnaire after a confirmation dialog. Delete is not offered while a company is answering. Deleting a submitted questionnaire does not affect results already handed to the Cye Delivery team.
Search the Dashboard:
The dashboard also filters by status or questionnaire, searches by company, questionnaire, or recipient email, and sorts by any column.
Notifications:
PE administrators receive in-app notifications when a questionnaire is submitted, when a due date is extended (previous date, new date, and the reason), and when a questionnaire expires.
Each row has a menu with the actions that fit its current status:
How It Works: From Answers to Risk Metrics
How It Works: From Answers to Risk Metrics
The core value of the questionnaire lies in how it transforms structured and free-text answers into standardized platform data after submission:
1. Entity Generation (New and Existing)
When a questionnaire is submitted, the Cye Delivery Team compares the answers against the current organizational inventory. This results in three types of Changes:
Creation: If an answer describes a Finding, Process, or Technology that does not exist in the platform, a new entity is created.
Update: If an answer corresponds to an existing entity, the team updates its fields or changes its status.
Skip: If an answer matches an entity that already exists in the same state, no change is made.
2. Impact on Risk Metrics
Questionnaire-sourced entities participate in platform calculations immediately upon creation:
Exposure: Findings flow into Exposure calculations and the Org Attack Graph.
Maturity: Processes and Technologies populate the security inventory and influence Maturity scoring.
Likelihood: Impacted indirectly via Exposure—new findings and control gaps update attack paths and control posture, which adjust likelihood estimates.
Cost of Breach: Entity creation does not change cost assumptions directly; cost is driven by the Cost of Breach model. However, overall risk (Expected Loss) changes when likelihood shifts due to Exposure/Maturity updates.
How Questionnaire Data Behaves
How Questionnaire Data Behaves
Following the review of submitted answers and evidence, Cye's delivery team generates corresponding Findings and Assets, and establishes the initial Maturity score for the organization.
Findings and Assets: Cye Services initiates a new engagement dedicated to the questionnaire to house all generated Findings and Assets. Findings populate the Findings page, while Processes and Technologies populate the Assets page. These records retain permanent Cye Platform attribution and cannot be deleted by company administrators.
Maturity Score: Cye's delivery team establishes the baseline Maturity score for the organization derived directly from the questionnaire responses.
Audit Log
Audit Log
The Cye Platform records questionnaire activity in each company's audit log. An event is written to the log of the company where the action happened, and every entry captures the company name, the questionnaire name, the acting user, and the time.
Parent-level log: program operations, including sending, resending invitations, adding respondents, archiving, deleting, and export generation.
Subsidiary/Portfolio company level log: activity on that company's own questionnaire, including answer changes (with the previous and new value), evidence added or removed, question owners and collaborators assigned or removed, due-date extensions (previous date, new date, and justification), and submission.
Shown in both logs: submission and due-date extension are also written to the parent's log, since they change what the parent sees on the dashboard.
Who can read it: the company's admin, in companies with the platform audit log. Respondents and collaborators cannot read the audit trail.
Wrap-Up/Next Steps
Wrap-Up/Next Steps
The Cye Platform Questionnaire for Private Equity turns critical information that automated scanning cannot reach into trusted, standardized platform data.
Expert Review: Submitted answers and evidence are reviewed by Cye Services and incorporated into your Findings, Processes, and Technologies.
Clear Traceability: Every generated item includes its specific source field, system tag, and a comment linking it directly back to the originating question and answer.
These questionnaire-sourced entities act as first-class inputs, feeding directly into the organization's core risk model.
Next Steps - Completing the Cye Platform Questionnaire for Private Equity: A step-by-step respondent guide for portfolio companies.
