Ruben Arredondo Mon, Jul 22, 2024, 9:32 PM
I may have someone. What types of questions are they asking?
Cecilia Ziniti Mon, Jul 22, 2024, 9:36 PM
Standard security questions you’d ask for SaaS but they are all phrased a little different and require knowledge of our systems, so it’s hard to automate. Would love your reco!
Ruben Arredondo Mon, Jul 22, 2024, 9:47 PM
My friend/ colleague Patrick Miller may be able to help. mailto:pmiller@ampyxcyber.com. We've done critical infrastructure cyber security work before. As a lawyer I like working with him because he understands how lawyers think and talk and he can help translate between engineer and lawyer talk. Hopefully he can help you. He knows you may be reaching out to him
Jeff Brom Tue, Jul 23, 2024, 12:07 AM
Auditive is an excellent SaaS solution to help field and fill questionnaires with gen AI. Full disclosure, they’re a client. Happy to make an intro if helpful. http://Auditive.io
Cecilia Ziniti Tue, Jul 23, 2024, 12:20 AM
Super helpful. Thank you so much. I will check out auditive and reach out to your friend Ruben if that doesn’t work. 🙏
Jason Soni Tue, Jul 23, 2024, 2:20 AM
@cecilia Another AI, human in the loop, provider similar to Auditive: https://www.securitypalhq.com/
Jeff Gordon Tue, Jul 23, 2024, 2:25 AM
There are also a few third party providers who serve as aggregators (answer one generic, very detailed questionnaire, and then provide access to it via the service provider).
Cecilia Ziniti Wed, Jul 24, 2024, 7:26 AM
@jeff do you have a favorite?
Jeff Gordon Wed, Jul 24, 2024, 4:44 PM
I don’t. And I realized it’s been a number of years since I looked at the field. My “favorite” has already imploded - their GTM model was to try to make the vendors pay for it. :)
Laurel Palluzi Fri, Jul 26, 2024, 1:04 AM
@jeff - I feel like a lot of them thought charging the vendors was a good model. We kept getting requests at my last company and always declined. I'm not willing to pay until all the vendors talk to each other so I only have to fill out my info one time (and update no more than once a year). Otherwise, it's more noise to have to update in 20 systems (and pay to do so!).
❤️
1
Jeff Gordon Fri, Jul 26, 2024, 1:13 AM
What these aggregator vendors should’ve done instead was align with a vendor management company. Then create a great risk assessment and convince a TON of SaaS providers to fill it out.
Then they could’ve sold it to buyers.
Laurel Palluzi Fri, Jul 26, 2024, 1:31 AM
I feel like a few of the privacy vendors ended up doing that. DataGrail comes to mind? Maybe Osano?