As John Wheeler and I work on the updated Enterprise GRC Platform magic quadrant, I wonder what has happened to many of the vendors that used to brief us. Actually, I know where they are, and now and then I’ll see them at a trade show, or shoot them an e-mail asking for an update. I always tell these vendors to make sure they stay in touch with, at a minimum, an annual briefing. Some do, some don’t.
Not keeping the analysts up to date is a mistake. Everyday I recommend vendors to clients that are looking for solutions, and often those recommendations include vendors who have a special capability, industry domain knowledge, or geographic focus, but who do not meet all the magic quadrant inclusion criteria.
Another thing I do is make sure I include vendors in other research, such as hype cycles. For instance in the enterprise GRC platforms profile on the GRC hype cycle, I include vendors who have updated me in the last year, and I remove any who have not. Same for the continuous controls monitoring profile. So the best way to get yourself removed from the “example vendors” on the hype cycle is to make sure you do not brief the analysts.
Vendors are also often mentioned in technology overview notes. Sure, I’ll reach out to try to get them to brief me for the third party risk management and social GRC notes I’m working on, but could I miss a particular vendor because they have not kept in touch? Yes, I could.
Category: Uncategorized Tags: