Where Security Meets Procurement

Peer Review

Gartner brand name text logo in white with registered trademark symbol.
5-star rating
4.8

Proven Trust

Dark blue circle with two overlapping checkmarks, one green and one light blue.
ISO 27001 text with a globe outline symbol on a black background.
2025 winner badge for Cyber Security Excellence Awards with gold and black design.

Every successful security partnership starts before the RFP is even written. This guide covers what goes wrong when collaboration comes too late, and how to get it right from day one:

  • How to define the right requirements and avoid last-minute red flags
  • Governance under DORA, GDPR, and the EU AI Act
  • 4 tips for choosing the right security partner
  • Why security should be built into the blueprint, not bolted on afterward
  • Breaking down silos between procurement, IT, and security

Built on Real Partnership Experience

Insight drawn directly from procurement and security leaders who've lived through the process, not theory.

  • Direct guidance from Margaret Corrigan, CISO at CluneTech
  • Real perspective from Tamas Hermann, Global Category Manager at Trivium Packaging
  • A practical RACI-based approach to defining ownership before problems start

Who This Guide is For

Procurement / Vendor Risk Lead

This guide is built directly for you. It covers how to define requirements, run RFPs, and choose a security partner without last-minute red flags.

CISO / Head of Security

Security's side of the procurement relationship rarely gets written down. This guide gives you a shared framework to bring into that conversation early.

CEO / Board-Level Executive

DORA, GDPR, and the EU AI Act all raise the stakes on vendor governance. This guide shows what good procurement oversight looks like at board level.