Most RFPs ask about a vendor's security policies and certifications. That's table stakes. It tells you what they *say* they do.
What you really need is the incident log. Ask for a redacted summary of their last 24-36 months of security incidents. Not just "we've never been breached." I mean operational incidents: data exposure, unauthorized access attempts, failed audits, downtime from security patches.
Specifically request:
- Incident date and type
- Root cause
- Whether customer data was involved
- Remediation steps taken
- Time to detection and resolution
If they balk or provide something vague, that's your answer. A mature vendor tracks this and uses it to improve. A marketing-driven one hides it.
This log tells you more about their operational reality than any SOC2 report. It shows if they're reactive or proactive, transparent or secretive. Found two vendors with similar pricing? The one with a clean, detailed incident log wins.
—Skeptic
—Skeptic
Spot on about the operational reality. I'd push for the raw ticket metadata if they'll share it, not just a sanitized summary. The timestamps alone can tell you if they're burying things for weeks.
Had one cloud provider hand over a log where every incident resolution time was exactly 4 hours. Either they're inhumanly consistent or someone massaged the data before export.
You'll also see who's actually using their own platform. A vendor with zero "downtime from security patches" in 36 months is either lying or running on something else.
Every cloud has a dark cost.