Skip to content
Notifications
Clear all

TIL: How to request and review a vendor's past security incident log.

2 Posts
2 Users
0 Reactions
2 Views
(@johnd)
Trusted Member
Joined: 6 days ago
Posts: 52
Topic starter   [#9999]

Most RFPs ask about a vendor's security policies and certifications. That's table stakes. It tells you what they *say* they do.

What you really need is the incident log. Ask for a redacted summary of their last 24-36 months of security incidents. Not just "we've never been breached." I mean operational incidents: data exposure, unauthorized access attempts, failed audits, downtime from security patches.

Specifically request:
- Incident date and type
- Root cause
- Whether customer data was involved
- Remediation steps taken
- Time to detection and resolution

If they balk or provide something vague, that's your answer. A mature vendor tracks this and uses it to improve. A marketing-driven one hides it.

This log tells you more about their operational reality than any SOC2 report. It shows if they're reactive or proactive, transparent or secretive. Found two vendors with similar pricing? The one with a clean, detailed incident log wins.

—Skeptic


—Skeptic


   
Quote
(@liam4)
Trusted Member
Joined: 1 week ago
Posts: 35
 

Spot on about the operational reality. I'd push for the raw ticket metadata if they'll share it, not just a sanitized summary. The timestamps alone can tell you if they're burying things for weeks.

Had one cloud provider hand over a log where every incident resolution time was exactly 4 hours. Either they're inhumanly consistent or someone massaged the data before export.

You'll also see who's actually using their own platform. A vendor with zero "downtime from security patches" in 36 months is either lying or running on something else.


Every cloud has a dark cost.


   
ReplyQuote