Skip to content
Hot take: Vendor se...
 
Notifications
Clear all

Hot take: Vendor security assessments are a joke. Demand your own pen test results.

3 Posts
3 Users
0 Reactions
1 Views
(@davidk)
Trusted Member
Joined: 1 week ago
Posts: 68
Topic starter   [#5586]

Alright, let's get this started. I've been reviewing a lot of vendor security documentation lately, and I've hit a breaking point.

We all know the drill: you're evaluating a SASE/SSE platform, you ask for their security posture, and you get a glossy PDF summary of a third-party audit (SOC 2, ISO 27001) or a high-level "security white paper." Sometimes, if you push, you might get an executive summary of a penetration test conducted *for* them, by a firm *they* hired and paid.

Here's my hot take: **Those are largely theater.** They're designed to check a compliance box, not to give you genuine insight into the resilience of the platform *you* will be routing all your traffic through. A clean report from a year ago means nothing for the code pushed last week.

We need to shift the dynamic. My proposal:

* **Demand the actual pen test report excerpts** (vulnerability details redacted, if necessary) from the last two cycles. Look for the *methodology*: was it a black-box, periodic test, or a continuous, integrated assessment? The former is a snapshot; the latter is a culture.
* **Require evidence of how findings were remediated.** A "passed" stamp is meaningless without the paper trail of how critical issues were fixed and re-tested.
* **Ask for their bug bounty program scope and historical data.** Are they engaging with the independent security community? A robust program is a stronger trust signal than a staged annual audit.
* **Negotiate for the right to commission your own independent pen test** against your intended instance or tenant as part of the procurement contract. Yes, it's an upfront cost, but it's a cost of due diligence.

The stakes are too high with SASE/SSE. We're consolidating our most critical security controls and network pathways into a single vendor. Their security *is* our security. We can't outsource the trust, we have to verify it empirically.

Anyone else pushed for and gotten these concessions? What was the vendor reaction? Any success stories (or horror tales) from going beyond the standard assessment paperwork?

—David (mod)


Stay factual, stay helpful.


   
Quote
(@dianaf)
Estimable Member
Joined: 1 week ago
Posts: 84
 

Totally agree about the snapshot vs. culture distinction. It's like checking someone's cholesterol once a decade versus them actually eating well.

But practically, how do you even get that level of detail? In my experience, asking for remediation evidence gets you a vague "ticket closed" note from their internal tracker, which proves nothing. Has anyone successfully gotten a vendor to share their actual pentest methodology section? I'd think they'd guard that like crown jewels.



   
ReplyQuote
(@kevinh7)
Trusted Member
Joined: 1 week ago
Posts: 42
 

Yeah, that "ticket closed" note is so frustrating. It feels like a black box.

But has anyone had luck just asking for a sample finding? Not the whole report or methodology, but a single, anonymized example of a vulnerability they fixed? Maybe that's less sensitive for them to share and still gives you a peek.



   
ReplyQuote