SlideShare a Scribd company logo
DAN KAHN
Global Open Finance Lead
Plaid
EVA PITTAS
Founder, COO
Laika
The Secrets of Enterprise Buyers
Closing Enterprise Deals
What to expect when you’re expecting a deal
The first deal
is the hardest
to close
01 Identify your champion
02 Provide product access
03 React to feedback quickly
04 Provide data to support ROI
05 Demonstrate commitment
to security
3
The Gatekeepers
of Enterprise Procurement
5
BEFORE: Bilateral Relationship
Business owners
care about business
results
NOW: Multilateral with Multiple Gatekeepers
6
Business owners
care about business
results
Gatekeepers
predominantly care
about complying
with regulations &
managing risk
You closed the deal. Now what?
Continuous compliance. Or risk being replaced.
7
→ Ongoing diligence driven by
criticality and risk rating of 3rd party
→ Incident-driven diligence
→ More scrutiny over 4th Parties
→ Cloud Security Certification
specifications
→ Continuous Monitoring
requirements
8
What’s coming?
Signing a deal is only the start of
your compliance journey.
Maturing enterprise relationships
and the ever-changing compliance
landscape means that your
compliance posture needs to
continuously evolve.
9
Being
enterprise-ready
never ends
Demonstrating Trust
through the procurement process
11
Standards, Frameworks, and Best Practices
Growing Concerns Growing Regulations
→ $4.6 million: Avg. cost of cyber attack
recovery for $1B+ businesses
→ 97%: Financial services pros worried
about 3rd-party risk
→ 82%: Nations with privacy regulations
to protect consumer data
→ 31%: Security leaders who say lack of
visibility of sensitive data is a
compliance concern
→ 280 cybersecurity bills introduced in
2020 in the U.S. alone
→ First time the OCC, Fed, and the FDIC
proposed unified guidance for the
banking industry - around managing
3rd party relationships
→ CMMC required for all DOD 3rd parties
and supply chain by 2026
12
Regulations… and more regulations!
Due diligence and security questionnaires keep coming. Even after audit.
→ Industry needs to
standardize compliance
→ Businesses need to
customize compliance
13
SOC 2 is ubiquitous. Why do we still need to
answer security questionnaires?
SOC 2 + CC 3.4
The entity identifies and assesses changes that could
significantly impact the system of internal control.
DDQ + I.2.3
Are applications released to production
on a fixed schedule? Identify the schedule.
Continuous Procurement
Supporting the process of
15
//
The emerging fintech ecosystem includes thousands of nodes
connecting banks to fintechs
16
//
The emerging fintech ecosystem includes thousands of nodes
connecting banks to fintechs
FINANCIAL INSTITUTIONS
11,000 financial institutions (US, Canada, Europe)
17
//
The emerging fintech ecosystem includes thousands of nodes
connecting banks to fintechs
DIGITAL APPLICATIONS & SERVICES
5,000+ applications built on Plaid
18
//
The emerging fintech ecosystem includes thousands of nodes
connecting banks to fintechs
DIGITAL APPLICATIONS & SERVICES
5,000+ applications built on Plaid
FINANCIAL INSTITUTIONS
11,000 financial institutions (US, Canada, Europe)
Emerging data security standards
19
→ Plaid and Laika, alongside our industry competitors are developing a
new Open Finance Data Security Standard (OFDSS)
→ Industry-driven proposal to enhance data security in the fintech
ecosystem and foster responsible innovation
→ Security framework optimized for cloud-native, tech-focused
startups and growth-stage companies
Takeaways
20
Check-the-box security won’t land
and retain enterprise deals
The bar for infosec and data
privacy is already high--but rising
with calls for vertical-specific,
actionable guidelines and
continuous monitoring
Security and Compliance should
be a permanent business function
enabling responsible innovation
and building trust in the
marketplace
01
02
03
THANK YOU
SLIDE BANK
Current
compliance
landscape
01 Financial Services
02 Privacy
03 Federal
04 Healthcare
25
Current
compliance
landscape
01 Financial Services
02 Privacy
03 Federal
04 Healthcare
27
Prepare for growing
regulations
28
Industry wants to standardize security
and businesses need to customize
security
Top 4 Cybersecurity frameworks
Nist: 29%
CIS: 32%
ISO: 35%
PCI DSS: 47%
90%: Share of security pros who believe their personal data is at risk
20%: Percentage of practitioners who say their SecOps practices are
mature
31%: Percentage of security leaders who say lack of visibility of
sensitive data is a compliance concern
$4.6 million: Average cost to recover from a cyberattack for
organizations with more than $1 billion in revenue
97%: Percentage of financial services pros who worry about third-party
risk
34%: Percentage of IT pros who questioned disclosing accidental data
breaches
$21 billion: Amount organizations will spend on managed security
service providers in 2019
Prepare for growing regulations
29
Privacy & Security Frameworks
Regulatory Non Regulatory
CMMC ISO
GDPR
CCPA
SOC
Current compliance landscape
31
01 Financial Services 02 Privacy 03 Federal 04 Healthcare
PCI DSS
GDPR, CCPA,
state privacy
regulations
CMMC, NIST HIPAA
32
Security Privacy
● $4.6 million: Avg. cost of cyber attack
recovery for $1B+ businesses
● 97%: Financial services pros worried
about 3rd-party risk
● 31%: Security leaders who say lack of
visibility of sensitive data is a compliance
concern
● 34%: IT pros who questioned disclosing
accidental data breaches
33
4th Party Regulation
Define Risk
Clarify
Standards
Create
Transparency
Demonstrate
Trust
34
Growing Concerns
→ $4.6 million: Avg. cost of cyber attack
recovery for $1B+ businesses
→ 97%: Financial services pros worried about
3rd-party risk
→ 82%: Nations with privacy regulations to
protect consumer data
→ 31%: Security leaders who say lack of
visibility of sensitive data is a compliance
concern
Source: Merrill Research for Radware, BitSight and CeFPro, Censuswide for Panaseer
Standards… and more standards!
Growing Regulations
→ 280 cybersecurity bills introduced in
2020 in the U.S. alone
→ First time the OCC, Fed, and the FDIC
proposed unified guidance for the
banking industry - around managing 3rd
party relationships
→ CMMC required for all DOD 3rd parties
and supply chain by 2026
Growing Regulations -
● 280 Cybersecurity Bills Introduced in
2020 in the U.S. alone
● First time the OCC, Fed and the FDIC
proposed unified guidance for the
banking industry - around managing 3rd
party relationships
● CMMC required for all DOD 3rd parties
and supply chain by 2026
35
Standards, Frameworks, and Best Practices
36
Financial Services Privacy Federal Healthcare
→ PCI DSS → GDPR
→ CCPA
→ State privacy
regulations
→ CMMC
→ FedRAMP
→ NIST
→ HIPAA
→ HITRUST

More Related Content

What's hot

Staying ahead in the cyber security game - Sogeti + IBM
Staying ahead in the cyber security game - Sogeti + IBMStaying ahead in the cyber security game - Sogeti + IBM
Staying ahead in the cyber security game - Sogeti + IBMRick Bouter
 
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Sydney: Identity Management  - A Strategic OpportunityIdentity Live Sydney: Identity Management  - A Strategic Opportunity
Identity Live Sydney: Identity Management - A Strategic OpportunityForgeRock
 
Digital Transformation ROI
Digital Transformation ROIDigital Transformation ROI
Digital Transformation ROIKevin Sigliano
 
Digital economy and its effect on cyber risk
Digital economy and its effect on cyber riskDigital economy and its effect on cyber risk
Digital economy and its effect on cyber riskaakash malhotra
 
Data Analytics is Driving The Business Forward
Data Analytics is Driving The Business ForwardData Analytics is Driving The Business Forward
Data Analytics is Driving The Business ForwardIDG
 
Final 2021 security_priorities_infographic (1)
Final 2021 security_priorities_infographic (1)Final 2021 security_priorities_infographic (1)
Final 2021 security_priorities_infographic (1)IDG
 
Microsoft to Acquire LinkedIn: Overview for Investors
Microsoft to Acquire LinkedIn: Overview for InvestorsMicrosoft to Acquire LinkedIn: Overview for Investors
Microsoft to Acquire LinkedIn: Overview for InvestorsMicrosoft
 
Salesforce Basecamp Helsinki 8.5.2018 - Boston Consulting Group
Salesforce Basecamp Helsinki 8.5.2018 - Boston Consulting GroupSalesforce Basecamp Helsinki 8.5.2018 - Boston Consulting Group
Salesforce Basecamp Helsinki 8.5.2018 - Boston Consulting GroupSalesforce Finland
 
State of the CIO 2018 Infographic
State of the CIO 2018 InfographicState of the CIO 2018 Infographic
State of the CIO 2018 InfographicIDG
 
2020 IDG Role & Influence of the Technology Decision-Maker
2020 IDG Role & Influence of the Technology Decision-Maker2020 IDG Role & Influence of the Technology Decision-Maker
2020 IDG Role & Influence of the Technology Decision-MakerIDG
 
10 WealthTech podcasts every wealth advisor should listen to
10 WealthTech podcasts every wealth advisor should listen to10 WealthTech podcasts every wealth advisor should listen to
10 WealthTech podcasts every wealth advisor should listen toIBM Analytics
 
Understanding the Data & Analytics Specific Purchase Process [Infographic]
Understanding the Data & Analytics Specific Purchase Process [Infographic]Understanding the Data & Analytics Specific Purchase Process [Infographic]
Understanding the Data & Analytics Specific Purchase Process [Infographic]IDG
 
The Digital Shift in Financial Services
The Digital Shift in Financial ServicesThe Digital Shift in Financial Services
The Digital Shift in Financial ServicesTrustmarque
 
CWIN17 telford gdpr or how to eat the elephant a bit at a time - andy powell
CWIN17 telford   gdpr or how to eat the elephant a bit at a time - andy powellCWIN17 telford   gdpr or how to eat the elephant a bit at a time - andy powell
CWIN17 telford gdpr or how to eat the elephant a bit at a time - andy powellCapgemini
 
Accenture Security CG&S Cyber Resilience
Accenture Security CG&S Cyber ResilienceAccenture Security CG&S Cyber Resilience
Accenture Security CG&S Cyber Resilienceaccenture
 
How SaaS Provide Powerful Competitive Advantage To Industries
How SaaS Provide Powerful  Competitive Advantage To IndustriesHow SaaS Provide Powerful  Competitive Advantage To Industries
How SaaS Provide Powerful Competitive Advantage To IndustriesChandan Kumar
 
2018 IDG Customer Engagement Study
2018 IDG Customer Engagement Study2018 IDG Customer Engagement Study
2018 IDG Customer Engagement StudyIDG
 
2018 Global State of Information Security Survey
2018 Global State of Information Security Survey2018 Global State of Information Security Survey
2018 Global State of Information Security SurveyIDG
 
CSO Pandemic Impact Survey, 2020
CSO Pandemic Impact Survey, 2020CSO Pandemic Impact Survey, 2020
CSO Pandemic Impact Survey, 2020IDG
 

What's hot (20)

Staying ahead in the cyber security game - Sogeti + IBM
Staying ahead in the cyber security game - Sogeti + IBMStaying ahead in the cyber security game - Sogeti + IBM
Staying ahead in the cyber security game - Sogeti + IBM
 
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Sydney: Identity Management  - A Strategic OpportunityIdentity Live Sydney: Identity Management  - A Strategic Opportunity
Identity Live Sydney: Identity Management - A Strategic Opportunity
 
Digital Transformation ROI
Digital Transformation ROIDigital Transformation ROI
Digital Transformation ROI
 
Digital economy and its effect on cyber risk
Digital economy and its effect on cyber riskDigital economy and its effect on cyber risk
Digital economy and its effect on cyber risk
 
Data Analytics is Driving The Business Forward
Data Analytics is Driving The Business ForwardData Analytics is Driving The Business Forward
Data Analytics is Driving The Business Forward
 
Final 2021 security_priorities_infographic (1)
Final 2021 security_priorities_infographic (1)Final 2021 security_priorities_infographic (1)
Final 2021 security_priorities_infographic (1)
 
Microsoft to Acquire LinkedIn: Overview for Investors
Microsoft to Acquire LinkedIn: Overview for InvestorsMicrosoft to Acquire LinkedIn: Overview for Investors
Microsoft to Acquire LinkedIn: Overview for Investors
 
Salesforce Basecamp Helsinki 8.5.2018 - Boston Consulting Group
Salesforce Basecamp Helsinki 8.5.2018 - Boston Consulting GroupSalesforce Basecamp Helsinki 8.5.2018 - Boston Consulting Group
Salesforce Basecamp Helsinki 8.5.2018 - Boston Consulting Group
 
State of the CIO 2018 Infographic
State of the CIO 2018 InfographicState of the CIO 2018 Infographic
State of the CIO 2018 Infographic
 
2020 IDG Role & Influence of the Technology Decision-Maker
2020 IDG Role & Influence of the Technology Decision-Maker2020 IDG Role & Influence of the Technology Decision-Maker
2020 IDG Role & Influence of the Technology Decision-Maker
 
10 WealthTech podcasts every wealth advisor should listen to
10 WealthTech podcasts every wealth advisor should listen to10 WealthTech podcasts every wealth advisor should listen to
10 WealthTech podcasts every wealth advisor should listen to
 
Understanding the Data & Analytics Specific Purchase Process [Infographic]
Understanding the Data & Analytics Specific Purchase Process [Infographic]Understanding the Data & Analytics Specific Purchase Process [Infographic]
Understanding the Data & Analytics Specific Purchase Process [Infographic]
 
The Digital Shift in Financial Services
The Digital Shift in Financial ServicesThe Digital Shift in Financial Services
The Digital Shift in Financial Services
 
How to build a digital insurance company
How to build a digital insurance companyHow to build a digital insurance company
How to build a digital insurance company
 
CWIN17 telford gdpr or how to eat the elephant a bit at a time - andy powell
CWIN17 telford   gdpr or how to eat the elephant a bit at a time - andy powellCWIN17 telford   gdpr or how to eat the elephant a bit at a time - andy powell
CWIN17 telford gdpr or how to eat the elephant a bit at a time - andy powell
 
Accenture Security CG&S Cyber Resilience
Accenture Security CG&S Cyber ResilienceAccenture Security CG&S Cyber Resilience
Accenture Security CG&S Cyber Resilience
 
How SaaS Provide Powerful Competitive Advantage To Industries
How SaaS Provide Powerful  Competitive Advantage To IndustriesHow SaaS Provide Powerful  Competitive Advantage To Industries
How SaaS Provide Powerful Competitive Advantage To Industries
 
2018 IDG Customer Engagement Study
2018 IDG Customer Engagement Study2018 IDG Customer Engagement Study
2018 IDG Customer Engagement Study
 
2018 Global State of Information Security Survey
2018 Global State of Information Security Survey2018 Global State of Information Security Survey
2018 Global State of Information Security Survey
 
CSO Pandemic Impact Survey, 2020
CSO Pandemic Impact Survey, 2020CSO Pandemic Impact Survey, 2020
CSO Pandemic Impact Survey, 2020
 

Similar to Secrets of the Enterprise Buyers with Plaid's Global Finance Lead and Laika's Co-founder

Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...Burton Lee
 
Maintain data privacy during software development
Maintain data privacy during software developmentMaintain data privacy during software development
Maintain data privacy during software developmentMuhammadArif823
 
Privacy 2020: Recap & Predictions
Privacy 2020: Recap & PredictionsPrivacy 2020: Recap & Predictions
Privacy 2020: Recap & PredictionsTrustArc
 
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy ComplianceCorporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy ComplianceFinancial Poise
 
Security, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightSecurity, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightN-iX
 
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...TrustArc
 
What trends will 2018 bring for Business Continuity Professionals?
What trends will 2018 bring for Business Continuity Professionals?What trends will 2018 bring for Business Continuity Professionals?
What trends will 2018 bring for Business Continuity Professionals?PECB
 
Navigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryNavigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryCitrin Cooperman
 
7th ERM - S2 - Cyber security, Cyber Risk and Data Privacy - Kalpesh Doshi (1...
7th ERM - S2 - Cyber security, Cyber Risk and Data Privacy - Kalpesh Doshi (1...7th ERM - S2 - Cyber security, Cyber Risk and Data Privacy - Kalpesh Doshi (1...
7th ERM - S2 - Cyber security, Cyber Risk and Data Privacy - Kalpesh Doshi (1...TraintechTde
 
New regulations and the evolving cybersecurity technology landscape
New regulations and the evolving cybersecurity technology landscapeNew regulations and the evolving cybersecurity technology landscape
New regulations and the evolving cybersecurity technology landscapeUlf Mattsson
 
2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy ManagementTrustArc
 
Corum group: Paris Presentation
Corum group: Paris PresentationCorum group: Paris Presentation
Corum group: Paris PresentationYoussef Rahoui
 
Corporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber SecurityCorporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber SecurityJoan Weber
 
The Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOTThe Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOTCompliancy Group
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 
Managing Consumer Data Privacy
Managing Consumer Data PrivacyManaging Consumer Data Privacy
Managing Consumer Data PrivacyGigya
 
Matt_Cyber Security Core Deck September 2016.pptx
Matt_Cyber Security Core Deck September 2016.pptxMatt_Cyber Security Core Deck September 2016.pptx
Matt_Cyber Security Core Deck September 2016.pptxNakhoudah
 
A holistic approach to risk management 20210210 w acfe france & cyber rea...
A holistic approach to risk management 20210210 w acfe france & cyber rea...A holistic approach to risk management 20210210 w acfe france & cyber rea...
A holistic approach to risk management 20210210 w acfe france & cyber rea...Judith Beckhard Cardoso
 
Envisioning the Future of Law: Critical Lessons from the 2020 Legal Trends Re...
Envisioning the Future of Law: Critical Lessons from the 2020 Legal Trends Re...Envisioning the Future of Law: Critical Lessons from the 2020 Legal Trends Re...
Envisioning the Future of Law: Critical Lessons from the 2020 Legal Trends Re...Clio - Cloud-Based Legal Technology
 

Similar to Secrets of the Enterprise Buyers with Plaid's Global Finance Lead and Laika's Co-founder (20)

Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
Marcel van der Heijden - SpeedInvest & Aircloak - EU GDPR & Data Privacy Comp...
 
Maintain data privacy during software development
Maintain data privacy during software developmentMaintain data privacy during software development
Maintain data privacy during software development
 
Privacy 2020: Recap & Predictions
Privacy 2020: Recap & PredictionsPrivacy 2020: Recap & Predictions
Privacy 2020: Recap & Predictions
 
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy ComplianceCorporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
 
Security, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightSecurity, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it right
 
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
 
What trends will 2018 bring for Business Continuity Professionals?
What trends will 2018 bring for Business Continuity Professionals?What trends will 2018 bring for Business Continuity Professionals?
What trends will 2018 bring for Business Continuity Professionals?
 
Navigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryNavigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services Industry
 
7th ERM - S2 - Cyber security, Cyber Risk and Data Privacy - Kalpesh Doshi (1...
7th ERM - S2 - Cyber security, Cyber Risk and Data Privacy - Kalpesh Doshi (1...7th ERM - S2 - Cyber security, Cyber Risk and Data Privacy - Kalpesh Doshi (1...
7th ERM - S2 - Cyber security, Cyber Risk and Data Privacy - Kalpesh Doshi (1...
 
New regulations and the evolving cybersecurity technology landscape
New regulations and the evolving cybersecurity technology landscapeNew regulations and the evolving cybersecurity technology landscape
New regulations and the evolving cybersecurity technology landscape
 
2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management
 
Corum group: Paris Presentation
Corum group: Paris PresentationCorum group: Paris Presentation
Corum group: Paris Presentation
 
Corporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber SecurityCorporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber Security
 
Data Privacy Compliance
Data Privacy ComplianceData Privacy Compliance
Data Privacy Compliance
 
The Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOTThe Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOT
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
Managing Consumer Data Privacy
Managing Consumer Data PrivacyManaging Consumer Data Privacy
Managing Consumer Data Privacy
 
Matt_Cyber Security Core Deck September 2016.pptx
Matt_Cyber Security Core Deck September 2016.pptxMatt_Cyber Security Core Deck September 2016.pptx
Matt_Cyber Security Core Deck September 2016.pptx
 
A holistic approach to risk management 20210210 w acfe france & cyber rea...
A holistic approach to risk management 20210210 w acfe france & cyber rea...A holistic approach to risk management 20210210 w acfe france & cyber rea...
A holistic approach to risk management 20210210 w acfe france & cyber rea...
 
Envisioning the Future of Law: Critical Lessons from the 2020 Legal Trends Re...
Envisioning the Future of Law: Critical Lessons from the 2020 Legal Trends Re...Envisioning the Future of Law: Critical Lessons from the 2020 Legal Trends Re...
Envisioning the Future of Law: Critical Lessons from the 2020 Legal Trends Re...
 

More from saastr

Workshop Wednesdays with Jason Lemkin, CEO @ SaaStr
Workshop Wednesdays  with Jason Lemkin, CEO @ SaaStrWorkshop Wednesdays  with Jason Lemkin, CEO @ SaaStr
Workshop Wednesdays with Jason Lemkin, CEO @ SaaStrsaastr
 
Workshop Wednesday with HyperGrowth Partners
Workshop Wednesday with HyperGrowth PartnersWorkshop Wednesday with HyperGrowth Partners
Workshop Wednesday with HyperGrowth Partnerssaastr
 
SaaStr Workshop Wednesday with CEO of Guru
SaaStr Workshop Wednesday with CEO of GuruSaaStr Workshop Wednesday with CEO of Guru
SaaStr Workshop Wednesday with CEO of Gurusaastr
 
SaaStr Workshop Wednesdays - RevenueCat.pdf
SaaStr Workshop Wednesdays - RevenueCat.pdfSaaStr Workshop Wednesdays - RevenueCat.pdf
SaaStr Workshop Wednesdays - RevenueCat.pdfsaastr
 
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, YardstickSaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, Yardsticksaastr
 
SaaStr Workshop Wednesday w: Jason Lemkin, SaaStr
SaaStr Workshop Wednesday w: Jason Lemkin, SaaStrSaaStr Workshop Wednesday w: Jason Lemkin, SaaStr
SaaStr Workshop Wednesday w: Jason Lemkin, SaaStrsaastr
 
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.comSaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.comsaastr
 
SaaStr Workshop Wednesdays: Top 5 Lessons Learned from Databricks' Journey fr...
SaaStr Workshop Wednesdays: Top 5 Lessons Learned from Databricks' Journey fr...SaaStr Workshop Wednesdays: Top 5 Lessons Learned from Databricks' Journey fr...
SaaStr Workshop Wednesdays: Top 5 Lessons Learned from Databricks' Journey fr...saastr
 
SaaStr Workshop Wednesdays: What I Learned Selling My Company: Insights into ...
SaaStr Workshop Wednesdays: What I Learned Selling My Company: Insights into ...SaaStr Workshop Wednesdays: What I Learned Selling My Company: Insights into ...
SaaStr Workshop Wednesdays: What I Learned Selling My Company: Insights into ...saastr
 
SaaStr Workshop Wednesdays: From Operator to Founder: What I’m Learning as a ...
SaaStr Workshop Wednesdays: From Operator to Founder: What I’m Learning as a ...SaaStr Workshop Wednesdays: From Operator to Founder: What I’m Learning as a ...
SaaStr Workshop Wednesdays: From Operator to Founder: What I’m Learning as a ...saastr
 
SaaStr Workshop Wednesdays - 10 Things Founders Should Know About Getting Acq...
SaaStr Workshop Wednesdays - 10 Things Founders Should Know About Getting Acq...SaaStr Workshop Wednesdays - 10 Things Founders Should Know About Getting Acq...
SaaStr Workshop Wednesdays - 10 Things Founders Should Know About Getting Acq...saastr
 
SaaStr Workshop Wednesdays: Pricing and Packaging for AI Products with Unusua...
SaaStr Workshop Wednesdays: Pricing and Packaging for AI Products with Unusua...SaaStr Workshop Wednesdays: Pricing and Packaging for AI Products with Unusua...
SaaStr Workshop Wednesdays: Pricing and Packaging for AI Products with Unusua...saastr
 
SaaStr Workshop Wednesdays - From the Other Side: Advice from a Founder-Turne...
SaaStr Workshop Wednesdays - From the Other Side: Advice from a Founder-Turne...SaaStr Workshop Wednesdays - From the Other Side: Advice from a Founder-Turne...
SaaStr Workshop Wednesdays - From the Other Side: Advice from a Founder-Turne...saastr
 
SaaStr Workshop Wednesdays: Territory Assignment Innovation: High-Velocity Te...
SaaStr Workshop Wednesdays: Territory Assignment Innovation: High-Velocity Te...SaaStr Workshop Wednesdays: Territory Assignment Innovation: High-Velocity Te...
SaaStr Workshop Wednesdays: Territory Assignment Innovation: High-Velocity Te...saastr
 
SaaStr Workshop Wednesdays: How to Build Out an SDR Function
SaaStr Workshop Wednesdays: How to Build Out an SDR FunctionSaaStr Workshop Wednesdays: How to Build Out an SDR Function
SaaStr Workshop Wednesdays: How to Build Out an SDR Functionsaastr
 
Workshop Wednesdays: Customer Service Part 2: AMA with Jason and Nick
Workshop Wednesdays: Customer Service Part 2: AMA with Jason and NickWorkshop Wednesdays: Customer Service Part 2: AMA with Jason and Nick
Workshop Wednesdays: Customer Service Part 2: AMA with Jason and Nicksaastr
 
SaaStr Workshop Wednesdays: Dropbox, Klaviyo, Lightspeed Commerce: 10 Things ...
SaaStr Workshop Wednesdays: Dropbox, Klaviyo, Lightspeed Commerce: 10 Things ...SaaStr Workshop Wednesdays: Dropbox, Klaviyo, Lightspeed Commerce: 10 Things ...
SaaStr Workshop Wednesdays: Dropbox, Klaviyo, Lightspeed Commerce: 10 Things ...saastr
 
Special Workshop Tuesday: The Future of Customer Success in 2024 with Gainsig...
Special Workshop Tuesday: The Future of Customer Success in 2024 with Gainsig...Special Workshop Tuesday: The Future of Customer Success in 2024 with Gainsig...
Special Workshop Tuesday: The Future of Customer Success in 2024 with Gainsig...saastr
 
SaaStr Workshop Wednesdays: Lessons (Un)Learned: Successes and Setbacks on th...
SaaStr Workshop Wednesdays: Lessons (Un)Learned: Successes and Setbacks on th...SaaStr Workshop Wednesdays: Lessons (Un)Learned: Successes and Setbacks on th...
SaaStr Workshop Wednesdays: Lessons (Un)Learned: Successes and Setbacks on th...saastr
 
SaaStr Workshop Wednesdays: State of SaaS with Altimeter Capital
SaaStr Workshop Wednesdays: State of SaaS with Altimeter CapitalSaaStr Workshop Wednesdays: State of SaaS with Altimeter Capital
SaaStr Workshop Wednesdays: State of SaaS with Altimeter Capitalsaastr
 

More from saastr (20)

Workshop Wednesdays with Jason Lemkin, CEO @ SaaStr
Workshop Wednesdays  with Jason Lemkin, CEO @ SaaStrWorkshop Wednesdays  with Jason Lemkin, CEO @ SaaStr
Workshop Wednesdays with Jason Lemkin, CEO @ SaaStr
 
Workshop Wednesday with HyperGrowth Partners
Workshop Wednesday with HyperGrowth PartnersWorkshop Wednesday with HyperGrowth Partners
Workshop Wednesday with HyperGrowth Partners
 
SaaStr Workshop Wednesday with CEO of Guru
SaaStr Workshop Wednesday with CEO of GuruSaaStr Workshop Wednesday with CEO of Guru
SaaStr Workshop Wednesday with CEO of Guru
 
SaaStr Workshop Wednesdays - RevenueCat.pdf
SaaStr Workshop Wednesdays - RevenueCat.pdfSaaStr Workshop Wednesdays - RevenueCat.pdf
SaaStr Workshop Wednesdays - RevenueCat.pdf
 
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, YardstickSaaStr Workshop Wednesday w/ Lucas Price, Yardstick
SaaStr Workshop Wednesday w/ Lucas Price, Yardstick
 
SaaStr Workshop Wednesday w: Jason Lemkin, SaaStr
SaaStr Workshop Wednesday w: Jason Lemkin, SaaStrSaaStr Workshop Wednesday w: Jason Lemkin, SaaStr
SaaStr Workshop Wednesday w: Jason Lemkin, SaaStr
 
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.comSaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
 
SaaStr Workshop Wednesdays: Top 5 Lessons Learned from Databricks' Journey fr...
SaaStr Workshop Wednesdays: Top 5 Lessons Learned from Databricks' Journey fr...SaaStr Workshop Wednesdays: Top 5 Lessons Learned from Databricks' Journey fr...
SaaStr Workshop Wednesdays: Top 5 Lessons Learned from Databricks' Journey fr...
 
SaaStr Workshop Wednesdays: What I Learned Selling My Company: Insights into ...
SaaStr Workshop Wednesdays: What I Learned Selling My Company: Insights into ...SaaStr Workshop Wednesdays: What I Learned Selling My Company: Insights into ...
SaaStr Workshop Wednesdays: What I Learned Selling My Company: Insights into ...
 
SaaStr Workshop Wednesdays: From Operator to Founder: What I’m Learning as a ...
SaaStr Workshop Wednesdays: From Operator to Founder: What I’m Learning as a ...SaaStr Workshop Wednesdays: From Operator to Founder: What I’m Learning as a ...
SaaStr Workshop Wednesdays: From Operator to Founder: What I’m Learning as a ...
 
SaaStr Workshop Wednesdays - 10 Things Founders Should Know About Getting Acq...
SaaStr Workshop Wednesdays - 10 Things Founders Should Know About Getting Acq...SaaStr Workshop Wednesdays - 10 Things Founders Should Know About Getting Acq...
SaaStr Workshop Wednesdays - 10 Things Founders Should Know About Getting Acq...
 
SaaStr Workshop Wednesdays: Pricing and Packaging for AI Products with Unusua...
SaaStr Workshop Wednesdays: Pricing and Packaging for AI Products with Unusua...SaaStr Workshop Wednesdays: Pricing and Packaging for AI Products with Unusua...
SaaStr Workshop Wednesdays: Pricing and Packaging for AI Products with Unusua...
 
SaaStr Workshop Wednesdays - From the Other Side: Advice from a Founder-Turne...
SaaStr Workshop Wednesdays - From the Other Side: Advice from a Founder-Turne...SaaStr Workshop Wednesdays - From the Other Side: Advice from a Founder-Turne...
SaaStr Workshop Wednesdays - From the Other Side: Advice from a Founder-Turne...
 
SaaStr Workshop Wednesdays: Territory Assignment Innovation: High-Velocity Te...
SaaStr Workshop Wednesdays: Territory Assignment Innovation: High-Velocity Te...SaaStr Workshop Wednesdays: Territory Assignment Innovation: High-Velocity Te...
SaaStr Workshop Wednesdays: Territory Assignment Innovation: High-Velocity Te...
 
SaaStr Workshop Wednesdays: How to Build Out an SDR Function
SaaStr Workshop Wednesdays: How to Build Out an SDR FunctionSaaStr Workshop Wednesdays: How to Build Out an SDR Function
SaaStr Workshop Wednesdays: How to Build Out an SDR Function
 
Workshop Wednesdays: Customer Service Part 2: AMA with Jason and Nick
Workshop Wednesdays: Customer Service Part 2: AMA with Jason and NickWorkshop Wednesdays: Customer Service Part 2: AMA with Jason and Nick
Workshop Wednesdays: Customer Service Part 2: AMA with Jason and Nick
 
SaaStr Workshop Wednesdays: Dropbox, Klaviyo, Lightspeed Commerce: 10 Things ...
SaaStr Workshop Wednesdays: Dropbox, Klaviyo, Lightspeed Commerce: 10 Things ...SaaStr Workshop Wednesdays: Dropbox, Klaviyo, Lightspeed Commerce: 10 Things ...
SaaStr Workshop Wednesdays: Dropbox, Klaviyo, Lightspeed Commerce: 10 Things ...
 
Special Workshop Tuesday: The Future of Customer Success in 2024 with Gainsig...
Special Workshop Tuesday: The Future of Customer Success in 2024 with Gainsig...Special Workshop Tuesday: The Future of Customer Success in 2024 with Gainsig...
Special Workshop Tuesday: The Future of Customer Success in 2024 with Gainsig...
 
SaaStr Workshop Wednesdays: Lessons (Un)Learned: Successes and Setbacks on th...
SaaStr Workshop Wednesdays: Lessons (Un)Learned: Successes and Setbacks on th...SaaStr Workshop Wednesdays: Lessons (Un)Learned: Successes and Setbacks on th...
SaaStr Workshop Wednesdays: Lessons (Un)Learned: Successes and Setbacks on th...
 
SaaStr Workshop Wednesdays: State of SaaS with Altimeter Capital
SaaStr Workshop Wednesdays: State of SaaS with Altimeter CapitalSaaStr Workshop Wednesdays: State of SaaS with Altimeter Capital
SaaStr Workshop Wednesdays: State of SaaS with Altimeter Capital
 

Recently uploaded

5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographerofm712785
 
Evolution and Growth of Supply chain.pdf
Evolution and Growth of Supply chain.pdfEvolution and Growth of Supply chain.pdf
Evolution and Growth of Supply chain.pdfGutaMengesha1
 
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
8 Questions B2B Commercial Teams Can Ask To Help Product DiscoveryDesmond Leo
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiaFalcon Invoice Discounting
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanasabutalha2013
 
USA classified ads posting – best classified sites in usa.pdf
USA classified ads posting – best classified sites in usa.pdfUSA classified ads posting – best classified sites in usa.pdf
USA classified ads posting – best classified sites in usa.pdfsuperbizness1227
 
HR and Employment law update: May 2024.
HR and Employment law update:  May 2024.HR and Employment law update:  May 2024.
HR and Employment law update: May 2024.FelixPerez547899
 
Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024Equinox Gold Corp.
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small businessBen Wann
 
Understanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and EmployeesUnderstanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and EmployeesDragon Dream Bar
 
NewBase 24 May 2024 Energy News issue - 1727 by Khaled Al Awadi_compresse...
NewBase   24 May  2024  Energy News issue - 1727 by Khaled Al Awadi_compresse...NewBase   24 May  2024  Energy News issue - 1727 by Khaled Al Awadi_compresse...
NewBase 24 May 2024 Energy News issue - 1727 by Khaled Al Awadi_compresse...Khaled Al Awadi
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134LR1709MUSIC
 
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxTaurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxmy Pandit
 
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case StudyTransforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case StudyPMaps Assessments
 
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...ssuserf63bd7
 
Luxury Artificial Plants Dubai | Plants in KSA, UAE | Shajara
Luxury Artificial Plants Dubai | Plants in KSA, UAE | ShajaraLuxury Artificial Plants Dubai | Plants in KSA, UAE | Shajara
Luxury Artificial Plants Dubai | Plants in KSA, UAE | ShajaraShajara Artificial Plants
 
The Inspiring Personality To Watch In 2024.pdf
The Inspiring Personality To Watch In 2024.pdfThe Inspiring Personality To Watch In 2024.pdf
The Inspiring Personality To Watch In 2024.pdfinsightssuccess2
 
India’s Recommended Women Surgeons to Watch in 2024.pdf
India’s Recommended Women Surgeons to Watch in 2024.pdfIndia’s Recommended Women Surgeons to Watch in 2024.pdf
India’s Recommended Women Surgeons to Watch in 2024.pdfCIOLOOKIndia
 
Matt Conway - Attorney - A Knowledgeable Professional - Kentucky.pdf
Matt Conway - Attorney - A Knowledgeable Professional - Kentucky.pdfMatt Conway - Attorney - A Knowledgeable Professional - Kentucky.pdf
Matt Conway - Attorney - A Knowledgeable Professional - Kentucky.pdfMatt Conway - Attorney
 
TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024Adnet Communications
 

Recently uploaded (20)

5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer
 
Evolution and Growth of Supply chain.pdf
Evolution and Growth of Supply chain.pdfEvolution and Growth of Supply chain.pdf
Evolution and Growth of Supply chain.pdf
 
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
8 Questions B2B Commercial Teams Can Ask To Help Product Discovery
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about venice
 
USA classified ads posting – best classified sites in usa.pdf
USA classified ads posting – best classified sites in usa.pdfUSA classified ads posting – best classified sites in usa.pdf
USA classified ads posting – best classified sites in usa.pdf
 
HR and Employment law update: May 2024.
HR and Employment law update:  May 2024.HR and Employment law update:  May 2024.
HR and Employment law update: May 2024.
 
Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
 
Understanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and EmployeesUnderstanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and Employees
 
NewBase 24 May 2024 Energy News issue - 1727 by Khaled Al Awadi_compresse...
NewBase   24 May  2024  Energy News issue - 1727 by Khaled Al Awadi_compresse...NewBase   24 May  2024  Energy News issue - 1727 by Khaled Al Awadi_compresse...
NewBase 24 May 2024 Energy News issue - 1727 by Khaled Al Awadi_compresse...
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134
 
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxTaurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
 
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case StudyTransforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
 
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
 
Luxury Artificial Plants Dubai | Plants in KSA, UAE | Shajara
Luxury Artificial Plants Dubai | Plants in KSA, UAE | ShajaraLuxury Artificial Plants Dubai | Plants in KSA, UAE | Shajara
Luxury Artificial Plants Dubai | Plants in KSA, UAE | Shajara
 
The Inspiring Personality To Watch In 2024.pdf
The Inspiring Personality To Watch In 2024.pdfThe Inspiring Personality To Watch In 2024.pdf
The Inspiring Personality To Watch In 2024.pdf
 
India’s Recommended Women Surgeons to Watch in 2024.pdf
India’s Recommended Women Surgeons to Watch in 2024.pdfIndia’s Recommended Women Surgeons to Watch in 2024.pdf
India’s Recommended Women Surgeons to Watch in 2024.pdf
 
Matt Conway - Attorney - A Knowledgeable Professional - Kentucky.pdf
Matt Conway - Attorney - A Knowledgeable Professional - Kentucky.pdfMatt Conway - Attorney - A Knowledgeable Professional - Kentucky.pdf
Matt Conway - Attorney - A Knowledgeable Professional - Kentucky.pdf
 
TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024TriStar Gold Corporate Presentation May 2024
TriStar Gold Corporate Presentation May 2024
 

Secrets of the Enterprise Buyers with Plaid's Global Finance Lead and Laika's Co-founder

  • 1. DAN KAHN Global Open Finance Lead Plaid EVA PITTAS Founder, COO Laika The Secrets of Enterprise Buyers
  • 2. Closing Enterprise Deals What to expect when you’re expecting a deal
  • 3. The first deal is the hardest to close 01 Identify your champion 02 Provide product access 03 React to feedback quickly 04 Provide data to support ROI 05 Demonstrate commitment to security 3
  • 5. 5 BEFORE: Bilateral Relationship Business owners care about business results
  • 6. NOW: Multilateral with Multiple Gatekeepers 6 Business owners care about business results Gatekeepers predominantly care about complying with regulations & managing risk
  • 7. You closed the deal. Now what? Continuous compliance. Or risk being replaced. 7 → Ongoing diligence driven by criticality and risk rating of 3rd party → Incident-driven diligence
  • 8. → More scrutiny over 4th Parties → Cloud Security Certification specifications → Continuous Monitoring requirements 8 What’s coming?
  • 9. Signing a deal is only the start of your compliance journey. Maturing enterprise relationships and the ever-changing compliance landscape means that your compliance posture needs to continuously evolve. 9 Being enterprise-ready never ends
  • 10. Demonstrating Trust through the procurement process
  • 12. Growing Concerns Growing Regulations → $4.6 million: Avg. cost of cyber attack recovery for $1B+ businesses → 97%: Financial services pros worried about 3rd-party risk → 82%: Nations with privacy regulations to protect consumer data → 31%: Security leaders who say lack of visibility of sensitive data is a compliance concern → 280 cybersecurity bills introduced in 2020 in the U.S. alone → First time the OCC, Fed, and the FDIC proposed unified guidance for the banking industry - around managing 3rd party relationships → CMMC required for all DOD 3rd parties and supply chain by 2026 12 Regulations… and more regulations!
  • 13. Due diligence and security questionnaires keep coming. Even after audit. → Industry needs to standardize compliance → Businesses need to customize compliance 13 SOC 2 is ubiquitous. Why do we still need to answer security questionnaires? SOC 2 + CC 3.4 The entity identifies and assesses changes that could significantly impact the system of internal control. DDQ + I.2.3 Are applications released to production on a fixed schedule? Identify the schedule.
  • 15. 15 // The emerging fintech ecosystem includes thousands of nodes connecting banks to fintechs
  • 16. 16 // The emerging fintech ecosystem includes thousands of nodes connecting banks to fintechs FINANCIAL INSTITUTIONS 11,000 financial institutions (US, Canada, Europe)
  • 17. 17 // The emerging fintech ecosystem includes thousands of nodes connecting banks to fintechs DIGITAL APPLICATIONS & SERVICES 5,000+ applications built on Plaid
  • 18. 18 // The emerging fintech ecosystem includes thousands of nodes connecting banks to fintechs DIGITAL APPLICATIONS & SERVICES 5,000+ applications built on Plaid FINANCIAL INSTITUTIONS 11,000 financial institutions (US, Canada, Europe)
  • 19. Emerging data security standards 19 → Plaid and Laika, alongside our industry competitors are developing a new Open Finance Data Security Standard (OFDSS) → Industry-driven proposal to enhance data security in the fintech ecosystem and foster responsible innovation → Security framework optimized for cloud-native, tech-focused startups and growth-stage companies
  • 20. Takeaways 20 Check-the-box security won’t land and retain enterprise deals The bar for infosec and data privacy is already high--but rising with calls for vertical-specific, actionable guidelines and continuous monitoring Security and Compliance should be a permanent business function enabling responsible innovation and building trust in the marketplace 01 02 03
  • 23. Current compliance landscape 01 Financial Services 02 Privacy 03 Federal 04 Healthcare 25
  • 24. Current compliance landscape 01 Financial Services 02 Privacy 03 Federal 04 Healthcare 27
  • 25. Prepare for growing regulations 28 Industry wants to standardize security and businesses need to customize security Top 4 Cybersecurity frameworks Nist: 29% CIS: 32% ISO: 35% PCI DSS: 47% 90%: Share of security pros who believe their personal data is at risk 20%: Percentage of practitioners who say their SecOps practices are mature 31%: Percentage of security leaders who say lack of visibility of sensitive data is a compliance concern $4.6 million: Average cost to recover from a cyberattack for organizations with more than $1 billion in revenue 97%: Percentage of financial services pros who worry about third-party risk 34%: Percentage of IT pros who questioned disclosing accidental data breaches $21 billion: Amount organizations will spend on managed security service providers in 2019
  • 26. Prepare for growing regulations 29 Privacy & Security Frameworks Regulatory Non Regulatory CMMC ISO GDPR CCPA SOC
  • 27. Current compliance landscape 31 01 Financial Services 02 Privacy 03 Federal 04 Healthcare PCI DSS GDPR, CCPA, state privacy regulations CMMC, NIST HIPAA
  • 28. 32 Security Privacy ● $4.6 million: Avg. cost of cyber attack recovery for $1B+ businesses ● 97%: Financial services pros worried about 3rd-party risk ● 31%: Security leaders who say lack of visibility of sensitive data is a compliance concern ● 34%: IT pros who questioned disclosing accidental data breaches
  • 29. 33 4th Party Regulation Define Risk Clarify Standards Create Transparency Demonstrate Trust
  • 30. 34 Growing Concerns → $4.6 million: Avg. cost of cyber attack recovery for $1B+ businesses → 97%: Financial services pros worried about 3rd-party risk → 82%: Nations with privacy regulations to protect consumer data → 31%: Security leaders who say lack of visibility of sensitive data is a compliance concern Source: Merrill Research for Radware, BitSight and CeFPro, Censuswide for Panaseer Standards… and more standards! Growing Regulations → 280 cybersecurity bills introduced in 2020 in the U.S. alone → First time the OCC, Fed, and the FDIC proposed unified guidance for the banking industry - around managing 3rd party relationships → CMMC required for all DOD 3rd parties and supply chain by 2026
  • 31. Growing Regulations - ● 280 Cybersecurity Bills Introduced in 2020 in the U.S. alone ● First time the OCC, Fed and the FDIC proposed unified guidance for the banking industry - around managing 3rd party relationships ● CMMC required for all DOD 3rd parties and supply chain by 2026 35
  • 32. Standards, Frameworks, and Best Practices 36 Financial Services Privacy Federal Healthcare → PCI DSS → GDPR → CCPA → State privacy regulations → CMMC → FedRAMP → NIST → HIPAA → HITRUST

Editor's Notes

  1. Q: What does it look like to close your first enterprise deal?
  2. A: Identify your champion Provide product access React to feedback quickly Measure enterprise ROI Demonstrate commitment to security
  3. Q: who are the four horsemen of procurement? Remember: compliance isn’t just about your internal security, but also about the company you keep (aka your vendors).
  4. OLD WAY: Sell into a company, sign the contract, onboard with procurement NEW WAY: Find a champion, tackle legal & compliance, then information security, then risk. Finally, talk to procurement about pricing and signing the contract. Q: What challenges or documentation will these departments throw your way? Legal & Compliance Information Security Risk: SPEAKER NOTES: You’ll need to face off with Legal, Information Security, Compliance, and Risk to get a signed contract. Each of these departments has veto power and decision-making authority. While each enterprise is different, the heads of each department likely reports directly to the BoD
  5. Annual vendor review Incident driven Continuous monitoring 4th-party Review driven by regulation changes Privacy and data protection in DD Exit strategy is part of the vendor lifecycle - need to have a way to get out if the vendor misses the bar Q: Okay, so what happens after you get the contract signed? How can you keep their business? Periodic diligence Continuous review and monitoring Attention and reporting for SLAs Joint testing of major changes, BCP and/or incident response Being pulled into a regulatory review Maybe we can find a cycle visual for this? REFERENCE: https://www.youtube.com/watch?v=vNpl7nUsWk8 https://www.youtube.com/watch?v=uN-LxfehITU
  6. need for continuous monitoring - impacts who you are as a company and how you do business Reputational risk * Criticality of vendor impacts the number of requirements As your business grows with the enterprise, this process will increase for your business lines - reflective of a good relationship with the enterprise More robust reviews (this is a good thing!) Q: What does the current compliance landscape look like for SaaS businesses? Financial Services Privacy Federal Healthcare SPEAKER NOTES: Financial Services - New proposed interagency guidance for managing 3rd party relationships. First time the Federal Reserve, FDIC and the OCC issued guidance jointly. It is out now for comments. PCI DSS → Privacy - GDPR, CCPA, state privacy regulations. Repealing privacy shield, EU Cookie Directive Federal government - CMMC requirement for all 3rd parties/4th parties working with DOD to be certified by 2026. NIST: new prescriptive framework of choice Increasing difficulty as requirements rise to make this a core capability Health Care - we need to research something about this. Not familiar enough
  7. need for continuous monitoring - impacts who you are as a company and how you do business Reputational risk * Criticality of vendor impacts the number of requirements As your business grows with the enterprise, this process will increase for your business lines - reflective of a good relationship with the enterprise More robust reviews (this is a good thing!) Q: What does the current compliance landscape look like for SaaS businesses? Financial Services Privacy Federal Healthcare SPEAKER NOTES: Financial Services - New proposed interagency guidance for managing 3rd party relationships. First time the Federal Reserve, FDIC and the OCC issued guidance jointly. It is out now for comments. PCI DSS → Privacy - GDPR, CCPA, state privacy regulations. Repealing privacy shield, EU Cookie Directive Federal government - CMMC requirement for all 3rd parties/4th parties working with DOD to be certified by 2026. NIST: new prescriptive framework of choice Increasing difficulty as requirements rise to make this a core capability Health Care - we need to research something about this. Not familiar enough
  8. Used to be trust but verify Now, zero-trust What to expect as a regulated partner
  9. \To cope with the increasing complexity of vendor risks, industries and regulators have developed need for continuous monitoring - impacts who you are as a company and how you do business Reputational risk * Criticality of vendor impacts the number of requirements As your business grows with the enterprise, this process will increase for your business lines - reflective of a good relationship with the enterprise More robust reviews (this is a good thing!) Q: What does the current compliance landscape look like for SaaS businesses? Financial Services Privacy Federal Healthcare SPEAKER NOTES: Financial Services - New proposed interagency guidance for managing 3rd party relationships. First time the Federal Reserve, FDIC and the OCC issued guidance jointly. It is out now for comments. PCI DSS → Privacy - GDPR, CCPA, state privacy regulations. Repealing privacy shield, EU Cookie Directive Federal government - CMMC requirement for all 3rd parties/4th parties working with DOD to be certified by 2026. NIST: new prescriptive framework of choice Increasing difficulty as requirements rise to make this a core capability Health Care - we need to research something about this. Not familiar enough
  10. 25+ different frameworks to consider. Growing regulation list: https://docs.google.com/spreadsheets/d/1SUVWukag0Rcgs_mH9wGeMdYF4EUAd4D8lcOVx8JHla8/edit?usp=sharing 25 different frameworks: https://securityscorecard.com/blog/top-cybersecurity-frameworks-to-consider Rising number of Regulations Cybersecurity & Privacy (e.g. 280 new cybersecurity bills introduced in 2020 alone) Snowball effect Lack of standardization within and across industries Leaves a lot up to interpretation There are attempts to harmonize within industries but this could take years. So, for now SaaS companies should think about InfoSec and Privacy compliance as: Core Capabilities that need to be invested in Programs need to be flexible and adaptable to allow SaaS companies to scale because of : The current landscape and the rising tide And because as your relationship grows, the risk to the enterprise grows. Q: How do we expect 4th parties to be regulated? Define Risk Clarify Standards Create Transparency Demonstrate Trust SPEAKER NOTES: Needs to be something more to offer back to banks in terms of security We need to defining risk - what is an appropriate level of risk for small businesses? Adding clarity around standards and assessments, as well as those who are executing assessments Creating easier flow of information and management of risk through continuous monitoring, integrations, etc. transparently Systems that have data available when it’s needed to answer questions on demand Annual diligence process dependent on criticality of the vendor
  11. Identify the schedule (e.g., Daily, Weekly, Monthly, Ad-hoc) in the Additional Information field. Growing regulation list: https://docs.google.com/spreadsheets/d/1SUVWukag0Rcgs_mH9wGeMdYF4EUAd4D8lcOVx8JHla8/edit?usp=sharing Rising number of Regulations Cybersecurity & Privacy (e.g. 280 new cybersecurity bills introduced in 2020 alone) Snowball effect Lack of standardization within and across industries Leaves a lot up to interpretation There are attempts to harmonize within industries but this could take years. So, for now SaaS companies should think about InfoSec and Privacy compliance as: Core Capabilities that need to be invested in Programs need to be flexible and adaptable to allow SaaS companies to scale because of : The current landscape and the rising tide And because as your relationship grows, the risk to the enterprise grows. Q: How do we expect 4th parties to be regulated? Define Risk Clarify Standards Create Transparency Demonstrate Trust SPEAKER NOTES: Needs to be something more to offer back to banks in terms of security We need to defining risk - what is an appropriate level of risk for small businesses? Adding clarity around standards and assessments, as well as those who are executing assessments Creating easier flow of information and management of risk through continuous monitoring, integrations, etc. transparently Systems that have data available when it’s needed to answer questions on demand Annual diligence process dependent on criticality of the vendor
  12. Q: What advice can you give growing SaaS businesses, looking to move upmarket? -Check the box security won’t work in the long run. Information Security, Privacy compliance is truly a day 1 core capability that will need to grow and mature with your company.
  13. PLAID SLIDE* Our competitors think about compliance as one-size-fits-all but OFDSS and Laika are striving to customize the standards and security posture for growing businesses Eva: New regulations are being introduced at high velocity. What can you share about OFDSS? Dan: When to sell into enterprises depends on your unique business model Similarly, the security programs and risk management you need is dependent on your business model -
  14. Takeaways: industry wants to standardize security and businesses need to customize security Check-the-box security won’t land enterprise deals or scale with you Bar is already high to deal with the federal government, privacy protections are already popular, and PHI needs to be taken seriously (even if it doesn’t require an audit) as industry evolves with increasing scrutiny, we need to uplevel entire ecosystem: through empowering not just the big clients but making it easier for “2 gals in a garage” to access to demonstrate responsibility stage-appropriate examinations along with stage-appropriate security Always going to be some level of scrutiny, doing what we can to create clear guidelines and accessible lanes to growth - informed by real-world participants SPEAKER NOTES: -Check the box security won’t work in the long run. Information Security, Privacy compliance is truly a day 1 core capability that will need to grow and mature with your company. -For FI’s Last Interagency guidance around managing 3rd party relationships was in 2013 and that spurred what is currently in place. -Bar is high already if you want to do biz with the Federal government. FedRAMP already has a continuous monitoring component. But now all vendors (approx. 300,000) who deal with non critical (need to get the right term) will need to be CMMC certified or they will lose their contracts. The gov. Is giving the industry a few years to -Privacy, privacy, privacy -Healthcare? -Need solutions like Laika to help support innovation. - as industry evolves with increasing scrutiny, we need to uplevel entire ecosystem: through empowering not just the big clients but making it easier for “2 gals in a garage” to access to demonstrate responsibility - stage-appropriate examinations along with stage-appropriate security Always going to be some level of scrutiny, doing what we can to create clear guidelines and accessible lanes to growth - informed by real-world participants
  15. 25+ different frameworks to consider. Growing regulation list: https://docs.google.com/spreadsheets/d/1SUVWukag0Rcgs_mH9wGeMdYF4EUAd4D8lcOVx8JHla8/edit?usp=sharing Top 4 Cybersecurity frameworks: https://www.itgovernanceusa.com/blog/top-4-cybersecurity-frameworks 25 different frameworks: https://securityscorecard.com/blog/top-cybersecurity-frameworks-to-consider Rising number of Regulations Cybersecurity & Privacy (e.g. 280 new cybersecurity bills introduced in 2020 alone) Snowball effect Lack of standardization within and across industries Leaves a lot up to interpretation There are attempts to harmonize within industries but this could take years. So, for now SaaS companies should think about InfoSec and Privacy compliance as: Core Capabilities that need to be invested in Programs need to be flexible and adaptable to allow SaaS companies to scale because of : The current landscape and the rising tide And because as your relationship grows, the risk to the enterprise grows. Q: How do we expect 4th parties to be regulated? Define Risk Clarify Standards Create Transparency Demonstrate Trust SPEAKER NOTES: Needs to be something more to offer back to banks in terms of security We need to defining risk - what is an appropriate level of risk for small businesses? Adding clarity around standards and assessments, as well as those who are executing assessments Creating easier flow of information and management of risk through continuous monitoring, integrations, etc. transparently Systems that have data available when it’s needed to answer questions on demand Annual diligence process dependent on criticality of the vendor
  16. Q: What does the current compliance landscape look like for SaaS businesses? SOC 2 is ubiquitous Increasing regulations for SMBs Examining 4th-party relationships SPEAKER NOTES: SOC 2 is becoming ubiquitous for 3rd parties Varying infosec and compliance expectations are increasingly relevant for SMBs Huge increase in diligence questionnaires 4th parties becoming in-scope for diligence and mapping/understanding regulations New guidance was just proposed (OCC, Fed, FDIC) and they are accepting comments from the industry. Expect there to be more requirements especially around continuous monitoring SPEAKER NOTES: Enterprises in the US are requiring SOC 2 audits for practically all 3rd parties, not just those that represent a higher risk Inconsistent and varying info sec and compliance expectations from smaller and medium sized businesses. We have seen an Increase in diligence associated with privacy and data protection regulations 4th parties are increasingly in scope for diligence and understanding the risk in the supply chain New guidance was just proposed (OCC, Fed, FDIC) and they are accepting comments from the industry. Expect there to be more requirements especially around continuous monitoring Even with SOC 2 audits and other certifications, the questionnaires keep coming because SOC 2 audits are not all the same because a companies individual compliance and security program gets tested and written up. That could be 20 controls that are immature or 100 controls that are very mature. There is no easy way to determine that - no tools and transparency.
  17. need for continuous monitoring - impacts who you are as a company and how you do business Reputational risk * Criticality of vendor impacts the number of requirements As your business grows with the enterprise, this process will increase for your business lines - reflective of a good relationship with the enterprise More robust reviews (this is a good thing!) Q: What does the current compliance landscape look like for SaaS businesses? Financial Services Privacy Federal Healthcare SPEAKER NOTES: Financial Services - New proposed interagency guidance for managing 3rd party relationships. First time the Federal Reserve, FDIC and the OCC issued guidance jointly. It is out now for comments. PCI DSS → Privacy - GDPR, CCPA, state privacy regulations. Repealing privacy shield, EU Cookie Directive Federal government - CMMC requirement for all 3rd parties/4th parties working with DOD to be certified by 2026. NIST: new prescriptive framework of choice Increasing difficulty as requirements rise to make this a core capability Health Care - we need to research something about this. Not familiar enough
  18. Q: What does the current compliance landscape look like for SaaS businesses? SOC 2 is ubiquitous Increasing regulations for SMBs Examining 4th-party relationships SPEAKER NOTES: SOC 2 is becoming ubiquitous for 3rd parties Varying infosec and compliance expectations are increasingly relevant for SMBs Huge increase in diligence questionnaires 4th parties becoming in-scope for diligence and mapping/understanding regulations New guidance was just proposed (OCC, Fed, FDIC) and they are accepting comments from the industry. Expect there to be more requirements especially around continuous monitoring SPEAKER NOTES: Enterprises in the US are requiring SOC 2 audits for practically all 3rd parties, not just those that represent a higher risk Inconsistent and varying info sec and compliance expectations from smaller and medium sized businesses. We have seen an Increase in diligence associated with privacy and data protection regulations 4th parties are increasingly in scope for diligence and understanding the risk in the supply chain New guidance was just proposed (OCC, Fed, FDIC) and they are accepting comments from the industry. Expect there to be more requirements especially around continuous monitoring Even with SOC 2 audits and other certifications, the questionnaires keep coming because SOC 2 audits are not all the same because a companies individual compliance and security program gets tested and written up. That could be 20 controls that are immature or 100 controls that are very mature. There is no easy way to determine that - no tools and transparency.
  19. need for continuous monitoring - impacts who you are as a company and how you do business Reputational risk * Criticality of vendor impacts the number of requirements As your business grows with the enterprise, this process will increase for your business lines - reflective of a good relationship with the enterprise More robust reviews (this is a good thing!) Q: What does the current compliance landscape look like for SaaS businesses? Financial Services Privacy Federal Healthcare SPEAKER NOTES: Financial Services - New proposed interagency guidance for managing 3rd party relationships. First time the Federal Reserve, FDIC and the OCC issued guidance jointly. It is out now for comments. PCI DSS → Privacy - GDPR, CCPA, state privacy regulations. Repealing privacy shield, EU Cookie Directive Federal government - CMMC requirement for all 3rd parties/4th parties working with DOD to be certified by 2026. NIST: new prescriptive framework of choice Increasing difficulty as requirements rise to make this a core capability Health Care - we need to research something about this. Not familiar enough
  20. Growing regulation list: https://docs.google.com/spreadsheets/d/1SUVWukag0Rcgs_mH9wGeMdYF4EUAd4D8lcOVx8JHla8/edit?usp=sharing Rising number of Regulations Cybersecurity & Privacy (e.g. 280 new cybersecurity bills introduced in 2020 alone) Snowball effect Lack of standardization within and across industries Leaves a lot up to interpretation There are attempts to harmonize within industries but this could take years. So, for now SaaS companies should think about InfoSec and Privacy compliance as: Core Capabilities that need to be invested in Programs need to be flexible and adaptable to allow SaaS companies to scale because of : The current landscape and the rising tide And because as your relationship grows, the risk to the enterprise grows. Q: How do we expect 4th parties to be regulated? Define Risk Clarify Standards Create Transparency Demonstrate Trust SPEAKER NOTES: Needs to be something more to offer back to banks in terms of security We need to defining risk - what is an appropriate level of risk for small businesses? Adding clarity around standards and assessments, as well as those who are executing assessments Creating easier flow of information and management of risk through continuous monitoring, integrations, etc. transparently Systems that have data available when it’s needed to answer questions on demand Annual diligence process dependent on criticality of the vendor
  21. need for continuous monitoring - impacts who you are as a company and how you do business Reputational risk * Criticality of vendor impacts the number of requirements As your business grows with the enterprise, this process will increase for your business lines - reflective of a good relationship with the enterprise More robust reviews (this is a good thing!) Q: What does the current compliance landscape look like for SaaS businesses? Financial Services Privacy Federal Healthcare SPEAKER NOTES: Financial Services - New proposed interagency guidance for managing 3rd party relationships. First time the Federal Reserve, FDIC and the OCC issued guidance jointly. It is out now for comments. PCI DSS → Privacy - GDPR, CCPA, state privacy regulations. Repealing privacy shield, EU Cookie Directive Federal government - CMMC requirement for all 3rd parties/4th parties working with DOD to be certified by 2026. NIST: new prescriptive framework of choice Increasing difficulty as requirements rise to make this a core capability Health Care - we need to research something about this. Not familiar enough
  22. 25+ different frameworks to consider. Growing regulation list: https://docs.google.com/spreadsheets/d/1SUVWukag0Rcgs_mH9wGeMdYF4EUAd4D8lcOVx8JHla8/edit?usp=sharing Top 4 Cybersecurity frameworks: https://www.itgovernanceusa.com/blog/top-4-cybersecurity-frameworks 25 different frameworks: https://securityscorecard.com/blog/top-cybersecurity-frameworks-to-consider Rising number of Regulations Cybersecurity & Privacy (e.g. 280 new cybersecurity bills introduced in 2020 alone) Snowball effect Lack of standardization within and across industries Leaves a lot up to interpretation There are attempts to harmonize within industries but this could take years. So, for now SaaS companies should think about InfoSec and Privacy compliance as: Core Capabilities that need to be invested in Programs need to be flexible and adaptable to allow SaaS companies to scale because of : The current landscape and the rising tide And because as your relationship grows, the risk to the enterprise grows. Q: How do we expect 4th parties to be regulated? Define Risk Clarify Standards Create Transparency Demonstrate Trust SPEAKER NOTES: Needs to be something more to offer back to banks in terms of security We need to defining risk - what is an appropriate level of risk for small businesses? Adding clarity around standards and assessments, as well as those who are executing assessments Creating easier flow of information and management of risk through continuous monitoring, integrations, etc. transparently Systems that have data available when it’s needed to answer questions on demand Annual diligence process dependent on criticality of the vendor
  23. need for continuous monitoring - impacts who you are as a company and how you do business Reputational risk * Criticality of vendor impacts the number of requirements As your business grows with the enterprise, this process will increase for your business lines - reflective of a good relationship with the enterprise More robust reviews (this is a good thing!) Q: What does the current compliance landscape look like for SaaS businesses? Financial Services Privacy Federal Healthcare SPEAKER NOTES: Financial Services - New proposed interagency guidance for managing 3rd party relationships. First time the Federal Reserve, FDIC and the OCC issued guidance jointly. It is out now for comments. PCI DSS → Privacy - GDPR, CCPA, state privacy regulations. Repealing privacy shield, EU Cookie Directive Federal government - CMMC requirement for all 3rd parties/4th parties working with DOD to be certified by 2026. NIST: new prescriptive framework of choice Increasing difficulty as requirements rise to make this a core capability Health Care - we need to research something about this. Not familiar enough
  24. 25+ different frameworks to consider. Growing regulation list: https://docs.google.com/spreadsheets/d/1SUVWukag0Rcgs_mH9wGeMdYF4EUAd4D8lcOVx8JHla8/edit?usp=sharing Top 4 Cybersecurity frameworks: https://www.itgovernanceusa.com/blog/top-4-cybersecurity-frameworks 25 different frameworks: https://securityscorecard.com/blog/top-cybersecurity-frameworks-to-consider Rising number of Regulations Cybersecurity & Privacy (e.g. 280 new cybersecurity bills introduced in 2020 alone) Snowball effect Lack of standardization within and across industries Leaves a lot up to interpretation There are attempts to harmonize within industries but this could take years. So, for now SaaS companies should think about InfoSec and Privacy compliance as: Core Capabilities that need to be invested in Programs need to be flexible and adaptable to allow SaaS companies to scale because of : The current landscape and the rising tide And because as your relationship grows, the risk to the enterprise grows. Q: How do we expect 4th parties to be regulated? Define Risk Clarify Standards Create Transparency Demonstrate Trust SPEAKER NOTES: Needs to be something more to offer back to banks in terms of security We need to defining risk - what is an appropriate level of risk for small businesses? Adding clarity around standards and assessments, as well as those who are executing assessments Creating easier flow of information and management of risk through continuous monitoring, integrations, etc. transparently Systems that have data available when it’s needed to answer questions on demand Annual diligence process dependent on criticality of the vendor
  25. Growing regulation list: https://docs.google.com/spreadsheets/d/1SUVWukag0Rcgs_mH9wGeMdYF4EUAd4D8lcOVx8JHla8/edit?usp=sharing Rising number of Regulations Cybersecurity & Privacy (e.g. 280 new cybersecurity bills introduced in 2020 alone) Snowball effect Lack of standardization within and across industries Leaves a lot up to interpretation There are attempts to harmonize within industries but this could take years. So, for now SaaS companies should think about InfoSec and Privacy compliance as: Core Capabilities that need to be invested in Programs need to be flexible and adaptable to allow SaaS companies to scale because of : The current landscape and the rising tide And because as your relationship grows, the risk to the enterprise grows. Q: How do we expect 4th parties to be regulated? Define Risk Clarify Standards Create Transparency Demonstrate Trust SPEAKER NOTES: Needs to be something more to offer back to banks in terms of security We need to defining risk - what is an appropriate level of risk for small businesses? Adding clarity around standards and assessments, as well as those who are executing assessments Creating easier flow of information and management of risk through continuous monitoring, integrations, etc. transparently Systems that have data available when it’s needed to answer questions on demand Annual diligence process dependent on criticality of the vendor
  26. 25+ different frameworks to consider. Growing regulation list: https://docs.google.com/spreadsheets/d/1SUVWukag0Rcgs_mH9wGeMdYF4EUAd4D8lcOVx8JHla8/edit?usp=sharing 25 different frameworks: https://securityscorecard.com/blog/top-cybersecurity-frameworks-to-consider Rising number of Regulations Cybersecurity & Privacy (e.g. 280 new cybersecurity bills introduced in 2020 alone) Snowball effect Lack of standardization within and across industries Leaves a lot up to interpretation There are attempts to harmonize within industries but this could take years. So, for now SaaS companies should think about InfoSec and Privacy compliance as: Core Capabilities that need to be invested in Programs need to be flexible and adaptable to allow SaaS companies to scale because of : The current landscape and the rising tide And because as your relationship grows, the risk to the enterprise grows. Q: How do we expect 4th parties to be regulated? Define Risk Clarify Standards Create Transparency Demonstrate Trust SPEAKER NOTES: Needs to be something more to offer back to banks in terms of security We need to defining risk - what is an appropriate level of risk for small businesses? Adding clarity around standards and assessments, as well as those who are executing assessments Creating easier flow of information and management of risk through continuous monitoring, integrations, etc. transparently Systems that have data available when it’s needed to answer questions on demand Annual diligence process dependent on criticality of the vendor
  27. \To cope with the increasing complexity of vendor risks, industries and regulators have developed need for continuous monitoring - impacts who you are as a company and how you do business Reputational risk * Criticality of vendor impacts the number of requirements As your business grows with the enterprise, this process will increase for your business lines - reflective of a good relationship with the enterprise More robust reviews (this is a good thing!) Q: What does the current compliance landscape look like for SaaS businesses? Financial Services Privacy Federal Healthcare SPEAKER NOTES: Financial Services - New proposed interagency guidance for managing 3rd party relationships. First time the Federal Reserve, FDIC and the OCC issued guidance jointly. It is out now for comments. PCI DSS → Privacy - GDPR, CCPA, state privacy regulations. Repealing privacy shield, EU Cookie Directive Federal government - CMMC requirement for all 3rd parties/4th parties working with DOD to be certified by 2026. NIST: new prescriptive framework of choice Increasing difficulty as requirements rise to make this a core capability Health Care - we need to research something about this. Not familiar enough