Skip to content

For

Vendor side

You sell security software, or you run the function inside a software company that has to answer for it. Almost everything written about security buying is written for the buyer, which leaves the other half of the transaction reading between the lines of advice aimed at someone else.

Deepak founded LoginRadius in 2013 and scaled it to over a billion user identities, which meant several hundred enterprise security evaluations answered from the seller's chair. The pieces below are the parts of that experience that generalize: what the committee is actually doing while you wait, why the objection that kills a deal never reaches you, and what a questionnaire programme really costs.

Read in this order

3 pieces, sequenced. Each line says why that one sits in that position, so you can stop when the sequence stops applying to you.

  1. The Engineer Who Killed Your Deal Was Never on a Call

    Field Note

    Start here, because it names the person who decides against you and explains why you will never hear from them.

  2. The Security Questionnaire Is a Sales Weapon, Not a Compliance Chore

    Decision Brief

    Read this second. Once you know who holds the veto, the questionnaire stops reading as paperwork and starts reading as a position in a negotiation.

  3. SOC 2 as a Sales Gate, Not a Compliance Project

    Decision Brief

    Third, and only if you are the one being asked for the report. It covers what the audit actually buys you in a deal, which is narrower than most vendors assume.

Numbers worth having to hand

Each one carries its source, sample, and a sentence you can say out loud with your own figure beside it.

Common questions: vendor side

Why do security deals stall after a good technical call?
Usually because a reviewer who never joined a call was asked for a private opinion and gave an honest one. Security engineers and architects are consulted late, answer in an internal channel, and the deal dies without that objection ever reaching the vendor. The economic buyer signs, but the technical evaluator holds the veto.
Is it worth investing in a trust centre as a vendor?
Publishing artefacts pre-emptively pays off once inbound questionnaire volume is steady rather than occasional. The calculation is the cost of answering the same questions repeatedly, including expert time and deal delay, against the cost of maintaining a page. Volume, not company size, is the trigger.
How many people will evaluate a security purchase?
Gartner's published range for a B2B buying group is five to sixteen people across as many as four functions. Security purchases sit toward the upper end structurally, because the tool pulls in legal, privacy, procurement, and an architecture reviewer. No analyst publishes a separate measured figure for cybersecurity specifically.