The Challenge
In today’s climate, it’s very common for major security breaches to occur as a result of third party vendor relationships. Because of its unique business model, dōTERRA works with a large number of outside vendors, which makes it especially susceptible to outside threats.
Shortly after he started, Eric began looking for solutions to better manage vendor security assessments and to get better insights into the associated risks of third party relationships. The company signed a 1-year contract with a GRC vendor to handle multiple aspects of its security risk management needs, including vendor risk management.
Unfortunately, this partnership provided more headaches than solutions for the dōTERRA team.
“After a three-day training, we were left to our own devices to customize and implement our security workflow,” Eric said. “This was a challenging, time-consuming process that required more than one full-time resource to handle, and we didn’t have that kind of time.”
Because of the cumbersome customization process, resource demands, and ongoing process issues, the dōTERRA team never actually got up and running on their GRC platform in the year they had their contract. Once the contract was over, Eric knew the dōTERRA team needed a more focused, ready-to-use solution to take vendor security management to the next level. With Whistic, Eric knew they were getting a purpose-built, ready-to-use solution that would be easy for internal team members, executives, and vendors to use – without a year-long onboarding process.
“We needed to make the decision whether or not to move forward with our GRC solution rather quickly, and we realized that the vendor management platform we were using just wasn’t going to work for us,” said Eric. “The other security-focused components, we could customize over time, but this first project was just too time-consuming. Because vendor security management is so critical to the success of our business, we needed a platform that was going to deliver value fast.”