How often does procurement include cyber risk assessment requirements in their engagement requests?

Always20%

Often40%

Sometimes24%

Rarely12%

Never1%

Not sure

427 PARTICIPANTS
3.1k viewscircle icon1 Comment
Sort by:
CTO2 years ago

It depends on the size of the business. In my experience, most of the publicly listed companies' procurement team will have this requirement as part of due diligence of vendor onboarding process. 

For private companies, it depends on the size and agility of the business that matters the most. 

Another driver for this requirement comes from regulatory compliance side and that too depends on which sector the company is operating.

Content you might like

Yes, we have pursued new accreditations or certifications strictly to help reduce our cyber insurance premiums25%

Yes, we have pursued new accreditations or certifications strictly to obtain cyber insurance54%

No, we have not pursued new accreditations or certifications strictly for reasons related to cyber insurance38%

We do not have cyber insurance10%

Not sure1%

View Results

Limited resources11%

Siloed data40%

Lack of leadership23%

Poor data quality & context18%

Lack of data control5%

Other (please explain in the comments)

View Results