Skip to content
Notifications
Clear all

Unpopular opinion: Their security questionnaire responses are vague by design.

1 Posts
1 Users
0 Reactions
1 Views
(@gregm)
Estimable Member
Joined: 1 week ago
Posts: 83
Topic starter   [#18172]

Anyone else notice that security questionnaires from vendors are increasingly just an exercise in creative writing? You ask for specifics on encryption key management, and they give you a paragraph that could mean anything from "we use AES" to "we hope for the best." Ask about breach notification timelines, and you get "in accordance with industry standards." What standards? Their own?

This isn't incompetence. It's strategic. Vague answers create plausible deniability and limit contractual liability. If they promise "industry-standard encryption at rest," they haven't pinned themselves to a specific algorithm or key length. When an auditor asks you why you accepted that, you're left holding the bag. They get the checkbox ticked, and you get a false sense of security.

I've reviewed hundreds of these for compliance frameworks like SOC 2 and GDPR. The pattern is always the same. The more critical the control, the more likely the answer is a masterpiece of ambiguity. Data portability? "Available upon request." Request to whom? Under what conditions? At what cost? Zero-trust architecture? "Our platform is designed with security in mind." Wonderful. So is a bicycle lock.

We treat these questionnaires as a compliance hurdle, not a real due diligence tool. Until we start demanding answers with the same specificity we'd demand in a technical spec or a data processing agreement, nothing changes. They'll keep serving us word salad, and we'll keep signing because the sales rep promised it's all fine.

—Greg


Trust but verify


   
Quote