Sales & PartnershipsFree
Security Objection and Gap Brief
Your gap register filtered to what their own rulebook makes them ask, with every answer checked against dates you already gave somebody else.
Objection handling advice is the same everywhere: acknowledge the concern, clarify the root of it, answer with value, confirm and move on. Written for pricing, applied to security, where it fails for a specific reason. A pricing objection is a negotiation. A security objection is an inspection against a list the buyer did not write, and the only useful preparation is knowing which items on that list you will fail. River builds that, from your own register and their own obligations.
The filter is the point. A gap register is undifferentiated, and preparing an answer for all twenty-three is how a call turns into a disclosure nobody asked for. Most buyers are compelled to ask about a narrow, published set, because their regulator wrote the shape of the questionnaire before their security lead did. Filtering by that leaves the handful of rows this particular buyer will genuinely reach, and it names the seventeen that they will not.
Then the second half, which is where deals actually break. Every gap that gets answered with a date becomes a promise, and promises are made in a call, an email or a signed addendum and then never collected in one place. Built for the account executive walking into the security call and the sales engineer behind them. When the review turns into a workstream, it belongs on the mutual action plan, and the tool index has the rest.
Their rulebook writes the questionnaire before they do
Take a New York regulated insurer. Its third-party service provider policy has to include contractual protections addressing access controls including multi-factor authentication, encryption in transit and at rest, notice of a cybersecurity event, and representations and warranties. Four areas, named in the rule. Their security lead is not improvising a questionnaire, they are discharging an obligation, so those four are the ones that will not be waived no matter how well the call goes.
A healthcare buyer arrives with a different fixed list. The business associate contract must provide that the associate will comply with the security requirements, ensure any subcontractors handling that data agree to comply, and report any security incident of which it becomes aware. Subcontractor flow-down and incident reporting, mandatory. That is why a gap in your subprocessor terms is a blocker for a hospital and a shrug for a design agency, and why one gap brief cannot serve both.
So the register gets read against the buyer rather than in isolation. Six rows survive the filter for the insurer, and seventeen drop out, which is the more useful number: those are the answers nobody needs rehearsed and the disclosures nobody needs to make. Each surviving row then gets typed as a compensating control, which is a real answer, or as a date, which is a promise. Only the second kind can be broken, and only the second kind needs checking against what somebody already said to another customer last spring.
How it works
Paste the register
Your control matrix, gap list and roadmap, in whatever shape they are currently in.
Describe the buyer
Their sector, their size, and anything their security lead has already asked you about.
River filters and cross-checks
Gaps against what their own rules force, then answers against dates already promised elsewhere.
Take the call
A short brief, the honest answer on each row, and the promises you must not repeat.
What you get
- The gaps this buyer is compelled to ask about, with the rule that compels each
- The gaps they will never reach, named so nobody rehearses an unnecessary disclosure
- Each answer typed as a compensating control today or a date in the future
- A ledger of every roadmap date already given to a customer on the same gap
- The dates that have already moved, with how many times and to whom
- The question to ask engineering before anybody says a month out loud
Common questions
What does it need from me?
Your gap list in whatever state it exists, and enough about the buyer to work out what governs them. Sector and size usually do it. Anything their security lead has already asked is worth pasting in, because the first two questions tell you a great deal about which list they are working from.
Why filter at all? Shouldn't we prepare for everything?
Preparing for everything means rehearsing seventeen disclosures nobody requested. Security reviews are inspections against a defined list, and volunteering a gap outside it introduces a finding the reviewer had no route to. The seventeen stay in the register, documented and owned. They just do not go in the brief for this call.
How does it know what this buyer has to ask?
From what governs them. A New York regulated financial firm has four contractual areas named in its own rule. A covered healthcare entity has subcontractor flow-down and incident reporting in its business associate contract. A design agency has whatever their general counsel remembered. The tighter the regime, the more precisely the questionnaire can be predicted.
Our roadmap dates are scattered across emails and contracts.
That is the normal state and it is exactly the problem. A date given on a call binds the relationship as firmly as one in an addendum, and neither gets recorded anywhere a rep can see. The ledger collects them from wherever they were said, so the fourth version of the same promise never gets made.
What if a gap has no answer at all?
Then the brief says so and gives you the question to take to engineering, rather than a form of words that sounds like a yes. Improvising a quarter in a security call is how a sales team acquires an obligation its platform team has never heard of, and the ledger exists because that keeps happening.
Where does this sit against the questionnaire itself?
Before it. This is the brief for the conversation. Filling in their spreadsheet is the security questionnaire response pack, and the privacy annex that usually arrives alongside is the DPA response, which runs the same check against your subprocessor terms.
Can it use our audit report as an answer?
For the gaps the report actually covers. Whether it does is a real question, since most reports examine two criteria categories and carve out the hosting provider entirely. The SOC 2 summary works that out question by question, and its output feeds straight into the compensating control column here.
Security Objection and Gap Brief
Fill in the form and your workspace opens with the work already underway.