Security reviews, often seen as time-consuming obstacles in sales, can be strategically leveraged as opportunities for relationship building and competitive differentiation when approached with the right mindset and tools. Rather than treating them as mere compliance exercises, sales teams should use security questionnaires as platforms for discovery to understand customer security culture, build trust with security professionals, and position their solutions as security differentiators. The key to success lies in shifting from reactive questionnaire completion to proactive engagement, utilizing self-service portals and generative AI tools to streamline low-level information exchange while reserving high-value human conversations for strategic discussions. Organizations should recognize that security review is not a one-time event but an ongoing process that spans the entire customer lifecycle, requiring cross-functional collaboration between pre-sales, solutions engineering, and compliance teams to turn this traditionally frustrating aspect of enterprise selling into a competitive advantage.
Security Reviews as Strategic Advantage in B2B SaaS Sales
Added:[Music] welcome to the webinar my name is Chris Ma I'm your host today general manager here at pre-sales Collective I was a solution consultant I'll take you way back 24 years ago I was in customer success I've been at startups mid-market companies ever since and I switched over to pre-sales Collective full-time six months ago and uh we're stoked to have events like this we have a rocking calendar even just this week we're in Singapore Berlin Chicago we've got webinars all over the place uh so thank you for taking a moment to tune in invest in yourself invest in the community I highly recommend throw some comments in the chat share your link share where you work right like make this meaningful for you um I ask people uh where they're tuning in from I love to see all the different locations we've got Brazil we have New York City we've got Atlanta where Daniel's located Upstate New York where I'm located so thank you so much everyone the uh title for today before I get into that one question who loves Security reviews and who loves security questionnaires crickets right yeah Daniel was just at RSA and said that was the question he asked everyone and Daniel what did they say it's the only question I've ever asked with 100% response rate the answer was the same and they all rolled their eyes they said H Security reviews questionnaires I can't stand them yeah yeah so we we specifically wanted to focus on this because I don't know about you but I've had a last minute 600 questions security questionnaire drop on me has anybody had that experience throw a little comment in the chat let us know you're there we've all done it it's not fun right uh you know the saying uh time kills deals Security review it's the trickiest time sync in selling in general our goal on this webinar is to introduce you to two people who know them very well introduce you to two people who are trying to solve this problem in their organizations we want to talk about tips and tricks on how to make them your secret weapon how to use a security questionnaire um and a process that actually helps you win deals um instead of that that wretched kind of gut snc hey we're almost at the finish line and here it is so so we want to cover a couple things one is we have seen a shift happening in this critical area there's a deal partnership to pre-sales teams that need to be fully recognized and used with infos and you know the the the inter cooperation between these organizations we know geni is quite possibly the most perfect tool to help us with this um in my personal experience I've never had a gen tool for Security reviews we we went old school with spreadsheets like like canned answers you know and it didn't work very well I don't know if it really ever helped us win a deal um and the market has changed and um you know we have complex security requirements we have tools we have processes we have tips and tricks we share all that here at pre-sales Collective one of the coolest things we do is share what good looks like it's a term I use in different organizations um and also I want to kind of double down on the fact that we can use these for good okay so I'm going to introduce you to our two guests today they're going to do a little bit of an intro we're going to get into some questions please a little housekeeping utilize the chat blow up the chat share everything you want in the Q&A ask us questions the more interactive this is the more we understand where you're at in your journey the better it is for us the better it is for the content the more we learn um we're all busy right so let's make the best best of it I'm going to pass it over to TJ gon is that how you pronounce your last name TJ I I kind of forget right wow you nailed it yeah perfect and TJ's at at figma uh and he has the coolest uh webinar setup apparently so take it away TJ yeah uh thanks so hey everybody my name is TJ I've been at figma now for about two and a half years I was a modern work architect at Microsoft before that um and yeah I'm currently focused on strategic and Enterprise segments my technical expertise is in things like like design design thinking videography sales and of course SAS identity and security uh and yeah it's an Eclectic but effective mix and I'm passionate about all of that stuff so looking forward to talking with you today definitely going to try to bring some hot takes of my own and yeah a fun fact about me is that my backyard is a digger be Sanctuary so every spring it there are thousands and thousands of thousands of bees in my backyard and it's amazing they're very docile and friendly so yeah looking forward to the conversation I'll I'll pass it over to Daniel all right hey everybody nice to meet you how do you follow a digger B Sanctuary I will try to um I hope that they make honey because at some point TJ will have to send me some of the Digger be honey I'm the VP of product marketing here at conveyor um I'm an ex engineer so this is like kind of my crowd I don't know how I ended up in marketing which is what I lead at conveyor um and I also know uh monetization because I'm I'm very passionate about cross sales cross market sales value positioning I come from places like gong Salesforce BCG and my fun fact is uh again I don't know how I ended up working for Special Forces making spy gear but I had a top secret security clearance for many years again I uh I don't use any of that in my current day job but it was a lot of fun while I did it in my early 20s uh back over to Chris yeah I don't know how I follow up this story I was telling Courtney before he jumped on it's like we got a B colonist named TJ and we got a special forces guy uh I'm just a nerd with a microphone so uh thank you guys I shared your LinkedIn let's all connect let's stay connected um if you have any takeaways after this or any followed questions just hit these guys up um I want to start with I like to start with a bit of spice so walk us through your worst experience so like what's the worst experience you've had in a Security review and then we'll get into defining some terms uh wow how do you pick just one you know there's such a diverse pallet of bad experiences uh but yeah and quick disclaimer like Security reviews when when I say review I think a lot of and we'll talk about it today but like getting in the room with people but all of my bad experiences are security questionnaire specific like I really like talking with security and it and I absolutely hate security questionnaires and so one example would be we actually have a thread on our team called SQ Nirvana Where we kind of capture these things like memes uh and one time I was it was a mandatory question was asked to provide the Ikea manual uh for figma or ass sass service so I thought that one was strange um and one time another mandatory question was is your team a whale or a squid and we no one on my team knew what that meant AI didn't help the internet didn't help so if there's anybody out there that actually knows what the the true intent of that question was let me know uh but yeah we answered squid really I answered na but yeah that was what the team decided so uh yeah they just threw that in to to just get by any maybe maybe any anything that was like autor response or something maybe maybe wow I thought it was G to be like some like obscure security term that was gonna have like this awesome background story and I'm still kind of hoping that's the case but yeah I have no idea all right wonderful uh anything to share on that Daniel you're good I think uh the only thing I would add there is my favorite is the questions are designed I'm sure we've all answered something that looks like explain your business yes no or Na and we've all kind of felt that pain right so these things are always designed by a human being human beings are trying to answer them there's a lot of wiggle room in how the the questions are organized but like I would say that's a pretty tough one yeah that's awesome uh before we get into the med of conversation and we'll jump right into some fun organizational stuff I want to Define terms because um you know I I've never had the most robust Security review questionnaire organization myself and I know many that are joining here are in the same boat so let's define some terms so talk to us about security questionnaires versus reviews those kinds of things Daniel you're in the space all day long so I'll hand it over to you sure so for folks who are either you know very familiar with Security review or beginning their Security review education Journey we think of Security review as simply the process by which a company can build technical trust throughout the sales process that they Safeguard data and why is this important today well everybody is a digital vendor these days right like there are Hardware providers or are software providers and everybody is selling digital tools and when digital tools have customer data how they share that customer data who that data goes to how you process it becomes really important for these companies and so any company who is uh putting their vendor through security review is ultimately trying to gauge trust and it's an important conversation that we need to have we need to recognize its importance and the way that a lot of companies engage in that process is by a few different mechanisms the first is they'll usually send everybody a Security review questionnaire right those might look like 30 questions they might look like 600 questions if you're talking to JP Morgan it's an 800 question questionnaire it's in a really complicated portal often times too you know want to bring in an expert who understands where is data moving how is it encrypted at in transit at rest things that are really Technical and sometimes throughout that process depending on the kind of sale you might also need to bring in an engineering team so these are people who not only want to have a human conversation that is like what's happening with the data but they then want to have an engineering level conversation like what are you actually processing what what languages they're using to code um because different security parameters might follow different languages and so when we think about that as an end to end process the answer is trust and the question is can I trust you um and so we find that you know there are various ways that people try to probe trust sometimes it feels like you're on a tribunal and you have to communicate trust um but ultimately it really is are you able to do it succinctly are you able to be clear and can you go at the different levels of information required in order to satisfy that um it's not just a checklist Security review is a process and it is not a one-time process it's annual it's the the life of the relationship and so it's important to remember that uh kind of is like a final thought security is not just a onetime event yeah totally agreed with everything you said and you know from my perspective I think of it pretty simply like there are questionnaires which are checklists and often are not Nuance they lack Nuance to put it lightly and then there's more of like reviews and Audits and assessments and talking with Security Professionals and it goes back to exactly what Daniel was talking about of a shared understanding of the actual risk of your platform that's something I'm always trying to get from security teams and that Mutual trust and yeah that's why I really like getting in the room with security and it and talking through that because we can build relationships and we can actually develop a meaningful shared understanding um and I find that you know a few minutes one question uh one meaningful motivated question to a security engine ER is more effective than you know 500 rows that are expected to cover every potential SAS tool and Beyond um so yeah I love that and I'm gonna put this quote so I'm trying to like record some of my favorite things that you've said and this is my first one which is like it's not a one-time event but it's a process uh I kind of I I think of this in in uh demoing too like a demo isn't a one-time thing you do it is a process go through and it's a process you go through over time and uh I never thought about Security reviews as the same way I think that's really interesting and as somebody who's leading teams it could help you do things like get budget it could help you do things like tool around it right so that's like my biggest takeaway so far um and since we're on kind of like you know Daniel you you focus on this problem I love talking to people who focus on a unique problem that we all have uh we have we've worked with tons of organizations security teams who typically works the review process like who's typically the owner more more often than not yeah so we see differences in the owner at different sizes of company so I would say that ordinarily a little bit uh lower on the on the market stack we think of like SMB midmarket tends to be in like an SNB mid-market sale you will have like a handful of info managers they might be the ones who are helping the sales and pre-sales team uh they might be doing a little bit of the security review answering and or they might be doing a little bit of the customer facing work but they're answering the predominant number of the questionnaires um and usually what starts to happen is they specialize As you move up right like when you start getting into the the figmas of the world and the bigger companies you get more solutions team who are taking a first pass those infos teams start to get a little bit smaller and they are responsible for quarterbacking not only the technical elements of the sale but also the technical blockers of getting the sale across the line because an infosec manager may or may not be comped in the right way to accelerate a deal but those who are customer facing kind of feel that that that pain all the time and so they're they're really uh they're trying to accelerate those deals I would say the last thing is like there's a lot of variation right so sometimes uh you know I might say something in the mid market and up Market it's like a kind of the exact same experience what we we tend to find is that you know up Market Security reviews tend to be really important right because as you as you go and sell up Market you're trying to go after usually a bigger customer who has a deeper requirement so that specialization makes a little bit more sense um and so it can it can vary a little bit but that's kind of what we see that's cool yeah it seems like uh it's extremely like nuanced like just depend dep of where you go how large the company is how important it is question to the audience um I'm curious who is in charge of this process in your org where you work just throw it in the uh chat if you'd like also we have the Q&A open so if you have any questions as we go through please pop them in there we'll make sure to include them in the conversation uh I have a second question which is kind of a pie in the sky question uh if you were to design a security process an RFP process how would you do it like let's say you can do it totally from scratch what what do you think is your your preferred way of seeing this thing organized over to you Daniel I I'll let you answer that one sure uh sorry we have uh there's some people who are cutting grass outside my my window right now everybody hear me okay yeah you sound fine okay perfect um yeah so I think one of the interesting things that we're seeing right now is there's so much tooling around deal scoring likelihood scoring and what we see now with like answering an RFP is it takes a huge amount of time right or answering a questionnaire but obviously we don't always know if the juice is worth the squeeze and so one of the things that we've noticed is that as we are seeing deal scoring and likelihoods to close enter the sales process it's a very good guide for how we should think about prioritization uh looking at whether or not the ARR is good is something that we should be bidding on um and then we kind of get down into like some some of the more interesting things like can customers get to self-serve dependent on their size and spend threshold right like there's more ways that we can get a customer to self- serve their security questionnaires these days and uh that burden should not fall exclusively to the pre-sales or for the infos teams um the the third thing that I would say is that it's pretty uh I mean obvious that our business is answering questionnaires in seconds as opposed to hours um but being able to do that what we find allows people to then focus on security as a differentiator not just at the lowest level of answering a question and so I would if I'm to redesign that process it's I need to answer every questionnaire immediately so that I can explain what's different not why are we better but why are we different in a sea of sameness nobody's going to win on better we always have to show why we're different that's like the product marketer and I'm sure a lot of people hear that from from their sales team and the last thing is um adding ways to measure Roi and efficacy of how we uh resource our teams like how often have we gone into a conversation where say hey our team's not resourced to do what we want to do and that process needs the ability to unlock visibility at every step of Security review so we can say hey our teams are bottlenecked down right now we would rather be doing more demos more technical Discovery and those are the kinds of things that I would unlock from process to generate more business value yeah that sounds amazing TJ you have any uh any insight on that any any opinions uh I mean yeah because you know figma we've like kind of rehashed this a few times but uh I'm really big on self-service these days not only because I think it's better for sc's and IC Solutions pre- Sellers and post sellers but I actually have seen like how when we invest in our knowledge base and our trust portal like the impact of that and so if I think back to over two and a half years of all the time that I've spent completing these one-off sqs having it if I could invest all of that time into knowledge base and process instead I think we'd be a lot further along in automating a lot of this than we are today and so yeah in short uh I'm big on self-service also self-service is faster I think when it's done really well uh you know you'll see these things get turned around a lot more quickly and the hope then is that we're spending all of our energy getting sales you know technical sellers in the room with security it and the Sea suite and then that should be the focus whether we're driving security conversations or upsell conversations uh regardless you know I want all of my time to basically be in front of someone if we can so yeah that would be my take there's a lot of great comments uh from Luke he's he's asking how do we talk about how Discovery can drive security which goes back to like security as a differentiator speed TJ your point on you know focusing on the right thing which is being in front of the customer right do you have any uh you have any thoughts on that uh yeah I think Discovery is everything and Discovery is really hard when you're trapped in a Excel file with impossible to navigate you know and very unnuanced questions and so for me one of the things we'll probably talk about a lot today is how there's a bit of a tension with security questionnaires to just do them as quickly as possible but I found a lot of success doing the opposite and using them to slow things down using them to mature my network within the customer get to know some new people get to understand what their overall security process looks like and all of this is a process of discovery for me it's Discovery to understand like who am I working with what are the opinions what is the culture of security at this customer what kind of things are they going to evaluate us against so that we can start to build a more sophisticated uh and custom talk track but I'm doing all of this discovery building these relationships and through this we can actually make meaningful progress towards security improvements so maybe to cut to the Chase and share another story is you know I fill out lots of these security questionnaires including the ones that are 500 plus questions and for the amount of questionnaires I've completed the amount of times that that questionnaire made a meaningful impact to security is almost none versus uh Gabe brby a seller here at figma uh was recently basically getting ghosted by an account it had plateaued we couldn't you know get people to respond to us they had been through the security questionnaire process many times you know like they were an existing account we were just looking for expansion um and Gabe had the idea and basically sent a DM to the CTO on LinkedIn and said hey are you aware that SSO isn't enforced for your organization and just that one message got him a meeting with you know senior leadership within 48 hours and guess what it made a meaningful Improvement to the security of their figma deployment and so I'm a big fan of things like that like how many security questionnaires I've completed that don't even ask like what is our Baseline deployment what capabilities do we have in the tool have we enforced SSO you know these are the things that get Lo lost you know lost in these big messy documents and why I prefer this idea of I I kind of like labeling it Discovery too it's like use the SQ as your you know your platform for Discovery at to customer uh and you you can do that pretty successfully especially if you know a few tricks and I think we're going to cover some of those too I love that use the SQ as a platform for Discovery that's a that's a nugget right there because uh as you said it it is something that we can use to slow deals down if you need to if you want to get more information from your prospect I I mean frankly I've just never thought about this process in that way ever so that's that's very insightful uh tons of great comments in here um I mean I love that the the term though I've heard Daniel you mentioned it and TJ you mentioned it on self-served Security reviews I kind of want to talk about this in a practical way because we we really want to drive a few things in these conversations Theory experience what ises good look like outside of our our existing organizations so we can learn how to get better and also practical advice for those who are tuning in um something they can use right now or practical advice on how to get customers to selfs serve more often right so I kind of want to unpack that and TJ hand it over to you you said self- serve is your favorite way so let's uh let's discuss that yeah uh lots to unpack here so one of the reasons I like self-service is data and insight so that's another thing conveyor kind of brought to the table for me is I can see prospects and customers and if they're looking at documents what have they downloaded how much time have they spent in our portal and that is amazingly helpful it also allows you to show to calls with like credibility you know I can show up and know whether or not the customer is starting from scratch or if they've actually you know done some due diligence and their homework on our security uh self-service is also tricky because I'm not going to sit here and pretend like it's you can just self-service and that customers are going to do it there's always push back uh there's always push back for self-service so one I think having a really good experience is important and exper experience meaning like what is the user experience for someone who's trying to selfservice I think that is the number one thing that will really block you because if you finally convince someone to try it and they can't find anything well then you've kind of blown your shot at self-service there too uh and then finally the trick that I think has landed me more like self-service than anything else is if you know it's an account where you want to slow it down if you know it's an account where you're trying to drive some self-service you know go talk to your seller and position the completion of the SQ as something that needs to be done live like a lot of times I'll say you know we can't complete this unless we book a bridge and we go through it together and so we'll put 60 or 90 minutes on the calendar whatever it takes and we'll sit in and at least 10 to 20% of the time that is enough for them to go in self-service because they're like I'd actually rather not sit on a bridge um and then for the other 80% of the time where the call gets scheduled you've already uplifted the SQ into something that's going to allow you to do Discovery and something that's going to make a more productive conversation so you can jump onto that call start working through a lot of it I've made really really good progress in 90 minutes on really big complex questionnaires with this method and it's something that I do pretty regularly at least when you know it's a possibility and when it's something we can try that's really cool I put that in the chat that's a TJ tip I'm G to maybe copyright that book a session to do the SQ live on the call so not only does it help you get more Discovery it helps you learn about your customer Prospect but it also can drive self-service if they're like hey I don't maybe need to do that yeah yeah on the experience side Daniel do you have anything to add there yeah I I'd say a couple of things so the first one is truly it's an experience right and when we think about who should drive that experience if we only put the capabilities of a lot of these tools in the hands of like infos team for example we might end up with an experience that serves an infosec team but doesn't always serve a customer and one of the amazing things about Solutions engineers and the consultant teams who are client facing is that they feel every bit of the customer experience so I would encourage everybody to think about like as a business leader or those who want to be future Business Leaders start considering like what does it mean to be a design partner working in partnership with those other teams who can help them do the heavy lifting for you but you kind of get to own that experience and so when we think of selfs serve we think of a few things obviously you can buy tons of tools out there today you can go selfs serve all your gated NDA documentation like a lot of that stuff's going to be on the free side these days um there's really complicated flows that you could set up that like hook in your Salesforce implementation that kind of give you insight into how do you prioritize how do you check out what leads are coming in with the right information and then when I also think of selfs serve it's like you want to give them some amount of questioning and answering and you know again like it's not perfect today to TJ's Point like we we do a good job of managing that conversation and what we want to do is continue to offload the low levels of conversation and up level to a high value conversation so when I think of selfs serve I don't think of it as like a fully automated no human ever talks to one another human that would be horrible that's not I think where anybody wants to go we want to get to a point where hey the human- to human conversations are rich in context are applicable to your product and easily communicate differentiation and that's the holy grail and Northstar that we think a lot of selfs serve should offshoot a lot of that low-level information and get to the high value ads yeah to to so to add on that I love that comment uh we recently did an event where we talked about how to spend time on critical deals right and a lot of us are frankly a lot of us are doing more with less these days our teams have shrunk but our responsibilities have grown um we've decided to take on more but haven't really grown our Personnel um so there's some talk about the Tooling in the chat there's like a few people making suggestions which I love keep keep doing that that's good um I always think about how to make business impact because when it comes to tooling you have to get budget free stuff is cool I like what you said Daniel but like I've never had the best success with like the free freeware stuff uh at a large organization right and never never just it never gets adopted it never gets approved so let's talk about the impact business let's say you're trying to go to budget or let's say you're trying to build a Security review uh Council on your team um so how should teams be thinking about how to present the impact on the business side yeah um how about I take a first pass and then TJ I'd love to hear your your take on this too because you've you've you've purchased and implemented and bought um one thing that we notice is like this is a revenue problem and if we let it kind of sit in the infos seex sphere too much then we need to find a way like it'll get uh only productivity uh levels of investment and so my my feeling has always been you got to go in with a billion dollar problem you got to tie that billion dollar problem to revenue and when you tie that billion dollar problem to revenue you need to have metrics that are easily influenced by getting those budget line items and you know when I think of like uh solutions that are in the revenue space we want to increase win rate we want to increase deal velocity or decrease cycle times and we want to show more attribution of Labor spent on Revenue outcomes and so what I encourage people to do is like evaluate tools that give you that first and foremost and second of all as you're thinking about putting together the business case is you know there are productivity gains always for a lot of these tools but no executive's eyes light up when they hear Time Savings because what they think of is like great your 40-hour work week is now fully stacked tipto tail um and we all know that that's a little bit silly of course but usually Time Savings and productivity don't really get the big budget line items so I found that like you know when we walk in we just released a state of Security review 2024 report and we showed like hey here's like the effect of pulling forward uh deal velocity by uh 23% and like increasing wind rates by 40% plus like these are real measurable outcomes that are benchmarked um and that you can go in with third party uh validation and say look like other companies are getting this if we're not kind of investing either we will fall behind or we shouldn't expect the outcomes uh that some of those do more with less targets that seem to fall in all of our heads uh seem to imply so that's kind of my guidance is you know know the metrics tie it to revenue and find a way to make it a billion dollar problem TJ what what do you think wow uh I will say I don't think I'm the expert here so I'm always open to like better ways to capture the impact especially because it if I'm being transparent it's really easy to get an SQ and complete it and then try to correlate the amount of time you spent on that SQ with like the associated Revenue but in my experience there is so much variation that's kind of a lost cause I've spent hours on sqs for you know 15K deals and one of our largest customers by revenue and size sent us a 10 question security question questionnaire as part of their annual assessment so it's like it's it's pretty difficult I think in that sense uh From figma's perspective when we brought in conveyor we we had to solve a need we had a very specific need that we wanted to solve so it was very easy to say like this tool does it does it in the way that we want so we're going to start utilizing it and since then we've just seen its use kind of mature across the SC team and figma's really been in this like high growth startup phase for a while so for a lot of times it was like tool get whatever tool you need so that we can like get the job done and scale as fast as possible and now you know of course I think we're starting to balance out uh but in short yeah get insights get metrics I totally agree with Daniel there there's no shortage uh at least the ones that we've been able to pull um but more so like make sure you're using it in a way that actually solves a problem it's really easy if every Solutions consultant on the team is like don't get rid of this tool because it will severely negatively impact the customer experience and our ability to get the job done and I think that's kind of The Stance we've taken or at least me I know that's the stance I've taken so yeah love that Daniel uh you guys do a lot of research so I find that I I've seen some reports that are really good is there anything you can drop in the chat or anything you can share on like on that data let's say let's say I am trying to build a business case yeah I'll give you one more data point that I think about all the time um BCG released uh a gen AI report and what they were saying was like Hey lot of hype a lot of Sizzle how much stake and the the answer to how much stake is that everybody thought 2023 was the year of hype right like we're going to use gen but every business leader said uh look I'm going to make investments but I'm going to encourage my team to guide me on the utility of a use case and so what we're starting to find right now I think is uh oh is that me is that somebody else sounds good to me okay sorry about that there's there's something that keeps dinging in my background um but gen right now is uh on everybody's lips and leaders think that 89% of them think that 2024 is going to be the year that all those Investments start to look at Topline uh growth and productivity and so basically it's it's the way of saying like we put our money where our mouth is in 2023 and 2024 is when we expect to see the return and so uh I'll I'll drop the state of Security review 2024 in the chat and folks can check it out but the truth is like we had a lot of hype and now it's kind of time to see the stake and so uh that's the thing that I'm most excited for is like are we gonna find the use cases are people going to adopt the use cases and are we going to see the productivity gains then translate into Revenue gains uh because I think if we don't we'll we'll we'll start to see um a lot of different investment mix but the truth is companies have thrown a lot of money behind this and so it's it's pretty likely if we're not uh uh if your teams aren't starting to use these things like other companies are and so like I I get worried like every day I'm using geni more and more yeah that's I mean that's perfectly sets us up to the geni conversation because when I think of generative AI I think of you know I think of a tool that can help me with this kind of problem right and it's going to speed it up it's going to make it more accurate uh so it's a huge topic when it comes to rfps Security reviews this kind of stuff so uh what opportunities and more importantly what are some of the risks you guys see in these um you know and I'm thinking anything obviously Beyond like free web tools on answering questions like but where where do you see the risks and opportunities I'll pass it to you TJ uh okay first things first I am a huge advocate for increasing the head count of your compliance teams so please if you're watching this and you're a leader don't think that geni replaces a compliance team uh so shout out Jordan Cole Berber they have been the single greatest thing to ever happen to us and our ability to actually manage these kind of you know situations in these contexts and the reason as well not only have they helped like our team and helped us mature our compliance and our security practice at figma but they've put a lot of investment in our knowledge base and having that robust set of questions and answers that are very detailed and have you know regular review and sign off and we know refresh in addition to having like all of our policies and documents together then geni becomes more and more powerful and that's another thing we've noticed is that you know the big concern with Gen is accuracy and precision and the risk of hallucination and it is we're talking about security so it's like especially potent that we accommodate for those things and so that's why gen is going to be amazing uh but you want to train it to be as conservative in hallucinating as possible and the way to do that is to train it on a large set of data so no matter what you still have to go in and have some kind of internal process for collecting refining and building this information now I think one thing that I'm really excited to see in the future is gen's ability to ingest and produce its own KBS that we could then sign off on because right now I'm finding a lot of the work a lot of the timec consuming work is going to all these different parts of your company and just getting consensus and fact and like and when you look at these questionnaires like they are not playing around you know they are trying to assess your company from every possible perspective and so we're also seeing questionnaires change um and these questionnaires I think are changing in way ways that generative AI might not immediately address them and so I can give you a specific example one that we saw recently was this giant countermeasures document and it was not just your normal security questionnaire it was uh somewhere between six and 800 questions specifically about our AWS infrastructure going feature by feature asking for precise you know answers as to what uh what we've deployed giving comments on everything and it's like that is not a small project it took us months uh and months and months of work to do and generative AI wouldn't have helped there that said there are lots of places generative AI is helping us it's it's helping us uplift our knowledge base to be more efficient and more robust it's also for me it's helping me kind of bridge the gap between things and the knowledge base because as figma's gotten more complex it's growing I'm having to track you know as an sc I have to keep up with the product and then trying to also keep up with all of the infrastructure and the security policy changes and the compliance landscape like all of that stuff is extremely difficult and so gen AI is really good at like connecting the dots like if we have three different facts in our KV that are knowledge based that aren't related geni can take those things and then craft a very compelling you know snippet of text that explains and accurately you know is able to answer questions with Nuance like that so that part is amazing it's making it a lot easier to just quickly validate my own understanding quickly uh answer some of these security questionnaire questions that are worded intentionally to be hard to answer you know like the issue with these old KBS where it was just all you could do was like directly match a question and an answer uh they just keep changing the question so that you can't really do that so J is great is because it kind of goes around that and says yeah can actually take these different things and create you know I can string them together and give you a response that answers the question uh with precision and accurately and that that's the magic word right accuracy and you know I I'll admit like I I'll do exactly what you're not supposed to do in marketing and admit that like a lot of accuracy claims out there in the market or a lot of hogwash you know anyone can say we're 95% accurate we're 82% and a half percent accurate right um and the truth is for a lot of these tools the users start to learn very quickly are they accurate enough are they accurate enough for the claim and are they helping with uh productivity workflows right so it usually starts there I find and like you can bake off those tools and you'll you'll find some way of figuring out like is it going to look at AWS and all 500 lines of you know are you in AWS East and what what prod are you using and things like that and usually like will fail miserably one of the things that we're noticing in AI though right now is there's this idea of like AI becoming as much an agent in your organization as opposed to a co-pilot and what I mean by that is like a co-pilot it's all the rage right I'm sure somebody in here probably has a co-pilot of some kind that's like following you around but those co-pilots when we think of gen AI are really designed for a function they're not designed for a company an agent is designed for a company they're usually built for like a specific user in mind or Persona whereas the AI agent is kind of built more for like the the customer in mind and so they're thinking about it more holistically um and so if I think then about the Gen tools that are starting to see a little bit more success it's that they're not looking like co-pilots they're looking like experts and what does an expert do they do four things they know everything they span functions they handle complexity and they take action and those are like the ways that I think the Gen tools of the future are going to start to help people not as like a co-pilot who might help the sales team might help the marketing team they're really somebody who sits there and spans all those functions um and they can do things like they can plan they can reflect on what they've done they can judge their own confidence and I think it's a lot of these human tasks that we're all doing um and so I would say as we're thinking about the future of geni like there's a lot of Promise out there it's going to take a long time to get there but the way that people are building is really different from organization to organization so I think like as a marketer it's really tough right now because every tool is super different there's a lot of claims and so even as a buyer I find like we all have to kind of experience a lot of these tools for ourselves so if you're into that it's a really exciting time if you're less into that you know maybe wait for all of that experimentation to play out a little bit more but that's kind of been my experience so far to date yeah that's that's a good insight for sure on the note of Agents like if a geni agent could go out into slack and just ping our infra team and say oh hey we need to confirm these things and then later on it fills that questioner out and I'm able to get it that would be amazing so I'm just putting that out in the universe and the hopes that that gets built very soon we're adding it to the road map DJ there you go yeah love it somebody on the call is thinking of their side hustle immediately that's that's great yeah and I agree with Danielle it's like that's an awesome overview Daniel so thank you um anybody I wanted to ask this question to the audience in the chat just are you using gen AI right now are you waiting are you kind of like lurking in the background kind of you know waiting for something to come to fruition I find many of my com it's we're using II but it's like built into the tools we're already bought in on right so we may use like an AI addin on some tool that we've already uh integrated into our tool set um so please let us know in the audience uh to switch gears a bit I want to see okay yeah using co-pilot there um if you have a security review in your queue right now let's say you're on this you're on this or you're even listening to the recording and you think I've got one that I have to do what's the fastest way to make improvements um with your relationships to the customer and the deal so not just on how to get the the the questions answered that's kind of on you and your internal process but let's say I've got one in the back of my head I don't wantan to I don't almost don't want to get to it and what's the way that I can actually impact my relationship and my opportunity with that today TJ I'll hand it to you good question uh it's a bit of a trick question though because in my opinion once it's in the queue you basically need to just get the thing done uh the easiest way to torpedo your relationships with your seller with your customer is just like let that SQ hang out uh so you know if it's in the queue if people expect it to be done you want to just kind of knock that thing out as quickly as you can you know use all the tools at your disposal to try and carve out that time and finish it the best thing you can do though is to try and get ahead of all of this stuff before the SQ even gets submitted so as early in the deal as you can and we say this a lot I think a lot of you know pre-sales people will know that we should bring security and identity into the conversation as early as possible and sometimes it's easier than others right like sometimes you can try to bring it up and it's just the deal isn't at that stage or they don't want to Loop that person in but the more that you can get ahead of that stuff or the more that you can set these table Stakes or these standards early on in an opportunity the better so one partner with your sellers to make sure that you're on the same page with them about how you handle this kind of stuff and the approach you want to take definitely Identify some top opportunities and try to proactively uh kick things off like security questionnaires tend to just arrive on a certain Cadence because they're triggered by like tools internally at the customer so even if you go to a customer and you say hey send me a security questionnaire and I'll complete it ahead of time a lot of times they're just going to be like well that's not really how it works you know we'll send it when the things trigger to send it across um that said reviews and assessments I have had success sometimes getting these things kicked off at a customer like I'm a big fan of as soon as I get looped in as an sc even if I'm doing like a a really early stage Discovery demo trying to get connected with security and it and offer them some kind of a download or an unboxing of the tool from a security perspective we offer up Enterprise deployment reviews and Baseline deployment guidance I do that all the time I'll go look at the customer's deployment pick out the things I know uh I would improve upon if I was that admin and I just put that stuff together and try to like use that almost as a proposal and when that stuff is done effectively you can really quickly get really far into a customer you can really quickly Network and meet new people and uplift it potentially um I like your take on on using these as a way to to uh to network and to build relationships and to build trust right be besides just filling it out I think that's a really strong take on the security review thank you everyone for your comments I me you got Tim so many people in here have left great stuff uh so thank you Luke John um I kind of want to wrap up with but Daniel I'm interested in Trends so we're keeping an eye close on we talked to ji uh you spend all your time in this area so I want to learn from you what are the trends you're watching uh what are you keeping a close eye on and what do you want to tell us to look out for yeah so I think the big one in AI right now that we asked was like hey who's using it should I be thinking about it am I making the Investments um we we ran a survey recently and what we're found we found was that 31% so about a third of companies across different market segments different verticals are currently using AI to transform their Security review productivity and another 24% of those are not but are planning to in the next 12 months so that's you know 55% uh roughly in there um which kind of tells us that we're at this weird Tipping Point right we're we've seen a lot of hype we talked about stake and Sizzle and we're starting to see a lot of investment and now it's kind of like game time so I think 2024 is going to be the year of like is is the juice fully worth the squeeze um and then the other Trend that I'm noticing is that Revenue team leadership is starting to measure everything right like it wasn't just that we would measure win rates and velocity we would look at close rates on uh you know different market segments and you know people's teams would get beat up over different market segments like who's doing well in mid-market who's doing well in ENT priz how do we think about deal cycles and things like that what we're starting to see is back office start to get measured so deal like time kills all deals what a wonderful thing that we all say what are we doing about it and what we've noticed is that cro are starting to realize in a world where every CFO is looking at the budget a lot closer every time we go through legal review deal desk Finance review all the backend process that gums up a deal is a lot of backlog that we are kind of imposing on the selling and customer facing team that in some ways is just natural company friction but in a lot of ways is a lot of dysfunction that we're all trying to get past and so what we're noticing is that it's not just an AI Solution that's going to solve all of that it's AI plus good workflow plus better process redefinition and we're kind of seeing all those three things take shape together and so I think that's like the recent trend is uh Revenue team teams are realizing we cannot let back office slow down front of house revenue and so we will measure Security review we will measure legal review and when we get to those bottlenecks we will figure out how to solve them because they are resulting in real dollars and so that's been a change in my world for like within the last two or three years I have never seen anybody care about Security review now cro are coming into meetings and they're saying yeah we got to fix this uh especially up Market um and the last thing I would say is like the way that a lot of people are pitching this is like we can't go up market and we can't do big deals if we don't have hipa compliance fed ramp and so as we talk about teams pulling in other teams and solving it cross functionally what TJ said Is Right like we love our compliance teams we need to elevate them in the eyes of our cro because let's be honest a lot of them are not too good at selling themselves internally but we know having work with them how good they are and so I think that's kind of like maybe the third Trend if I had to pull one out is like it's a partnership and part of that partnership involves helping those teams sell themselves and connect to revenue and so I kind of view this as like an exciting time to show all of that value in a new light yeah I mean it makes me think if that's not already happening in my organization if I'm the you know I was a solution consultant manager and leader before I came the pre-sales collective if I'm the one that brings that to my cro and I'm the one that says here is a here's an area where you have not focused yet but but here's how much impact it can make on the business I feel like that would be that would be a heck of a thing to bring to the executive staff and and then back it up with a potential solution saying here's how much time we're taking this is a paino but it's not just a time thing it's a revenue thing yep um I would I would take that away from this and I would think okay I'm by maybe Friday I I want to bring that to my cro yeah wonderful TJ any last uh any last words on Trends or things you're seeing in the market um yeah I mean I'll plus one compliance again and I guess I can also speak to Trends from figma um because you know we're at this cool stage where we were this hypergrowth startup and now we're maturing and we're like we we sold a lot of customers who now have very big security and compliance demand so I think if I went back a few years all of the sqs I I was doing at figma were like rapid fire it was a lot of net new business or annual sqs you know like a c an existing customer would send us one questionnaire once a year we could almost even know what week out of the year we would get an SQ because it was on a rhythm now it is non-stop uh larger more regulated customers it's not one S I have a customer right now where it is going on six months of constant assessments Audits and it's great but we didn't necessarily see it coming so it's this thing like as your company changes the demands of sqs will change and the relationship of sqs will change and you're it's not just this simple like we're doing more sqs it becomes an entire function almost an entire job to itself to manage some of these accounts and their their they have giant teams assessing you as a service provider so it's like if all you have is your one low you know your IC pre- seller trying to manage that it is extremely painful and it's also a diservice to the company to your customer and it will impact Revenue because when that customer finds a certain amount of findings or things that you need to change they will demand it and they will use their spend as a way to motivate those things at your company so it goes even more into being forward about relationship building because it is so much better when you're working with these teams if you have that trust than if they don't have the trust you know and I've been in both situations and I can tell you I would rather do non-stop Security reviews and assessments with a customer where we have that trust then a single security questionnaire from a customer who we haven't established any kind of connection or relationship and so that's the thing and considering all the noise and the Nuance of security my last point I'll continue to bring home is just like get in the room with people build relationships and make this Security review thing something that's more human and it will be more productive I promise um especially if as you're trying to like grow revenue and yeah get to know customers better and improve your own product you know I think it's been great because a lot of the customers I have the best relationships with we've spent a lot of time thinking about how can figma improve security and what is that going to take what does that look like and it gives me something to go back to my product teams with that's specific it's tied to revenue it's well thought out um and that's ultimately what I'm looking for as well as I Look to build those internal cross functional Partnerships so yeah yeah I think that's a great way to land the plane TJ thank you for that no problem yeah I I want to wrap this up by thanking everyone who who joined live everyone who's watched it everybody who's consumed it thank you so much for all the comments Barry uh really appreciate you um I put your LinkedIn profiles in there before but can you share with us the best way to get a hold of the two of you easiest way to LinkedIn connect and I'm I'm happy to always chat if if folks like same please hit me up on LinkedIn that's where I'm at yeah thank you so much my biggest takeaways were and one of my surprises is this this could be used as a tool as a way to slow things down if you need it if you need to build a better relationship um get in the room with those individuals make the security review a part of building that long-term trust relationship AI is looking more like an expert than a co-pilot I think that's a cool uh way of looking at the trends that you're seeing in the market Daniel and also it's just this isn't a one-time event this is a process it's a process you go through once twice again and again it's something you're always building towards especially as you move up Market thank you for tuning in Chris maber here GM at prales Collective my um my entire philosophy here is I want every member to interact with us anytime you do to be learning connecting and growing so thank you very much for t for tuning in and until next time take care thanks everybody see you thanks everybody
Up Next

Harvard Negotiation Principles: A Guide to Win-Win Outcomes
@ErichPommerInstitut
2.4M views•2018-06-27

IFS Therapy Demonstration: Complete Session with Unburdening
@IFSCA
95.9K views•2021-01-13

FastAPI vs Flask vs Django: Choosing the Right Python Web Framework
@TechWithTim
302.5K views•2024-05-26

Game of Thrones Opening Credits: A Cinematic Analysis
@gameofthrones
46.3M views•2011-04-18
Related Study Plans & Knowledge Roadmaps
Structured learning paths in General & Interdisciplinary Studies





















![[Masterclass] Closing with confidence: Security as a competitive edge in the sales process](https://i.ytimg.com/vi/kXq1i1lZFbI/sddefault.jpg)

















