top of page

HOW TO EXPLORE FIT

See whether we're the right partner — before you commit to anything.

No-Risk Discovery is a short, practical conversation that gets you a clear view of your options — with no obligation to keep working with us.

Getting Zoho Through a Security Review: The Questions Procurement Will Ask.

1 day ago
5 min read

It happens at the best possible moment and the worst. A larger customer is ready to sign, or an insurer is renewing the cyber policy, and a questionnaire arrives: forty to two hundred questions about how you handle their data. Your systems run on Zoho, so the first instinct is to send Zoho's trust page and wait.

That answers about a third of the questions. The rest are not about Zoho. They are about you: how the estate is configured, who can see what, what gets logged, how access is reviewed, and who is accountable when any of that is wrong. This post walks the questionnaire from the operating company's side, which is the side nobody writes about.

Which questions Zoho's pages answer, and which they do not.

A vendor's certifications cover the vendor. Zoho publishes its SOC 2 and ISO attestations, its data centre locations and its encryption practices, and those pages are the right answer to the questions that ask about them: where is the data hosted, is it encrypted at rest and in transit, does the provider have an independent audit. Send the links, and record which questions they answer.

Getting Zoho Through a Security Review: The Questions Procurement Will Ask.

The remaining questions share a shape. They ask what your company does inside the platform. Who has administrative access. How access is granted and removed. Whether users see only the records they need. Whether changes are logged and reviewed. How you test changes before they reach production. Whether you can export and delete a customer's data on request. A certification cannot answer these, because the vendor does not know how you configured its product. Only you do, and if nobody in the company can say, that is the finding.

The configuration questions, and what answers each one.

Most of the hard questions map to a specific control in Zoho CRM and its neighbours. The map below is the one we use when we prepare a client for a review.

Who can see what. The answer is your roles and profiles: profiles decide which modules and actions a user has, roles decide which records they can see through the hierarchy. The questionnaire wants to hear that support cannot see deal amounts and that a departed rep's role was reassigned, not that the feature exists.

Least privilege. Data sharing rules and field-level security are how a company proves it, and the proof is the list: which fields are hidden from which profiles, and why. A company that has never set one has every user seeing every field, which is the default and the answer procurement does not want.

Logging and review. The audit log records who changed what and when. The question is rarely whether the log exists; it is whether anyone reads it. A monthly review, documented, by a named person, is the answer that passes.

Administrative access. How many administrators, who they are, and how a new one is approved. Three is a defensible number for a company of eighty. Eleven, because every power user was made an admin to save time, is a finding.

Change control. Whether you have a sandbox, whether changes are tested there before production, and who approves a change. The question is really about whether an untested automation can silently alter customer data.

Access reviews. When someone leaves, how quickly their access is removed, and how you know it was. Zoho's user list is the evidence; the process around it is the answer.

Data subject requests. Can you find, export and delete everything held about one person, across the sales system, the help desk and the marketing tool. This is where integration shows its value or its absence: a customer who exists under three names in three systems cannot be deleted with confidence.

Backups and recovery. What is backed up, how often, where, and when you last restored from one. The last part is the one most companies cannot answer.

The question underneath all of them.

Read the questionnaire again and one question sits under every other: who is accountable for this. Not which feature, not which vendor. Which person in your company owns the configuration of the estate, reviews it, and signs the answers.

In a company with an administrator who is also the sales operations lead and also the person who built the automations, the honest answer is nobody, because that person owns the work and not the outcome. Procurement teams have learned to hear this. A questionnaire returned with confident answers and no named owner is a questionnaire that gets a follow-up call.

This is the point of the review, from the buyer's side. They are not trying to verify Zoho. They are trying to find out whether the company they are about to depend on knows how its own systems are set up. A clean, owned, documented estate answers in a day. An estate that grew by accretion answers in three weeks of archaeology, and the deal waits.

How to prepare before the questionnaire arrives.

The work is a configuration audit with a document at the end, and it is worth doing before any customer asks.

Inventory the administrators and cut the list to the people who need it. Write down the profiles and what each one may do, and the roles and what each one may see. List the sharing rules and the hidden fields. Confirm the audit log is on for every module that holds customer data, and put a monthly review on someone's calendar with their name on it. Set up a sandbox if you do not have one, and write the rule that nothing reaches production without passing through it. Document the leaver process with a timing commitment. Find out where backups go and restore one.

Then write it up: one document, the estate's security posture, with an owner's name and a review date. When the questionnaire arrives, most of the answers are copied from it, and the ones that are not are small.

What this has to do with headcount.

The reflex when a review stalls a deal is to hire someone: a compliance person, a security lead. Most mid-market companies do not need one. They need the estate to be owned, which is an accountability question, not a headcount question. The work is a few days of configuration and a document that is reviewed quarterly, and it can sit with a named internal owner or with a partner who is accountable for the estate's configuration under a managed arrangement.

Either way, the test is the same one procurement applies: can someone in the company, by name, explain how the systems are set up and sign for it. A company that can pass a security review in a day is not more secure than one that takes three weeks. It is better governed, and buyers can tell.

Discovery is no-risk: we read your estate against the questionnaire you are most likely to receive, show you the findings, and you pay only if you go ahead.

Find out what one connected Zoho system would change in the way you run.

In a no-risk discovery we look at your CRM, finance and operations systems and who owns each part, and show what a connected system would do differently. You pay only if you proceed. Or see how we approach it.

More on the same problem:

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Subscribe

We'll send you periodic updates when new articles, thought leadership content and news is released.

Be Social

Follow CodeStringers on social media.

  • LinkedIn
  • Youtube
  • X

Featured Articles

About CodeStringers

CodeStringers helps growth-stage and small-to-mid-market companies implement, integrate, extend, and operate Zoho-centered business “operating systems”. The company combines fractional technology leadership, business systems integration, custom software development, and managed technical operations to help clients reduce operational friction and improve business outcomes.

bottom of page