This document is a conversation, not a form. Work through it with the partner contact who knows the business best. Incomplete answers are fine. A blank field tells you something too.
How to use this document
| Section | Topic | Content |
|---|---|---|
| Section 1 | About the Partner | Business model, geography, client profile, sales motion |
| Section 2 | About the Vendor Relationship | Origin, stage, expectations, and material usefulness |
| Section 3 | About the Client Problem | Archetype-specific: select one of six variants |
| Section 4 | About the Gap | Where the current motion breaks down and what would fix it |
| Variants | Archetype Question Sets | Six scenario-specific versions of Section 3 |
Understanding the partner’s business model, client base, and market position
01. What is your primary business model? e.g. systems integrator / boutique consultancy / reseller / MSSP / hybrid
[Answer field]
02. What is your primary geographic market? e.g. Japan / broader APJ / global with APJ focus
[Answer field]
03. Describe your typical client. Sector, size, and the role of the person you usually sell to
[Answer field]
04. What does a successful engagement look like for your business? e.g. product sale / recurring managed service / project-based consulting / retainer
[Answer field]
05. What is your current sales cycle length, and where do deals most often stall?
[Answer field]
Understanding where this relationship stands and what the partner actually needs from it
06. How did this vendor relationship originate? e.g. inbound from vendor / you sought them out / introduced through a third party
[Answer field]
07. What stage is the relationship at? e.g. exploring / signed agreement / active but underperforming / scaling
[Answer field]
08. What does the vendor expect from you, and do you agree with that expectation?
[Answer field]
09. What materials has the vendor already provided, and how useful have they actually been in real client conversations?
[Answer field]
Use the archetype-specific version of this section from the variant pages below
Select your archetype and use the relevant questions from the Archetype Variants section at the end of this document. The questions there replace questions 10–13 on this page.
| Code | Archetype | Description | Example |
|---|---|---|---|
| A1 | Classic Enterprise Cyber | Established vendors, global products, direct enterprise security motion | e.g. Mimic |
| A2 | Industrial / OT / IIoT | OT security, industrial environments, multi-stakeholder buyer chains | e.g. WI-SUN, Toyota Tsusho |
| A3 | Emerging / Sensitive AI | AI governance, data sovereignty, regulated sector sensitivity | e.g. WitnessAI |
| A4 | PKI / PQC / Crypto Lifecycle | Certificate management, post-quantum readiness, crypto infrastructure | e.g. Keyfactor, OmniTrust |
| A5 | Remediation / Hygiene at Scale | Patching, vulnerability management, managed remediation motion | e.g. Northern Tech Mender |
| A6 | SOC Modernization / Agentic D&R | Moving from log aggregation to in-house detection engineering and agentic response | e.g. Agentic SOC vendors |
What is missing, and what would a good partner methodology actually give this partner
14. Where does your current go-to-market motion break down? e.g. finding the right entry point / building internal champions / technical credibility / commercial structuring
[Answer field]
15. What would a successful partner methodology give you that you do not have today?
[Answer field]
16. Is there anything about your market or your clients that you think the vendor fundamentally misunderstands?
[Answer field]
Section 3: About the Client Problem
Use the version below that matches your engagement. Replace questions 10–13 in Section 3 with the relevant archetype variant. All other sections remain identical.
e.g. Mimic and similar established security vendors
10. What threat scenarios are you most concerned about, and why those specifically?
[Answer field]
11. Where does the vendor’s standard positioning fall flat in your specific client conversations?
[Answer field]
12. What proof points land with your clients, and what feels imported from another market?
[Answer field]
13. What does a successful first deployment look like, and who owns it on the client side?
[Answer field]
e.g. WI-SUN Alliance, Toyota Tsusho context
10. Who is the actual buyer in this engagement: IT security, OT engineering, or procurement?
[Answer field]
11. What is the consequence of a security failure in the client’s OT environment, in operational terms?
[Answer field]
12. What existing OT vendor or integrator relationships does the partner have that need to be respected?
[Answer field]
13. What does the partner need to be credible in an OT room that they do not currently have?
[Answer field]
e.g. WitnessAI and AI governance vendors
10. What is the partner’s honest read on client appetite for AI-related products in their market right now?
[Answer field]
11. Where does data residency or sovereignty become a concrete blocker, not a theoretical concern?
[Answer field]
12. What regulatory conversations is the partner already having that this vendor’s story could plug into?
[Answer field]
13. What would need to be true about the vendor’s data handling for this story to be safe to tell in a Japanese FSI context?
[Answer field]
e.g. Keyfactor, OmniTrust
10. How technically mature is the partner’s client base on certificate management and cryptographic infrastructure today?
[Answer field]
11. Is the PQC conversation being driven by external regulation, internal risk appetite, or is it not happening yet?
[Answer field]
12. What does the partner need to explain quantum risk clearly to a non-technical executive?
[Answer field]
13. Where are the quick wins that build credibility and momentum before the full PQC roadmap conversation?
[Answer field]
e.g. Northern Tech Mender
10. What does the partner’s client’s current patching and vulnerability management process actually look like in practice?
[Answer field]
11. Where does remediation most often break down: detection, prioritization, execution, or verification?
[Answer field]
12. Is the client aware they have a hygiene problem, or does that awareness conversation need to happen first?
[Answer field]
13. What would a managed remediation motion look like for this partner’s client base, and can the partner deliver it today?
[Answer field]
e.g. Agentic SOC vendors, autonomous detection and response
10. What is the client currently outsourcing to an MSSP that, with the right capability, they should own internally?
[Answer field]
11. What is the partner’s honest assessment of the client’s current MSSP detection and response quality?
[Answer field]
12. Where has the client felt most exposed by slow or inadequate response, and do they connect that to the outsourcing model?
[Answer field]
13. What does the partner need to be credible in a conversation about agentic detection and autonomous response?
[Answer field]