- Job title
- Data entry clerk
- Sector
- Sports and fitness
- Organization type
- early-stage startup
- Joined
- Feb 2023
- Message
- 10
We're a 12-person enterprise software integration team in Riyadh. We are on the verge of signing a 450,000 SAR annual maintenance and development contract with a major semi-governmental logistics company. Everything was progressing smoothly until procurement sent over an extensive cybersecurity audit questionnaire.
As a contract prerequisite, they require us to complete a "basic cybersecurity controls" checklist and provide evidence for each item. The questionnaire contains dozens of requirements: multi-factor authentication, network segmentation, data encryption, offline backup policies, access logs, regular employee awareness training, and more.
Our budget and time are limited; we have only 3 weeks left to sign. As a small team, implementing all of these from scratch is virtually impossible. Which of these controls are strict red lines for enterprise buyers, and which can we defer with a reasonable commitment roadmap?