Skip survey header

Business Partner IT Risk Management Survey

Thank you for participating in our brief survey! As a token of our appreciation for your honest responses, you will receive an exclusive report with a comprehensive analysis of the findings. With the results, you will be able to benchmark your third-party risk management program against other leading organizations.
 
Additionally, you’ll be entered to win a $100 Amazon gift card (must provide contact information).
1. What option below best describes your role related to IT Security? (Please assume IT and information security are equivalent for this survey.) *This question is required.
2. PARTNER CONTROL ENVIRONMENT: How often (frequency) does your organization use the following controls for all business partners? Please select the response that is most accurate. *This question is required.
Space Cell NeverRarelyAbout HalfFrequentlyAlways
External entity audit reports (e.g. SOC II, etc.)
Telephone / web audit interviews
On-premises audits / site visits of partner
Encrypted communications with partner
Firewall-isolated network
Unique user accounts
Multifactor authentication (tokens, etc.)
Network monitoring (IDS)
User activity monitoring (UBA)
Custom application protection (WAF, CASB, etc.)
Custom data protection (DLP, DRM, etc.)
User session recording/review
Emulation, virtual machines, containers for separation
3rd party online "scoring" service
3. PARTNER RISK: When assessing the risk of a business partner or prospective partner what effect do the following factors have in your ultimate assessment of risk toward a partner relationship? (NONE = no impact on risk assessment.) *This question is required.
Space Cell Lowest RiskMuch LowerLowerNONEHigherMuch HigherHighest Risk
Very Large Partners (revenue, employees, etc.)
Very Small Partners (revenue, employees, etc.)
Less IT Activity (users, connections, etc.)
More IT Activity (users, connections, etc.)
Higher Contract Value
Lower Contract Value
Highly Sensitive Data
Strong Positive 3rd party audit information (e.g. SOC II, PCI related, etc.)
Strong Positive audit results by my organization
Strong Positive (High) 3rd Party online risk "score" (IT info)
Recent breach(es) at partner
4. DECISIONS: How frequently have the following IT and information risk-related events occurred between your organization and its business partners in the past THREE years? *This question is required.
Space Cell NeverOnceA few times~10 times~50 timesMany times (>100)
My org rejected a proposal primarily because the partner's IT security was inadequate
My org selected a proposal primarily because the partner's IT security was superior
My org paid more to a partner for additional IT security measures
My org negotiated a lower rate because partner security was only adequate
My org withheld payment from partner due to security concerns
5. INCIDENTS: How frequently have the following IT and information risk-related events occurred between your organization and its business partners in the past THREE years? *This question is required.
Space Cell NeverOnceA few times~10 times~50 timesMany times (>100)
My org detected minor security issues (e.g. malware) in the partner IT environment
Our partner detected minor security issues in my org's IT environment
My org detected a significant security breach in the partner IT environment
Our partner detected a significant security breach in my org's IT environment
My org detected a security problem in the partner IT environment that turned out to be incorrect
Our partner detected a security problem in my org's IT environment that turned out to be incorrect
6. Which of the following statements about your organization's IT security posture compared with your business partner's IT security posture do you believe is most accurate? *This question is required.
7. How many full-time equivalent employees (FTEs) and audits does your Business Partner / Vendor Relationship risk management team have/conduct? *This question is required.
8. Please provide the following information about your organization (round to millions - $m - for financial items).
10. Thank you for completing this survey. The following Contact Information is optional, but required if you'd like to be considered for the $100 Amazon gift card drawing and/or the survey results report: