About

Roger Ramey, CISSP, CCSP

Thirty-five years inside a bank's security function, on both sides of the assessment. I now do one thing: complete the vendor security questionnaires that stall enterprise deals, and tell you the truth about what is in them.

Roger Ramey
Background

Thirty-five years of the thing these questions are about.

I spent my career as a senior network security analyst inside a bank — firewalls, access control, F5, SIEM, and the audit cycle across a six-country Caribbean footprint, under continuous regulator scrutiny. Not a consultancy engagement that ended when the report shipped. The same estate, year after year, with the consequences of every answer landing back on my desk.

That means two things for you. I have completed these assessments as the vendor, under a deadline someone else set. And I have run them from the other side, reading a supplier's answers and deciding whether to believe them. I know which sentences a reviewer stops on, because I stopped on them.

CISSP and CCSP certified. Based in Port of Spain, Trinidad & Tobago; I work in English with companies anywhere.

The rule I work by

I will not write a yes your evidence cannot support.

Not when it would be faster. Not when you ask me to. A confident wrong answer is what turns a compliance exercise into a legal problem eighteen months later, and keeping that off your desk is the entire job.

So when your evidence does not reach, you get the honest answer, the smallest fix that would close the gap, and a realistic estimate of the effort. That is worth more than a spreadsheet of yeses, and it is the reason the work is defensible when someone reads it back to you at renewal.

What I do not do.

I do not issue certifications or audit opinions — I am not an audit firm and no one should represent my work as an attestation. I do not draft contractual, insurance or indemnification language; breach-notification windows, right-to-audit clauses and liability limits go to your counsel, and I mark them clearly rather than guessing. And I do not answer questions about your environment from imagination. If it is not in your evidence and you cannot confirm it, it gets flagged.

What I work with

The formats, and what they actually are.

Buyers rarely explain what they have sent you. Here is the short version.

FormatWho publishes itWhat to expect
SIG Shared Assessments A scoping tool, not a fixed document. In the 2025 release the Lite, Core and Detail presets held 128, 627 and 1,936 questions; the current release is SIG 2026 and counts are not published. Twenty-one risk domains, including a dedicated Artificial Intelligence domain. A “SIG” can be almost any length — which is why I price on the question count, not the name.
CAIQ Cloud Security Alliance v4.1 (January 2026) is current at 283 questions mapped to CCM v4.1's 207 controls across 17 domains. CAIQ-Lite is 138. CSA also publishes a separate AI Controls Matrix.
HECVAT EDUCAUSE The higher-education standard. Since version 4 the former Full, Lite and On-Premise editions are consolidated into a single conditional workbook, so the length depends on your answers.
Their own spreadsheet The buyer's procurement or security team The most common thing I receive. Usually a hybrid assembled from the above plus whatever the last incident taught them. Answered the same way, in their format, keyed to their numbering.

Version details as published by each body and current as of 26 August 2026. These move; I check before quoting.

Before you send anything

Questions people ask me first.

01

Will you sign an NDA?

Yes, before you send anything. Send me yours, or I will use a straightforward mutual one.

02

We have no SOC 2 and almost nothing written down. Is this a waste of your time?

No — that is the normal starting point at five to fifty people, and it is exactly what the security profile step is for. We do a short call, I write down what is actually true about your environment, and every answer comes from that.

03

Can you just answer yes so the deal closes?

No. That is the one thing I will not do, and it is the reason to hire me rather than someone who will. A flagged gap with a date attached tends to clear procurement; an overstated yes fails late, in the follow-up call, after the reviewer has stopped trusting the rest of the document.

04

How fast?

Three days for most documents, five for a full CAIQ, and a 48-hour rush is available. If your deadline is not achievable I will say so before you order rather than take it and miss it.

05

What happens to my documents afterwards?

Your evidence stays yours. I keep nothing beyond what is needed to finish the work and honour the revision window, and I delete it on request.

06

Do we have to do this again for the next customer?

Not from scratch. The security profile is the reusable asset — the second questionnaire is a fraction of the first, which is what the retainer is for.

Send me the questionnaire. I'll tell you what it'll cost and when you'll have it.

Reply the same day, with a fixed price and a delivery date — not an estimate.