• Skip to main content
  • Skip to primary sidebar
  • Skip to footer
QuestionPro

QuestionPro

questionpro logo
  • Products
    survey software iconSurvey softwareEasy to use and accessible for everyone. Design, send and analyze online surveys.research edition iconResearch SuiteA suite of enterprise-grade research tools for market research professionals.CX iconCustomer ExperienceExperiences change the world. Deliver the best with our CX management software.WF iconEmployee ExperienceCreate the best employee experience and act on real-time data from end to end.
  • Solutions
    IndustriesGamingAutomotiveSports and eventsEducationGovernment
    Travel & HospitalityFinancial ServicesHealthcareCannabisTechnology
    Use CaseAskWhyCommunitiesAudienceContactless surveysMobile
    LivePollsMember ExperienceGDPRPositive People Science360 Feedback Surveys
  • Resources
    BlogeBooksSurvey TemplatesCase StudiesTrainingHelp center
  • Features
  • Pricing
Language
  • English
  • Español (Spanish)
  • Português (Portuguese (Brazil))
  • Nederlands (Dutch)
  • العربية (Arabic)
  • Français (French)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • Türkçe (Turkish)
  • Svenska (Swedish)
  • Hebrew IL (Hebrew)
  • ไทย (Thai)
  • Deutsch (German)
  • Portuguese de Portugal (Portuguese (Portugal))
Call Us
+1 800 531 0228 +1 (647) 956-1242 +52 999 402 4079 +49 301 663 5782 +44 20 3650 3166 +81-3-6869-1954 +61 2 8074 5080 +971 529 852 540
Log In Log In
SIGN UP FREE

Home Surveys Assessments

6 Common Misconceptions Regarding Vendors’ Data Security Risk

Difference between Questionnaires and surveys

Do Any of These Beliefs about Data Security Risk Sound Familiar?

#1 If a vendor has been certified as PCI or HIPAA compliant, procurement can skip the security review.

Not a good idea.

  •      Regulatory compliance is just one data point. A vendor can be PCI compliant on a very specific portion of its technology yet have weak controls in other areas  
  •      Most products and applications that are PCI or HIPAA compliant fall into noncompliance quickly because they are often implemented with weak controls or over time, due to environmental changes, the original compliant configurations weaken enough to make them non-compliant.
  •      Vendors may be PCI or HIPAA compliant but their subcontractors and suppliers may ultimately put them out of compliance, putting your organization at risk
  •      Companies must be reviewed for data security risk annually to remain compliant
  •      Be wary of vendors who make a product seem too good to be true. There is no magic bullet that will make your network completely PCI or HIPAA compliant. Most vendors overstate their claims and promise much more than they can deliver. In the event of a security breach, consumers won’t care whether the fault lies with your business or with your vendor partner.

#2 Because we are a privately held company, we don’t need to demonstrate the same level of data security risk due diligence as a public company; we are also not required to disclose any data breaches.

Not true.

  •      Wow.  Are there still people in positions of power that believe this?
  •      Both public and private companies must disclose whether there has been a data breach involving PII and regulated data – that’s the bottom line. There is no get-out-jail card for private companies.
  •      California and other states have strictly regulated data breach notification policies based upon the size of the breach not whether or not a company is publicly or privately held.

#3 If we were to have a data breach our customers would continue to do business with us if it wasn’t our fault.

Research has shown that it doesn’t matter how a breach occurs – a serious breach picked up by the media can have a negative impact on revenue and company valuation.

  •      Ask Target
  •      Then ask Home Depot
  •      When consumer satisfaction, trust, and confidence drops due to a data breach it has a huge impact on the bottom line.   Make no mistake, if your customer loses trust and confidence in your ability to protect their data, they will go elsewhere and – even worse – they will black list you via social media where their rants can spread like wild fire.

#4 If a data breach occurred, our executive team is not liable and won’t be held responsible

Depends on the publicity and consumer impact of the data breach.

  •      Whoops! Take a look at the Target breach in Jan 2014.
  •      Executives including the CISO were fired.
  •      When the impact of a data breach affects shareholder value, consumer confidence and loyalty, and ultimately bottom-line revenue, it’s time to dust off the resume.  One of the few teams that usually emerges unscathed after a major breach is the Procurement Team – even in the case of a data breach attributed to a third party service provider that Procurement opted out of a risk assessment.  
  •      How much longer do you think that the Procurement Team will escape accountability?

#5 All open connections into my environment are well known and are properly managed and monitored.

Be careful – if you believe you are completely secured, you may miss something.

  •      External connectivity needs are changing all the time to support vendor engagements. Temporary connections are often left in place and become permanent and over time it’s these temporary connections that are forgotten or don’t properly protect data and can become a big data security risk.
  •      Precisely what happened at Target and Goodwill.

#6 My vendors signed contracts that assert that their security and privacy controls are strong and effective – so why do I need to do anything more to verify this?

Common misconception.

  •      Procurement should use an objective process to determine which vendors require a data security assessment.
  •      The fact that a vendor asserts these claims won’t protect you in the court of public opinion should a major data breach occur.
  •      Relying on Vendor attestations is never a good idea – even cherry picking, using the old-school Russian roulette process of assessing vendors is more reliable.
  •      Procurement should implement a “trust but verify” model for long-term successful and safe vendor engagements.
SHARE THIS ARTICLE:

About the author
Paresh Amin

View all posts by Paresh Amin

Primary Sidebar

Gain insights with 80+ features for free

Create, Send and Analyze Your Online Survey in under 5 mins!

Create a Free Account

RELATED ARTICLES

HubSpot - QuestionPro Integration

Behavior Science: The Delight of CX Management — Tuesday CX Thoughts

May 30,2023

HubSpot - QuestionPro Integration

Top 8 Online Qualitative Research Tools for Success

Jan 10,2024

HubSpot - QuestionPro Integration

They Failed to Show the CX LUV —Tuesday CX Thoughts

Feb 14,2023

BROWSE BY CATEGORY

  • Academic
  • Academic Research
  • Artificial Intelligence
  • Assessments
  • Audience
  • Brand Awareness
  • Business
  • Case Studies
  • Communities
  • Consumer Insights
  • Customer effort score
  • Customer Engagement
  • Customer Experience
  • Customer Loyalty
  • Customer Research
  • Customer Satisfaction
  • CX
  • Employee Benefits
  • Employee Engagement
  • Employee Engagement
  • Employee Retention
  • Enterprise
  • Events
  • Forms
  • Friday Five
  • General Data Protection Regulation
  • Guest Post
  • Insights Hub
  • Life@QuestionPro
  • LivePolls
  • Market Research
  • Marketing
  • Mobile
  • Mobile App
  • Mobile diaries
  • Mobile Surveys
  • New Features
  • non-profit
  • NPS
  • Online Communities
  • Polls
  • Question Types
  • Questionnaire
  • QuestionPro
  • QuestionPro Products
  • Release Notes
  • Research Tools and Apps
  • Revenue at Risk
  • Startups
  • Survey Templates
  • Surveys
  • Tech News
  • Tips
  • Training
  • Training Tips
  • Trending
  • Tuesday CX Thoughts (TCXT)
  • Uncategorized
  • VOC
  • Webinar
  • Webinars
  • What’s Coming Up
  • Workforce
  • Workforce Intelligence

Footer

MORE LIKE THIS

synthetic data and ai - market research

Redefining Research Strategy with AI and Synthetic Data

May 15, 2025

Kohl's-NPS-2025

Kohl’s NPS & Satisfaction in 2025

May 15, 2025

digital-customer-engagement

What is Digital Customer Engagement? Strategies Need to Know

May 14, 2025

Target-NPS-2025

Target NPS & Brand Sentiment in 2025

May 13, 2025

Other categories

  • Academic
  • Academic Research
  • Artificial Intelligence
  • Assessments
  • Audience
  • Brand Awareness
  • Business
  • Case Studies
  • Communities
  • Consumer Insights
  • Customer effort score
  • Customer Engagement
  • Customer Experience
  • Customer Loyalty
  • Customer Research
  • Customer Satisfaction
  • CX
  • Employee Benefits
  • Employee Engagement
  • Employee Engagement
  • Employee Retention
  • Enterprise
  • Events
  • Forms
  • Friday Five
  • General Data Protection Regulation
  • Guest Post
  • Insights Hub
  • Life@QuestionPro
  • LivePolls
  • Market Research
  • Marketing
  • Mobile
  • Mobile App
  • Mobile diaries
  • Mobile Surveys
  • New Features
  • non-profit
  • NPS
  • Online Communities
  • Polls
  • Question Types
  • Questionnaire
  • QuestionPro
  • QuestionPro Products
  • Release Notes
  • Research Tools and Apps
  • Revenue at Risk
  • Startups
  • Survey Templates
  • Surveys
  • Tech News
  • Tips
  • Training
  • Training Tips
  • Trending
  • Tuesday CX Thoughts (TCXT)
  • Uncategorized
  • VOC
  • Webinar
  • Webinars
  • What’s Coming Up
  • Workforce
  • Workforce Intelligence

questionpro-logo-nw
Help center Live Chat SIGN UP FREE
  • Sample questions
  • Sample reports
  • Survey logic
  • Branding
  • Integrations
  • Professional services
  • Security
  • Survey Software
  • Customer Experience
  • Workforce
  • Communities
  • Audience
  • Polls Explore the QuestionPro Poll Software - The World's leading Online Poll Maker & Creator. Create online polls, distribute them using email and multiple other options and start analyzing poll results.
  • Research Edition
  • LivePolls
  • InsightsHub
  • Blog
  • Articles
  • eBooks
  • Survey Templates
  • Case Studies
  • Training
  • Webinars
  • All Plans
  • Nonprofit
  • Academic
  • Qualtrics Alternative Explore the list of features that QuestionPro has compared to Qualtrics and learn how you can get more, for less.
  • SurveyMonkey Alternative
  • VisionCritical Alternative
  • Medallia Alternative
  • Likert Scale Complete Likert Scale Questions, Examples and Surveys for 5, 7 and 9 point scales. Learn everything about Likert Scale with corresponding example for each question and survey demonstrations.
  • Conjoint Analysis
  • Net Promoter Score (NPS) Learn everything about Net Promoter Score (NPS) and the Net Promoter Question. Get a clear view on the universal Net Promoter Score Formula, how to undertake Net Promoter Score Calculation followed by a simple Net Promoter Score Example.
  • Offline Surveys
  • Customer Satisfaction Surveys
  • Employee Survey Software Employee survey software & tool to create, send and analyze employee surveys. Get real-time analysis for employee satisfaction, engagement, work culture and map your employee experience from onboarding to exit!
  • Market Research Survey Software Real-time, automated and advanced market research survey software & tool to create surveys, collect data and analyze results for actionable market insights.
  • GDPR & EU Compliance
  • Employee Experience
  • Customer Journey
  • Synthetic Data
  • About us
  • Executive Team
  • In the news
  • Testimonials
  • Advisory Board
  • Careers
  • Brand
  • Media Kit
  • Contact Us

QuestionPro in your language

  • English
  • Español (Spanish)
  • Português (Portuguese (Brazil))
  • Nederlands (Dutch)
  • العربية (Arabic)
  • Français (French)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • Türkçe (Turkish)
  • Svenska (Swedish)
  • Hebrew IL (Hebrew)
  • ไทย (Thai)
  • Deutsch (German)
  • Portuguese de Portugal (Portuguese (Portugal))

Awards & certificates

  • survey-leader-asia-leader-2023
  • survey-leader-asiapacific-leader-2023
  • survey-leader-enterprise-leader-2023
  • survey-leader-europe-leader-2023
  • survey-leader-latinamerica-leader-2023
  • survey-leader-leader-2023
  • survey-leader-middleeast-leader-2023
  • survey-leader-mid-market-leader-2023
  • survey-leader-small-business-leader-2023
  • survey-leader-unitedkingdom-leader-2023
  • survey-momentumleader-leader-2023
  • bbb-acredited
The Experience Journal

Find innovative ideas about Experience Management from the experts

  • © 2022 QuestionPro Survey Software | +1 (800) 531 0228
  • Sitemap
  • Privacy Statement
  • Terms of Use