Security questionnaires need real-world scenarios
As usual, Ross Young brought forward a great approach towards questionnaires - keeping them grounded in real world scenarios that could lead to your vendors and thus, your data being breached.
This is one of many reasons that current TPRM processes are wildly unsuccessful at measuring and more importantly, improving your vendor's security postures.
Asking hundreds of questions that sound good in a vacuum but add little practical value like "Do you encrypt data in transit?" instead of concrete questions that map directly to risks makes people feel good that they now have a comprehensive list of 282 answers covering a broad range of topics, even if they don't actually tell you anything.