- Job title
- Customer Relations Manager
- Sector
- Logistics
- Organization type
- 20-person company
- Joined
- Feb 2023
- Message
- 74
I use vendors. Should I check their security?
Should I ask for SOC 2, ISO 27001?
What should I write in the contract?
I use vendors. Should I check their security?
Should I ask for SOC 2, ISO 27001?
What should I write in the contract?
Vendor matrix: criticality vs risk. High = ask for SOC 2. Contract: encryption, audit right.
Let me summarize what's been said so far. The harder it is to reverse a decision, the slower you should make it.
Solutions that work at a small scale collapse when you grow; I learned this late.
I feel the same way. Everything goes well for the first three months; problems arise in the fourth.
Hope this helps.
Doki · Infrastructure migration · 2026
If you're going this route, sort this out first. When making a decision first look at what data you have on hand.
Having backups accessible on the same network and with the same identity makes them part of the target... If I were you, Id go this route.
ill try it. an untested backup is not a backup.
if you have questions write them; I'll answer as best I can.
Correct in theory, but it doesn't work that way in practice. Most time waste accumulates in tasks waiting for approval.
Processes without records never improve, because you don't know what to fix. If you post the result here, it will help others too.
Thanks a lot, I'll try it today. An automated scan report is not the same as a penetration test.
Of course, it varies if your situation is different.
This thread is archived. Hasty decisions become decisions you have to fix six months later.
If 2FA is on, a stolen password alone is useless. If I were you, I'd go this route.
Doki · Vulnerability scanning · 2023
I think differently. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.
Solutions that work at a small scale collapse when you grow; I learned this late.
Doki · Penetration test · 2025
My perspective changed after experiencing that. Everything goes well for the first three months; problems arise in the fourth.
The biggest time-waster for us was not knowing who had the final say. Hope this helps.
we've heard this a lot, but it never happened like that for us and honestly having backups accessible on the same network and with the same identity makes them part of the target.
thats all, sorry if I went on too long.
I felt relieved reading this answer, so it's not just me. An untested backup is not a backup.
Just leaving this note, it might be useful.
I'm in the same situation, that's why I'm asking. Start with a small trial; don't commit to everything at once.
Hope this helps.
Looking at it as a process the picture changes. Mistakes made on the vendor security audit side are usually reversible but expensive.
Hope this helps.
Doki · Interface design · 2024
Let me share my experience. When making decisions, write down the worst-case scenario too, not just the best.
Forgotten test environments are more often the entry point than live systems. This is my opinion, I'm not claiming it's absolute truth.
Three different views emerged, they all complement each other. When you try to change everything at once, nothing settles.
The answer above hits the nail on the head. anyway an untested backup is not a backup.
Most incidents start with a leaked password not a vulnerability.