1-888-PIVOT-POINT | 1-888-748-6876 info@pivotpointsecurity.com
Talk with an Expert »
Select Page
Access Here >> The Recipe & Ingredients for ISO 27001 Certification
Reading Time: 2 minutes

TPRM why question marks

In our practice we’re seeing a big uptick in client stress levels with respect to security questionnaires, especially among software-as-a-service (SaaS) providers. Three trends are driving this:

  1. A growing percentage of prospects are mandating security questionnaires
  2. The length and complexity of the questionnaires is increasing, so they take longer to complete
  3. Almost 100% of organizations now use cloud services, which (hopefully) means business growth for SaaS providers, with more questionnaires being a side effect

According to a 2018 survey by Gemalto, 61% of organizations say they evaluate the security capabilities of SaaS providers before deploying their services. More than half of these (34% of those surveyed) require the completion of a security questionnaire—and that number is undoubtedly rising as regulatory mandates and headlines about third-party security breaches intensify vendor scrutiny.

Questionnaires are also getting longer in an effort to make them more comprehensive. In particular, Shared Assessments’ popular SIG Questionnaire was greatly expanded for 2019 (to something like 900 questions), and many organizations prefer to use this and similar tools as-is.

“Security questionnaires are a cost of doing business in today’s information economy…”

When individuals in key positions, such as CISOs or Information Security Managers, have the responsibility to reply to more and bigger questionnaires, the time demands eventually exceed what they can manage. The process can’t scale and becomes a hindrance to closing sales and growing the business.

If you find yourself in this position, you can find help here (no need to bore you with a sales pitch).

Security questionnaires are a cost of doing business in today’s information economy but if handled well, they can be leveraged to separate you from the pack.

TPRM for SMBs guideThrough our 17 years of experience, we've collected these 5 fast-track best practices for implementing a vendor risk management program as a small- to medium-size busiess (SMB).

Download our free TPRM PDF guide now!

close

Enjoy this blog? Subscribe to get new posts immediately!

Get new posts by email:
You can easily unsubscribe at any time - See our Privacy Policy here.
LINKEDIN