Your Enterprise Customer Is Lying to You About Who Is In Charge

The quiet transfer of governance through vendor-risk templates and the reality of the Fortune 500 heavy coat.

You believe you are the master of your own tech stack and you think the tools you chose were picked for their speed or their grace or their price. You are wrong.

You have built a 14-person company in a shared office in Jersey City and you have spent writing code that solves a problem no one else can touch. You chose your laptops and you chose your cloud providers and you felt like a sovereign nation.

But then the enterprise deal arrived. The contract was signed and the champagne was cold and the future looked like a straight line up and to the right. Then the security questionnaire arrived in an email and the email was from a person in a procurement office whose name you will never be able to pronounce.

The Spreadsheet Anxiety

Priya sat at the desk and she looked at the river and the water was gray. She is the cofounder and she handles everything that is not the code and she thought the deal was done. She clicked the attachment and it was a spreadsheet with 284 rows.

284

Rows in the procurement security questionnaire

She tried to read it on the screen but the rows ran long and the columns were narrow and her eyes began to ache. She walked to the printer and the printer hummed and it spat out pages and the paper was warm in her hands. She sat back down and she began to read.

The questionnaire did not ask about the elegance of their API or the speed of their database. It asked about full-disk encryption and it asked about Endpoint Detection and Response and it asked for a SOC 2 Type II report that she did not have.

Entry: Row 114

Describe the process for managing full-disk encryption recovery keys.

Priya looked at her own laptop and she looked at the laptops of the thirteen other people in the room. She knew the laptops were fast and she knew they were silver but she did not know if the disks were encrypted. She certainly did not know where the keys were.

She took a pen and she wrote in the margin of the warm paper. She wrote “We have keys?” and she felt a small coldness in her stomach. She took a photo of the page and she sent it to her cofounder and she did not add a caption because the question was enough.

The Power of the Modern Supply Chain

The misconception is that a small company sets its own security priorities. You think you are balancing risk against growth and you think you are making adult decisions about what matters.

But the power in the modern supply chain does not flow through the legislature or the courts. It flows through the vendor-risk templates of the Fortune 500. These companies have decided that they cannot trust you and they have decided that your lack of maturity is their greatest liability.

You will wear the coat or you will not get the check. Small businesses are being regulated by the private contracts of their buyers and this is a quiet transfer of governance that nobody voted for.

It raises the floor of security and that is a good thing but it also means your engineering roadmap is now dictated by the anxieties of an insurance underwriter in a different time zone. You are no longer building what you want. You are building what procurement demands.

The Revenue of Interruption

The questionnaire asked about patches. It asked if critical security updates were applied within . Priya thought about the times she had seen the “Update and Restart” notification on her screen and how she had clicked “Remind me tomorrow” for six days straight.

Developer status: 3 versions behind on OS.

Designer status: Firewall disabled for plugin compatibility.

These were not bad people but they were people who had work to do and the security was an interruption. Now the interruption was the requirement for the revenue. She realized that the security architecture of their firm was being designed downstream.

It was being dictated by the buyer. If the buyer wanted EDR on every endpoint then they would have EDR. If the buyer wanted centrally managed encryption keys then they would find a way to manage them. This is where the friction lives.

A small firm does not have a dedicated IT department and it does not have a security operations center. It has a cofounder who is tired and a printer that is running out of ink.

“The sea does not care if your beacon is beautiful. The light must turn and the oil must burn and the glass must be clean or the ships will break.”

– Elena A., Lighthouse Keeper

Procurement is the sea. It does not care about your culture or your vision. It only cares if your encryption keys are stored in a way that satisfies a column in a spreadsheet.

The SOC 2 Ransom

We often talk about SOC 2 readiness as a milestone of internal maturity. We speak of it as if the company has reached a certain age and has decided to put on a suit. But for most startups it is not a choice.

You pay the ransom in time and you pay it in software licenses and you pay it in the loss of the informal culture you loved. You do it because the alternative is to stay small and to stay poor.

Priya looked at the list again. It asked for a live asset inventory. It wanted to know the serial number and the warranty status and the software version of every device they owned. She looked at the cupboard where they kept the spare cables and she saw two laptops that had belonged to employees who left .

She did not know where the chargers were and she did not know if the data on the drives had been wiped. She felt like she was looking at a crime scene.

Managing the Macs of Jersey City

This is the reality for firms in New York and Northern New Jersey and everywhere else where the big companies buy from the small ones. You are forced to professionalize your endpoints before you are ready. You are forced to manage Macs with the same rigor that people manage Windows servers.

You need a way to prove that you are doing what you say you are doing. You need evidence. If you cannot produce a report that shows every laptop is patched and every drive is encrypted then the deal will die in the procurement office and it will never even reach the desk of the person who wanted to buy your software.

The burden of this management is heavy. You can try to do it yourself and you can spend your weekends reading forums about MDM profiles and patch management logic. Or you can find a partner who has already built the baseline.

Moving to a Solved State

Many firms reach a point where they realize that they cannot be an IT company and a software company at the same time. They need a system that watches the alerts and they need a program that brings the existing fleet up to a security baseline in .

InterDataLink provides this kind of managed desktop service for firms that are tired of being bullied by procurement questionnaires. They manage Windows and Mac fleets with the tools built for them and they do not force a one-size-fits-all agent onto a machine that was not meant for it.

They treat the endpoint as a complete program. This is the difference between having an antivirus icon in your system tray and having a documented control that an auditor will accept.

Priya stood up and she walked to the window. She could see the skyline across the water and she knew that inside those buildings there were thousands of people like her. They were all reading spreadsheets and they were all wondering where their recovery keys were.

She realized that she did not want to be an IT director. She wanted to be a founder. She wanted to solve the problem she had set out to solve and she wanted the security to be a solved state rather than a constant anxiety.

They see a world of risks and they see a world of vulnerabilities and they have decided that you are a part of that world. You can fight it or you can adapt to it but you cannot ignore it. The procurement department has become your IT director and they have a very specific vision for how your computers should work.

They want them encrypted and they want them patched and they want them watched. She went back to her desk and she started a new document. She did not call it “Security.” She called it “The Price of Admission.”

The Shift is Permanent

She began to list the things they needed to change and the list was long but it was clear. She knew that the next time a questionnaire arrived she would not print it out and she would not write in the margins. She would have the evidence ready and she would have the keys managed and she would have the fleet under control.

🗝️

The recovery keys are a sequence of numbers but they are the only locks that procurement knows how to turn.

The champagne from the contract signing was gone but the work was just beginning. The shift in power is permanent. The way we manage our computers is no longer a matter of personal preference or startup culture. It is a matter of compliance and it is a matter of trust.

If you want to play in the big leagues you have to follow the big leagues’ rules. You have to prove that your house is in order and you have to prove it every day.

It is a heavy lift but it is the only way forward and the sooner you accept that your procurement department is in charge the sooner you can get back to building something that matters.

By