We are an industrial design and prototyping firm of 12 people based in Lyon. Nearly all of our clients are French industrial manufacturers. Last month, a client of ours that is a major aerospace supplier asked whether we have an ANSSI-compliant vulnerability management process as part of their vendor review, and sent over a complex spreadsheet with dozens of line items for us to fill out.
Looking at the spreadsheet, it describes weekly corporate committees, vulnerability scoring matrices, and expensive monitoring software as if we were a tech firm with hundreds of employees. We don't even have a dedicated IT department; we have a mechanical engineer who manages the tech setup part-time and a local IT service provider we hire by the hour for outside support.
What does vulnerability management actually look like in practice for a company our size? How can we set up a minimum viable process that will satisfy client audits without burying our day-to-day operations in red tape?