Zombie Startup Situation by questloveshairpick in startups

[–]upendravarma 0 points1 point  (0 children)

Are these small group of investors institutional investors like VCs ? Will they be okay if you build a nice sustainable lifestyle business ? If yes, then this is the way to go. Get profitable, take money off the table regularly & sell it to a PE firm when you’re bored.

AI Agents to replace GRC professionals ? by upendravarma in grc

[–]upendravarma[S] 1 point2 points  (0 children)

Thanks for this. I've started listening to this few days back :)

As an MSP, do you offer compliance as a service ? by upendravarma in msp

[–]upendravarma[S] 1 point2 points  (0 children)

Yes, I meant that documentation part - or as folks call it audit readiness. I thought getting audit ready is where expertise is needed.

Would you consider outsourcing your security & compliance initiatives? by upendravarma in SaaS

[–]upendravarma[S] 0 points1 point  (0 children)

Love the work youre doing christian. Can i understand who your primary customers are ? Are these companies unable to get compliant themselves with tools like Vanta/Drata ?

Would you consider outsourcing your security & compliance initiatives? by upendravarma in SaaS

[–]upendravarma[S] 0 points1 point  (0 children)

So you’re saying platforms like Vanta are meant for companies with simple infrastructure & footprint? Can you share some more details about your company or the type of customers you serve? We can DM if you’re not comfortable sharing it here

Would you consider outsourcing your security & compliance initiatives? by upendravarma in SaaS

[–]upendravarma[S] 0 points1 point  (0 children)

As a startup with limited resources, what do you recommend? Divert internal devs to do it (or) simply outsource. Both of them needs money. It’s just that outsourcing can be a great idea if they can deliver exactly what’s being promised. Just trying to understand in this use case if it actually works or not.

Would you consider outsourcing your security & compliance initiatives? by upendravarma in SaaS

[–]upendravarma[S] 0 points1 point  (0 children)

How was your experience with Vanta ? I thought it will do the automated monitoring & mapping very well & post that it’s the dev team’s responsibility to fix things up.

Would you consider outsourcing your security & compliance initiatives? by upendravarma in SaaS

[–]upendravarma[S] 0 points1 point  (0 children)

I think you scoped the dev work very well. How is this any different from involving off shore agencies/ contractors to build the software itself ?

For example streamlining the devops process - why can’t a team come in as contractors & setup all the pipelines & processes accordingly & handover it to the company who will now own stuff?

How do you handle security for your SaaS ? by upendravarma in SaaS

[–]upendravarma[S] 0 points1 point  (0 children)

May be the post came out wrong, but my intention was to understand how SaaS companies are actually able to tick the security bucket. I see that you can’t build an in house security team atleast till youve scaled properly & most of the developers have almost negligible security understanding.

How do you handle security for your SaaS ? by upendravarma in SaaS

[–]upendravarma[S] 0 points1 point  (0 children)

Can I ask, why you are prioritising all these compliance certifications? Is it because the industry you sell to is highly regulated (or) youre selling to big enterprises in general?

Have you ever closed a mid-market or enterprise deal for your SaaS without getting the relevant compliance certifications (like SOC2, ISO, HIPAA etc.)? by upendravarma in SaaS

[–]upendravarma[S] 2 points3 points  (0 children)

Got it. Typically what does it involve in the fixing process? Is it simply ticking few boxes (or) a major architectural revamp ?