{"id":32962,"date":"2019-08-16T09:09:29","date_gmt":"2019-08-16T08:09:29","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=32962"},"modified":"2019-09-03T11:08:11","modified_gmt":"2019-09-03T10:08:11","slug":"how-can-vendors-and-end-users-get-the-best-out-of-their-partnerships","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/08\/16\/how-can-vendors-and-end-users-get-the-best-out-of-their-partnerships\/","title":{"rendered":"How can vendors and end-users get the best out of their partnerships?"},"content":{"rendered":"\n<p>One of the challenges that modern CISOs face is knowing where to channel investment. And given that there are many vendors, often offering similar services, choosing a provider or product can be difficult.<\/p>\n\n\n\n<p>A good vendor-end-user relationship based on trust and long-term partnerships is crucial.<\/p>\n\n\n\n<p>We asked three industry experts how vendors and end-users can get the best out of their partnerships. Here&#8217;s what they had to say&#8230;<\/p>\n\n\n\n<p><strong>Ghazal Asif, Senior Director of Worldwide Channels at Cybereason<\/strong><\/p>\n\n\n\n<p><strong>Build the human connection<\/strong><\/p>\n\n\n\n<p>In an age of rapidly evolving technology, we often forget the importance of the human connection. At the heart of every great relationship is a feeling of mutual trust. Building trust requires time and patience. The former is something we don\u2019t have, especially when there are so many vendors knocking on end-user doors. Once an end-user has identified a shortlist of vendors they will partner with (in a project, or generally), make the time to build the trust and relationship outside of the office. Coffee, dinner, a round of golf \u2013 there are unlimited ways to build the human connection.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Make peer to peer connections<\/strong><\/li><\/ul>\n\n\n\n<p>Most strategic partnerships span across multiple business units and\ndisciplines between end-users and vendors. For example, a CISO to CISO connection is\nexcellent, and necessary, but going up and across the organisation and making\nthose peer-to-peer connections gives both parties a fuller picture on the\norganisation. For example, end-user procurement staff connecting with vendor\nprocurement staff can lead to a better understanding of the paper process and\npotentially good practice sharing. <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Creating value<\/strong><\/li><\/ul>\n\n\n\n<p>The\nstrongest end-user and vendor relationships are based on creating value. This\nis especially important for vendors. The only way to create value for an\nend-user is to truly understand and empathise with the pain in their role,\nfully understand the priorities and then find ways to create value. Creating\nvalue can be done through sharing best practices, sharing key research that\naligns to their pain and desired outcome, leading workshops with the end-user\nteams for knowledge sharing and finding ways to share relevant expertise from\nthe work completed by the end-user. <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Build a joint success plan<\/strong><\/li><\/ul>\n\n\n\n<p>Agreeing\nto a joint success plan which is fully documented is a fantastic way to ensure\nthe end-user gets the most out of the investment. A\njoint success plan should include quantifiable metrics on what success looks like,\nespecially post-sales. This is also a great way for the end-user to hold\nthe vendor accountable.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Define and align on outcomes <\/strong><\/li><\/ul>\n\n\n\n<p>Priorities change regularly for companies and pains experienced by one end-user will quite likely be dramatically different with others within the same company. This makes it imperative to set expectations on timelines and communication in order define what a great outcome will be for the end-user. <\/p>\n\n\n\n<p>In addition, the more transparent end-users can be with vendors\nregarding goals, objectives and outcomes, the more likely of achieving success. It could be something\nas simple as scheduling follow up phone calls. If the end user isn\u2019t interested\nin receiving calls on a certain day or time because of other commitments, its\u2019s\nimportant for the vendor to know this. <\/p>\n\n\n\n<p>Maybe the end-user doesn\u2019t want a follow-up call on a Monday because their calendar is already filled with existing appointments. Therefore, scheduling the call on a Tuesday could go a long way in building trust. It seems simple but working extremely hard to not lose control of the basics is important. <\/p>\n\n\n\n<p><strong>Richard Archdeacon, Advisory CISO at Duo Security<\/strong><\/p>\n\n\n\n<p>As businesses demand greater agility and\nflexibility for their in-house and external teams, vendors must reflect that\nchange. This is particularly important in the area of security which, although\nvital to the success of an organisation, is not often seen as necessary. <\/p>\n\n\n\n<p>An author wants to write, a designer to design. They do not come in to work to be a security professional. So success will depend on the vendor ensuring that the end-user works in partnership to secure the organisation.<\/p>\n\n\n\n<p>Vendors must ensure solutions are easy to use\nand do not impede the user and their work experience. A\nkey way in which vendors can work with end users is to focus on the design of\ntheir solutions and ensure that they are effective but easy to use. <\/p>\n\n\n\n<p>An example of this would be ensuring a common\nexperience across all the platforms open to end users in their daily activities\n\u2013 a solution should be similar across laptops, mobile phones and intelligent\nwatches. <\/p>\n\n\n\n<p>The vendor needs to ensure that the functional\nrequirements are implemented without interrupting the user workflow. <\/p>\n\n\n\n<p>If it interrupts what a person needs to do it\nwill create a negative experience and, understandably, users will develop\nworkarounds, therefore undermining the purpose of any control.&nbsp; <\/p>\n\n\n\n<p>By making authentication simple\nwhilst running checks on devices in the background, end users can stay secure\nwithout degrading performance or interrupting work. If an update is\nneeded to a device then rather making it intrusive the vendor can develop an\napproach which includes the end user in the decision and implementation\nprocess.&nbsp;<\/p>\n\n\n\n<p>To develop these solutions, vendors need to\nhave a programme which includes end users in the development of new\nsolutions.&nbsp; <\/p>\n\n\n\n<p>Making it easy to use is the first step but ensuring that end users test it and provide their input is a critical second step before release. So keeping it simple and consistent while supporting \u2013 not interrupting \u2013 the end user is the way to get the best out of the partnership.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Paul Farrington, EMEA CTO at Veracode<\/strong><\/h4>\n\n\n\n<p>As a society, our digital lives are dependent\non code, whether it\u2019s managing our banking, controlling our vehicles and\ncritical infrastructure or operating our medical devices. Meanwhile, every\nbusiness now relies on software as a source of strategic differentiation,\ncompetitive advantage and top-line revenue generation. Cyberattackers have taken\nnote of this increasing attack surface, compromising systems at an alarming\nrate, and breaches are hurting companies.<\/p>\n\n\n\n<p>According to Verizon\u2019s <a href=\"https:\/\/enterprise.verizon.com\/resources\/reports\/dbir\/\"><em>2019 Data Breach Investigations\nReport<\/em><\/a>, 62% of breaches and 39% of\nincidents occur at the web application layer. While it is unclear exactly how\nthe web applications were compromised in some cases, we can assume that\nattackers are scanning for specific web app vulnerabilities, exploiting them to\ngain access, inserting some kind of malware and harvesting payment card data to\ncreate a profit.<\/p>\n\n\n\n<p>Meanwhile, analysis from Veracode\u2019s most recent\n<a href=\"https:\/\/www.veracode.com\/state-of-software-security-report\"><em>State of Software Security report<\/em><\/a><em>\n<\/em>shows that the number of vulnerable apps\nremains staggeringly high and open source components continue to present\nsignificant risks to businesses. More than 85% of all applications contain at\nleast one vulnerability following the first scan and more than 13% of\napplications contain at least one very high severity flaw. In addition,\norganisations\u2019 latest scan results indicate that one in three applications were\nvulnerable to attack through high or very high severity flaws.<\/p>\n\n\n\n<p>Vendors must closely manage the security\nof their software, whether that\u2019s software they buy, use or sell, in order to\nhelp prevent breaches and to retain trust of their customers.\nIt is easy to forget that third party applications can be just as vulnerable as\nthe applications companies build for themselves. <\/p>\n\n\n\n<p>Leading organisations such as OWASP, the PCI\nCouncil, FS-ISAC and NIST are raising awareness about the need to better\nunderstand and reduce the security risks associated with the use of third-party\nsoftware.<\/p>\n\n\n\n<p>Why is this critical for maintaining strong\nvendor and end-user partnerships? Because when you install applications or\nsoftware components from a third party, you also take ownership of all the\nvulnerabilities in their software.<\/p>\n\n\n\n<p>Since we now rely on software for everything \u2013 health,\nsafety and well-being \u2013 a policy of \u2018just trust me\u2019 to handle the security of\nour software puts us all at risk. It is no longer\nacceptable to fail to demonstrate that you actually are producing secure\nsoftware. There\u2019s too much at stake and customers are aware of the risks\ncreated by their software supply chain. They want assurances and independent\nvalidation that the software they procure from their software providers is\ncompliant with their corporate security policies.<\/p>\n\n\n\n<p>After all, many other industries such as\ntransportation, food and pharmaceuticals require independent audits and\nassessments related to product safety. This is a common practice of checks and\nbalances aimed at addressing product issues that would otherwise harm\nconsumers. Why should software be any different?<\/p>\n\n\n\n<p>To enhance the compliance of third-party\nsuppliers with your corporate security policies, Veracode:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Acts as an independent party\nfor enterprises procuring third-party software and for software vendors selling\nto enterprises<\/li><li>Analyses third-party\napplications and attest to their security posture while protecting the vendor\u2019s\nintellectual property through the use of binary static analysis<\/li><li>Provides software vendors with\ndetailed and prioritised remediation guidance<\/li><li>Keeps enterprise customers up\nto date with detailed program status reporting from vendors within the program<\/li><li>Brokers and manages the\nprogram and creates attainable compliance goals<\/li><\/ul>\n\n\n\n<p>Software purchasers must demand security\nattestation for the software they are purchasing. Software companies are not\ngoing to simply offer this information if no one is asking. Companies that are\npurchasing software from a vendor should ensure they\u2019re asking about secure\ndevelopment as a way to manage vendor IT risk. <\/p>\n\n\n\n<p>Businesses that take steps to prove to end\nusers, new prospects and partners and integrators that they follow secure\nsoftware development practices gain a competitive advantage in the marketplace.\nBy proving they take security seriously and demonstrating that value both\ninside the company and to external stakeholders, these businesses will\noutperform competitors that fail to keep pace with market demand for secure\nsoftware.<\/p>\n\n\n\n<p> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the challenges that modern CISOs face is knowing where to channel investment. And given that there are many vendors, often offering similar services, choosing a provider or product can be difficult. A good vendor-end-user relationship based on trust and long-term partnerships is crucial. We asked three industry experts how vendors and end-users can [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":33093,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1233,57,7359,1489,93,24],"tags":[13170,13171,54,13172],"class_list":["post-32962","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blogs","category-enterprise-security","category-industry-expert","category-insights","category-top-stories","category-used","tag-ghazal-asif","tag-richard-archdeacon","tag-security","tag-senior-director-of-worldwide-channels-at-cybereason"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/32962","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=32962"}],"version-history":[{"count":15,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/32962\/revisions"}],"predecessor-version":[{"id":33369,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/32962\/revisions\/33369"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/33093"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=32962"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=32962"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=32962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}