Do you ask for Cyber Essentials (CE) and/or a CE Plus certification when choosing a supplier for your organization?

Yes, we require both.21%

Yes, but only the Cyber Essentials.50%

We ask for neither.19%

We will consider asking for one/both in the future.8%

192 PARTICIPANTS
1.9k viewscircle icon2 Upvotescircle icon1 Comment
Sort by:
CTO in Software4 years ago

We are using a combination of Questionnaire and Vendor Risk Management platform. We are more oriented towards ISO, SOC, and in the near future CMMC.

Lightbulb on2

Content you might like

Always required – Security must formally review and approve every change request.8%

Required for security-impacting changes – Security reviews only changes flagged as having potential security implications. Please comment : Who decides which changes require security review and which do not ? Is this determination manual or automated? How do you avoid gaps or oversights in this process ?84%

Not required – Security does not review changes submitted CAB/RAB by other teams. 8%

Risk-based or automated – Security involvement is determined by a tiered model or automated risk scoring within ITSM.

View Results

Recruiting and hiring new full-time employees17%

Expanding relationships with IT staffing firms to meet immediate needs37%

Upskilling or reskilling employees for new roles31%

Improving internal processes to manage a remote or hybrid workforce11%

Other (please specify in comments)3%

View Results