Partner Discovery Questionnaire

↓ Download

This document is a conversation, not a form. Work through it with the partner contact who knows the business best. Incomplete answers are fine. A blank field tells you something too.

How to use this document

SectionTopicContent
Section 1About the PartnerBusiness model, geography, client profile, sales motion
Section 2About the Vendor RelationshipOrigin, stage, expectations, and material usefulness
Section 3About the Client ProblemArchetype-specific: select one of six variants
Section 4About the GapWhere the current motion breaks down and what would fix it
VariantsArchetype Question SetsSix scenario-specific versions of Section 3

Section 1: About the Partner

Understanding the partner’s business model, client base, and market position

01. What is your primary business model? e.g. systems integrator / boutique consultancy / reseller / MSSP / hybrid

[Answer field]

02. What is your primary geographic market? e.g. Japan / broader APJ / global with APJ focus

[Answer field]

03. Describe your typical client. Sector, size, and the role of the person you usually sell to

[Answer field]

04. What does a successful engagement look like for your business? e.g. product sale / recurring managed service / project-based consulting / retainer

[Answer field]

05. What is your current sales cycle length, and where do deals most often stall?

[Answer field]


Section 2: About the Vendor Relationship

Understanding where this relationship stands and what the partner actually needs from it

06. How did this vendor relationship originate? e.g. inbound from vendor / you sought them out / introduced through a third party

[Answer field]

07. What stage is the relationship at? e.g. exploring / signed agreement / active but underperforming / scaling

[Answer field]

08. What does the vendor expect from you, and do you agree with that expectation?

[Answer field]

09. What materials has the vendor already provided, and how useful have they actually been in real client conversations?

[Answer field]


Section 3: About the Client Problem

Use the archetype-specific version of this section from the variant pages below

Select your archetype and use the relevant questions from the Archetype Variants section at the end of this document. The questions there replace questions 10–13 on this page.

CodeArchetypeDescriptionExample
A1Classic Enterprise CyberEstablished vendors, global products, direct enterprise security motione.g. Mimic
A2Industrial / OT / IIoTOT security, industrial environments, multi-stakeholder buyer chainse.g. WI-SUN, Toyota Tsusho
A3Emerging / Sensitive AIAI governance, data sovereignty, regulated sector sensitivitye.g. WitnessAI
A4PKI / PQC / Crypto LifecycleCertificate management, post-quantum readiness, crypto infrastructuree.g. Keyfactor, OmniTrust
A5Remediation / Hygiene at ScalePatching, vulnerability management, managed remediation motione.g. Northern Tech Mender
A6SOC Modernization / Agentic D&RMoving from log aggregation to in-house detection engineering and agentic responsee.g. Agentic SOC vendors

Section 4: About the Gap

What is missing, and what would a good partner methodology actually give this partner

14. Where does your current go-to-market motion break down? e.g. finding the right entry point / building internal champions / technical credibility / commercial structuring

[Answer field]

15. What would a successful partner methodology give you that you do not have today?

[Answer field]

16. Is there anything about your market or your clients that you think the vendor fundamentally misunderstands?

[Answer field]


Archetype Variants

Section 3: About the Client Problem

Use the version below that matches your engagement. Replace questions 10–13 in Section 3 with the relevant archetype variant. All other sections remain identical.

A1 — Classic Enterprise Cyber

e.g. Mimic and similar established security vendors

10. What threat scenarios are you most concerned about, and why those specifically?

[Answer field]

11. Where does the vendor’s standard positioning fall flat in your specific client conversations?

[Answer field]

12. What proof points land with your clients, and what feels imported from another market?

[Answer field]

13. What does a successful first deployment look like, and who owns it on the client side?

[Answer field]


A2 — Industrial / OT / IIoT

e.g. WI-SUN Alliance, Toyota Tsusho context

10. Who is the actual buyer in this engagement: IT security, OT engineering, or procurement?

[Answer field]

11. What is the consequence of a security failure in the client’s OT environment, in operational terms?

[Answer field]

12. What existing OT vendor or integrator relationships does the partner have that need to be respected?

[Answer field]

13. What does the partner need to be credible in an OT room that they do not currently have?

[Answer field]


A3 — Emerging / Sensitive AI

e.g. WitnessAI and AI governance vendors

10. What is the partner’s honest read on client appetite for AI-related products in their market right now?

[Answer field]

11. Where does data residency or sovereignty become a concrete blocker, not a theoretical concern?

[Answer field]

12. What regulatory conversations is the partner already having that this vendor’s story could plug into?

[Answer field]

13. What would need to be true about the vendor’s data handling for this story to be safe to tell in a Japanese FSI context?

[Answer field]


A4 — PKI / PQC / Crypto Lifecycle

e.g. Keyfactor, OmniTrust

10. How technically mature is the partner’s client base on certificate management and cryptographic infrastructure today?

[Answer field]

11. Is the PQC conversation being driven by external regulation, internal risk appetite, or is it not happening yet?

[Answer field]

12. What does the partner need to explain quantum risk clearly to a non-technical executive?

[Answer field]

13. Where are the quick wins that build credibility and momentum before the full PQC roadmap conversation?

[Answer field]


A5 — Remediation / Hygiene at Scale

e.g. Northern Tech Mender

10. What does the partner’s client’s current patching and vulnerability management process actually look like in practice?

[Answer field]

11. Where does remediation most often break down: detection, prioritization, execution, or verification?

[Answer field]

12. Is the client aware they have a hygiene problem, or does that awareness conversation need to happen first?

[Answer field]

13. What would a managed remediation motion look like for this partner’s client base, and can the partner deliver it today?

[Answer field]


A6 — SOC Modernization / Agentic D&R

e.g. Agentic SOC vendors, autonomous detection and response

10. What is the client currently outsourcing to an MSSP that, with the right capability, they should own internally?

[Answer field]

11. What is the partner’s honest assessment of the client’s current MSSP detection and response quality?

[Answer field]

12. Where has the client felt most exposed by slow or inadequate response, and do they connect that to the outsourcing model?

[Answer field]

13. What does the partner need to be credible in a conversation about agentic detection and autonomous response?

[Answer field]