Skip to content
FortaRisks
Back to blogThird-Party Risk

The 5 questions to ask any vendor at a cyber trade show

September 22, 2026 · 6 min read

GoSec opens tomorrow at the Palais des congrès in Montreal. You will walk the aisles for three hours, watch fourteen demos that all look alike, leave with a stack of business cards and, by Thursday evening, be unable to say what separates the sixth from the eleventh.

The vendors are not the problem. The problem is that on a show floor the demo runs the conversation, and a demo is built never to fail.

Five questions are enough to take the lead back. Each takes a few minutes, they work at any booth, and none of them requires technical expertise.

Why the demo teaches you almost nothing

The screen you are shown runs on a prepared dataset: complete inventory, perfect configuration, no exceptions, no orphaned assets, no vendor who fails to answer. The person in front of you is there to talk about what works, and they do it honestly.

So you leave with a picture of the product's best day. What you will buy is its ordinary days: dirty data, an incomplete perimeter, a team of three people whose calendar is already full.

The five questions below have one thing in common: none of them can be answered with a screen.

1. "What problem does your product not solve?"

Ask it first. It sets the tone for the rest of the exchange, and it tells you immediately who you are talking to.

A vendor who knows their limits knows their product. The good answer names adjacent categories ("endpoint detection, that is not us"), owns up to the work that stays with your team, and describes the overlap with what you already run.

The bad answer is the one that covers "the entire risk lifecycle." It means either that the person does not know the offering, or that the product is a thin layer resting on a lot of promises.

A useful follow-up: "which of your customers stopped using you, and why?"

2. "What leaves our environment, where does it go, and who else touches it?"

Three points, in this order: which data leaves your environment, in which region it is processed and retained, and which subprocessors sit in the chain.

In Quebec, the question is not theoretical. Law 25 requires a privacy impact assessment before any communication of personal information outside the province. A support or analysis tool that ships your content to a region nobody validated creates that obligation, whether you noticed it or not.

Add the question almost nobody asks on a show floor: which features are on by default, and which ones send data to a third-party AI model? That is exactly the data path described in episode 4 of our AI security series, and it appears through an update, with no new contract.

A serious vendor answers in thirty seconds, names their regions and points you to their public subprocessor page. The one who has to "check with the team" has just told you the answer is written down nowhere.

3. "On day 1, who does the work, and how long until it pays off?"

The price on the slide is the licence. The real cost includes the agent to deploy, the inventory to provide, the asset repository to clean up, the identity provider to connect, the connectors another vendor has to approve, and your team's hours.

Put it in numbers: "at your last three customers our size, how many person-days between signature and the first decision actually made because of the tool?" A range with an example is a real answer. "It deploys very fast" is not.

Ask what month three looks like too, once the initial enthusiasm has worn off: who still opens the tool, and for how long each week.

4. "Show me real output, not the demo dashboard"

The dashboard is the marketing product. The raw output is the product.

Ask for the report as a customer receives it, anonymized: a full alert, a vulnerability report, a vendor record, an analysis result, with its empty fields and its uncertainties. Then two follow-ups:

  • What is your false positive rate, and how do you measure it? A vendor with no number has no method.
  • What does tuning look like after a month, and who does it, you or us?

This is the question that separates tools that produce a decision from tools that produce volume. Your team does not need 4,000 more findings a week, it needs the twelve that change a trade-off.

5. "What happens on the day it goes wrong?"

Three parts, and they can be asked standing up, in two minutes.

On their side. Have you had a security incident in the last twenty-four months, how did your customers learn about it, and how fast? The contractual notification deadline you negotiate later is worth exactly what this answer is worth. For products sold in the European Union, the Cyber Resilience Act now requires an early warning within 24 hours on an actively exploited flaw: ask the vendor what that changed in their procedures.

On your side. On a Saturday morning, who answers, how fast, and from what severity level? Get a person or a mechanism named, not an email address.

On the way out. What happens to our data if we leave in eighteen months, in what format, within what deadline, and at what cost? A vendor who has never thought about your exit has not thought about your recovery either.

The 2026 bonus question: "where is the AI, and who answers for it?"

Every booth will announce artificial intelligence. Two sub-questions are enough to sort them.

What does the model actually do: classify, summarize, or decide? And when it is wrong, who sees it? A model that prioritizes vulnerabilities and a model that closes tickets automatically do not raise the same governance problem, even if the booth uses the same word for both.

Three answers that should worry you

  • "All our customers do this." An appeal to authority with no content. Reply: which one, in our sector, our size, that we can call?
  • "We do not disclose our subprocessors for security reasons." A subprocessor list is not a defensive secret, it has been a standard contractual requirement for years. That answer no longer survives an audit.
  • "If you sign before the end of the quarter..." A discount tied to a date is a calendar decision, not a risk decision. A good tool will still be good in a month, and a solid vendor knows it.

What you do with it when you get back

A trade show is only worth the forty-eight hours that follow. While it is still fresh, write three lines per vendor you met: what they do not do, where the data goes, what day 1 costs your team. Three lines, not a page.

Then sort by inherent risk before assessing anything: a vendor who will process personal information or hold privileged access to your environment is not reviewed like a standalone visualization tool. That is the logic of the Third-Party Risk module, and it is also the order our free vendor security questionnaire works in: exposure level first, depth of assessment second.

Questionnaires sent to everyone at once never come back. Three questionnaires sent to the three right vendors, with a response date, do.

And on our side

We are at GoSec on September 23 and 24, booth 45, by appointment through Swapcard or simply by dropping in. Ask us the five questions, in that order, before we open a single screen. If an answer sounds vague, say so on the spot: that is exactly what these questions are for, and it is the most useful conversation we can have in ten minutes standing up.

Take it further

Generate a vendor questionnaire, free

Third-party risk starts with the right questions. Our generator produces a security questionnaire matched to the vendor's criticality, ready to send, no sign-up.