DEV Community

Serguey Shinder
Serguey Shinder

Posted on

Software We Already Bought Is Getting Capabilities We Never Evaluated

Our risk and procurement processes are built around a purchase. Before we buy something there is an assessment, a security review, a data protection questionnaire, a look at where the data will be held and who can reach it, and a contract. After we buy it, there is renewal, and between those two events we largely stop looking.

That model assumed that the product we assessed is the product we keep running. Over the last two years that assumption has quietly stopped being true. Three of our major platforms have added assistants, summarisation or content generation by routine update, enabled by default, processing our data through a subprocessor that did not exist in the assessment we did at purchase. In one case the first anyone in IT knew about it was a user asking why the tool had started drafting replies on her behalf.

None of the vendors did anything wrong contractually. The agreements permit them to develop the product, which is what we wanted when we signed. The subprocessor lists were updated with the required notice, in an email to a mailbox that goes to procurement rather than to anyone who would recognise the significance.

What I expect over the next several years is that due diligence stops being an event and becomes a continuous obligation, and that this lands on internal IT rather than on the vendor. Release notes become a risk artefact that someone is paid to read. The ability to control features at tenant level, and to keep them off until reviewed, becomes a purchasing criterion rather than a footnote. Contracts start carrying notification clauses for material capability changes, because that is the only leverage we have.

We have made a modest start, which is all I would recommend to anyone. A register of the twenty applications that hold anything sensitive, with a named owner who reads the vendor's change announcements. Default new features to off where the platform allows it. Ask about capability change notification in every renewal conversation.

The uncomfortable part is that the question at the next audit will not be whether we evaluated the tool. It will be whether we noticed when it changed.

– Serguey Shinder

Top comments (0)