Skip to content
Notifications
Clear all

How do I structure an RFP section for red-team testing results?

2 Posts
2 Users
0 Reactions
1 Views
(@alexh42)
Trusted Member
Joined: 7 days ago
Posts: 50
Topic starter   [#16967]

We're about to kick off an RFP for a new cloud-based security platform, and I've been handed the task of drafting the security validation section. My team is adamant that we need to see real red-team or penetration test results from the vendor, not just a checkbox for "we do pentests."

The problem I'm wrestling with is how to structure this in the RFP to get something *actionable* and comparable. I don't want a simple "Yes, we do that" answer, and I also don't want to get buried in a 200-page PDF that's been sanitized into uselessness.

Here's the structure I'm leaning towards. I'd love this community's gut check on whether this asks for enough—or too much.

**For the RFP Question Itself:**
* Require a summary of the two most recent third-party red-team or offensive security engagements conducted against the specific product/service in scope.
* Specify that the summary must include:
* The scope of the engagement (e.g., "the web application API and underlying cloud infrastructure").
* The independent firm that performed the test.
* The dates of the testing period.
* The overall outcome or rating (if one was provided).
* The total number of findings categorized by severity (Critical, High, Medium, Low).
* The number of findings from that test that remain open or unremediated as of the RFP response date.

**For the Evaluation Rubric (Scoring):**
We'll score responses on a 0-5 scale based on:
* **Transparency (0-2 points):** Do they provide all requested data without obfuscation?
* **Recency & Frequency (0-1 point):** Was the most recent test within the last 12 months?
* **Remediation Track Record (0-2 points):** What percentage of Critical/High findings from the *older* test were resolved before the more recent one? This shows if they actually fix issues, not just run tests.

The goal is to move beyond marketing claims and see evidence of a living security practice. Has anyone run a similar section in an RFP? What pitfalls did you hit? Did vendors actually provide the data, or did you get a lot of pushback?

stay pragmatic



   
Quote
(@data_pipeline_guy)
Estimable Member
Joined: 4 months ago
Posts: 107
 

You're asking for summaries. Summaries get you marketing slides. The scope, firm, and dates are just table stakes.

You need to ask for the raw findings distribution. "Give us the counts by CVSS score band from the last test. How many Critical, High, Medium, Low. And what's the average time to remediate for each band." That's comparable data.

If they balk at giving you numbers, you've got your answer about their security posture.


SQL is enough


   
ReplyQuote