Home
/
Case Studies
/
Collecting Artifacts Isn't The Same As Analyzing Them

Collecting Artifacts Isn't The Same As Analyzing Them

About the Company

Cresta

Cresta unlocks the true potential of the contact center, turning every customer conversation into a competitive advantage.

  • Headquarters:
    Sunnyvale, California
  • Company Size:
    501-1,000
  • Industry:
    Software Development

Cresta is an enterprise AI platform for the contact center, built to turn every customer conversation into a competitive advantage. Founded in 2017 out of the Stanford AI Lab, it serves Fortune 500 enterprises across telecommunications, financial services, and hospitality. 

Ryan Mathew leads GRC at Cresta, a remit that spans customer-facing security, compliance, and third-party risk. On the vendor side, he kept running into the same problem every security team does. Vendor risk has become an exercise in collection, not analysis.

"A lot of time was spent just getting the information and initiating the process, and almost no time was spent in actual analysis and review."

Why most vendor reviews skip the review

Ryan has run vendor risk programs before, on the workflow-heavy platforms that dominate the category. He knows what those tools are good at, and where they stop.

"What vendor risk management has become is just this big information gathering, but no review of the information."

His read is that the category optimized for the wrong thing. The established platforms built more and more elaborate approval chains, routing a document from one reviewer to the next until someone clicks approve. The workflow kept getting heavier while the analysis went missing. More routing never meant more review.

"They collect everything and then they say, now it's up to you to click a button."

A vendor comes in on a deadline, the documents and the questionnaire take time to land, and by the time everything is in hand there is no room left to actually read it. The review becomes a record that a review happened.

What the team cut

The old model put the questionnaire at the front door. Ryan moved it to the back. The vendor's documents go in first, Lema analyzes them and maps the findings against the controls that matter, and the questions come after that, targeted only at the gaps the artifacts leave open. The questionnaire he inherited was long, a trimmed version of a standard industry set. What replaced it is a shorter more focused set of questions, "I wanted to get away from the questionnaire piece and completely rely on Lema's analysis."

Where the review time goes

With the collection step compressed, the team's time moves to the part that was missing. Lema reads the vendor's documentation and returns the findings and gaps in a form a person can work through in minutes.

"It does the analysis and the review piece. That's the important part in vendor risk management, which is completely lost, forgotten."

That changes what Ryan spends his attention on. Instead of chasing every policy, he works the gaps Lema surfaces and follows up on the ones that matter for Cresta. Two come up consistently: a vendor's breach notification SLA, and how a vendor uses Cresta's data for model training. 

"Within the 5 to 10 minute decision time I have to make a decision about this vendor, I'm actually focusing on important things."

A review you can stand behind

Ryan puts the difference in one line.

"It's actual vendor risk management, compared to the checkbox exercise."

What he values is not a faster clock. It is that a genuine review now happens, instead of an approval resting on the fact that a vendor has a SOC 2 report. Lema does the reading a person would do, if a person had the time.

"Traditional TPRM is a weird circus where everyone knows they're wasting each other's time with spreadsheets and checklists. It provides next to zero value. Lema is the first solution that provides true assurance by actually validating the claims vendors make, not just taking an Excel sheet for granted."

Iain Paterson
Robert Kugler
Head of Security, IT & compliance at Cresta