<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" >

<channel><title><![CDATA[Logical Writing Solutions, Inc. - Blog]]></title><link><![CDATA[https://www.logicalwriters.com/blog]]></link><description><![CDATA[Blog]]></description><pubDate>Fri, 01 May 2026 13:03:28 -0400</pubDate><generator>Weebly</generator><item><title><![CDATA[HITRUST Requirement for "Independent Review of Information Security" Clarified]]></title><link><![CDATA[https://www.logicalwriters.com/blog/hitrust-requirement-for-independent-review-of-information-security-causes-questions]]></link><comments><![CDATA[https://www.logicalwriters.com/blog/hitrust-requirement-for-independent-review-of-information-security-causes-questions#comments]]></comments><pubDate>Fri, 23 Oct 2020 19:50:27 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.logicalwriters.com/blog/hitrust-requirement-for-independent-review-of-information-security-causes-questions</guid><description><![CDATA[       Photo&nbsp;by Mike van Schoonderwalt from Pexels  Organizations preparing for HITRUST certification typically have questions around&nbsp;Control Reference 05.h Independent Review of Information Security: "The organization's approach to managing information security and its implementation (control objectives, controls, policies, processes, and procedures for information security) shall be reviewed independently at planned intervals, at a minimum annually, or when significant changes to the [...] ]]></description><content:encoded><![CDATA[<div><div class="wsite-image wsite-image-border-none " style="padding-top:10px;padding-bottom:10px;margin-left:0;margin-right:0;text-align:center"> <a> <img src="https://www.logicalwriters.com/uploads/1/0/5/2/105297913/pexels-mike-van-schoonderwalt-5484671_orig.jpg" alt="Picture" style="width:auto;max-width:100%" /> </a> <div style="display:block;font-size:90%"></div> </div></div>  <div class="paragraph" style="text-align:right;"><span style="color:rgb(26, 26, 26)">Photo&nbsp;</span>by <a href="https://www.pexels.com/@mike-van-schoonderwalt-1884800?utm_content=attributionCopyText&amp;utm_medium=referral&amp;utm_source=pexels" target="_blank">Mike van Schoonderwalt</a> from Pexels</div>  <div class="paragraph" style="text-align:left;"><span style="color:rgb(35, 43, 52)">Organizations preparing for HITRUST certification typically have questions around&nbsp;Control Reference 05.h Independent Review of Information Security: "</span>The organization's approach to managing information security and its implementation (control objectives, controls, policies, processes, and procedures for information security) shall be reviewed independently at planned intervals, at a minimum annually, or when significant changes to the security implementation occur."<br /><br />The first question is typically: Does the requirement for an "independent" review necessitate hiring external auditors? The second question is often: How does this differ from other HITRUST review requirements?<br />&nbsp;<br /><strong>Defining independent:</strong>&nbsp;The Level 1 notes for<span style="color:rgb(42, 42, 42)">&nbsp;05.h in the Cyber Security Framework (CSF) begin to clarify things</span>. It says: "The review ... is carried out by individuals independent of the area under review (e.g. the internal audit function, an independent manager or a third-party organization specializing in such reviews." In addition, the HITRUST glossary defines <em>Independent</em> as&nbsp;"With respect to an assessor or measure, one that is not influenced by the person or entity that is responsible for the implementation of the requirement/control being evaluated or measured." So an independent review can be conducted either by staff in a separate department or on a separate team from the function being reviewed as long as it isn't being influenced by the implementors, or by an external team.&nbsp;<br /><br /><span style="color:rgb(42, 42, 42)"><strong>Overall HITRUST Review and Assessment Requirements:</strong>&nbsp;At a minimum, in addition to independent review, HITRUST baseline requirements typically include:</span><ol style="color:rgb(35, 43, 52)"><li>A HITRUST validated assessment (recertification) every other year.</li><li>A HITRUST interim assessment on the alternating years.</li><li>An annual review of the Information Security Management Program&nbsp;(ISMP) or set of information security policies.(Control Reference 00.a Information Security Management Program).</li><li>A Risk Assessment on the scoped environment that addresses all HITRUST domains (Control Reference 03.b Performing Risk Assessments).&nbsp;</li><li>Penetration testing (Control Reference 10.m Control of Technical Vulnerabilities).</li></ol><br /><span style="color:rgb(42, 42, 42)">Baseline requirements are identified for an organization based on an organization's answer to scoping questions.&nbsp;&nbsp;</span><br /><br />Besides HITRUST reviews, these organizations may also be subject to SOC, PCI-DSS, ISO27001, penetration tests, and/or other reviews.<br /><br /><strong>Illustrative procedures: </strong>In addition to the baseline requirement statements, organizations should also look at <span style="color:rgb(42, 42, 42)">the "illustrative procedure" (IP) language for selected 05.h baseline requirements to understand how they are being tested. (Organizations can export a spreadsheet from the reporting section of MyCSF that includes the baseline requirements and the IP language for each requirement.) With a solid understanding of the organization-specific controls, the organization can consider whether existing assessment efforts are sufficient.&nbsp;If so, an organization may create an assurance plan specifying how the independent review requirement is met by existing efforts instead of performing an additional review.&nbsp;</span><br /><br /><strong>Focus on IPs and not the CSF:&nbsp;</strong>Keep in mind that if an organization wants to achieve HITRUST certification with efficiency, it should not consider the HITRUST CSF as equivalent to every organization's HITRUST scope. Not all CSF&nbsp; "Implementation Requirements" apply for every organization. Organizations should primarily focus on their baseline requirements and IPs, referencing the CSF for additional context only.&nbsp;</div>]]></content:encoded></item><item><title><![CDATA[Top Security Podcasts]]></title><link><![CDATA[https://www.logicalwriters.com/blog/sec-podcasts]]></link><comments><![CDATA[https://www.logicalwriters.com/blog/sec-podcasts#comments]]></comments><pubDate>Fri, 02 Oct 2020 04:00:00 GMT</pubDate><category><![CDATA[Top Security Podcasts]]></category><guid isPermaLink="false">https://www.logicalwriters.com/blog/sec-podcasts</guid><description><![CDATA[       Photo by&nbsp;Gritte&nbsp;on&nbsp;Unsplash  By Ann Grove, Logical's PresidentAdded Hacker Valley and other updates: 10/2/2020Original post: 8/2/2017&#8203;If you are looking for opportunities to keep your finger on the pulse of security, podcasts fit the bill. Here are some of our favorite security podcasts, in alphabetical order.Brakeing Down Security&nbsp;covers a range of topics such as conferences, software bloat, containerization, and technology culture. Hosts Bryan Brake, Brian Boet [...] ]]></description><content:encoded><![CDATA[<div><div class="wsite-image wsite-image-border-none " style="padding-top:10px;padding-bottom:10px;margin-left:0;margin-right:0;text-align:center"> <a> <img src="https://www.logicalwriters.com/uploads/1/0/5/2/105297913/published/microphone-gritte-5jhhisaeiz0-unsplash.jpg?1601667327" alt="Picture" style="width:auto;max-width:100%" /> </a> <div style="display:block;font-size:90%"></div> </div></div>  <div class="paragraph" style="text-align:right;"><span style="color:rgb(17, 17, 17)">Photo by&nbsp;</span><a href="https://unsplash.com/@gritte?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Gritte</a><span style="color:rgb(17, 17, 17)">&nbsp;on&nbsp;</span><a href="https://unsplash.com/s/photos/microphone-studio?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></div>  <div class="paragraph">By Ann Grove, Logical's President<br /><br /><span style="color:rgb(42, 42, 42)">Added Hacker Valley and other updates: 10/2/2020</span><br />Original post: 8/2/2017<br /><br />&#8203;If you are looking for opportunities to keep your finger on the pulse of security, podcasts fit the bill. Here are some of our favorite security podcasts, in alphabetical order.<ol><li><strong><a href="https://www.brakeingsecurity.com/" target="_blank">Brakeing Down Security</a>&nbsp;</strong>covers a range of topics such as conferences, software bloat, containerization, and technology culture. Hosts Bryan Brake, Brian Boettcher, and Amanda Berlin broadcast every week or two. &nbsp;</li><li><span style="color:rgb(42, 42, 42)"><strong><a href="https://crypto-gram.libsyn.com/" target="_blank">Crypto-Gram Security Podcast</a></strong>&nbsp;is Bruce Schneier's newsletter, read by Dan Henage. Schneier covers news and books that are often overlooked by others.</span></li><li><strong><a href="https://cybersecurityinterviews.com/" target="_blank">Cyber Security Interviews</a> </strong>offers insights into the minds of security thought leaders and the direction of the industry.</li><li><a href="https://thecyberwire.com/podcasts" target="_blank"><strong>Cyberwire podcast lineup</strong></a><span style="color:rgb(42, 42, 42)">&nbsp;</span>includes a daily 20-minute podcast covering news about cyberspace and commentary.</li><li><span style="color:rgb(42, 42, 42)"><strong><a href="https://defensivesecurity.org/" target="_blank">Defensive Security Podcast</a></strong>&nbsp;is a deep dive into recent cyber security breaches with Jerry Bell and Andrew Kalat.&nbsp;</span></li><li><strong><a href="https://www.devseccon.com/the-secure-developer-podcast/" target="_blank">DevSecCon</a>&nbsp;</strong>(previously&nbsp;The Secure Developer)&nbsp;covers application security, security tools for developers, and development best practices.&nbsp;Guy Podjarny, CEO at Snyk, launched this podcast in 2016.</li><li><strong><a href="http://podcast.wh1t3rabbit.net/" target="_blank">Down the Security Rabbithole Podcast</a></strong><span style="color:rgb(42, 42, 42)">&nbsp;</span>provides "a business-first approach" to security hacks, risks, and threats.</li><li><strong><a href="https://hackervalley.com/blue" target="_blank">Hacker Valley Blue</a>&nbsp;</strong><span style="color:rgb(42, 42, 42)">by Ron and Chris (a friend of mine) focused on threat intelligence.&nbsp;Coming soon: Hacker Valley Red, focused on the human element of security.</span></li><li><span><strong><a href="https://itunes.apple.com/us/podcast/itspmagazine/id1268444163?mt=2" target="_blank">ITSPmagazine</a> </strong>discusses security within the context of IT, privacy, and society.</span></li><li><strong><a href="https://malicious.life/" target="_blank">Malicious Life</a>&nbsp;</strong>by Cybereason tells the unknown stories of the history of cybersecurity, with comments and reflections by real hackers, security experts, journalists, and politicians</li><li><strong><a href="https://securityweekly.com/shows/" target="_blank">Paul's Security Weekly</a> </strong>(aka Paul Dotcom), in play since about 2005, hasn't published for some time but some of the team's other shows including&nbsp;Enterprise Security Weekly are still in play.&nbsp;</li><li><strong><a href="https://risky.biz/" target="_blank">Risky Business</a>, </strong>hosted by Patrick Gray since 2007. Security luminaries provide commentary. For instance, a 2020 episode talks about identity as the new perimeter.&nbsp;&nbsp;</li><li><strong><a href="https://isc.sans.edu/podcast.html" target="_blank">SANS Internet Storm Center StormCast</a>, </strong>daily security threat updates in 10 minutes or less for the TL;DR crowd.</li><li><strong><a href="https://www.grc.com/SecurityNow.htm" target="_blank">Security Now!</a></strong><span>&nbsp;</span><span>with Steve Gibson and Leo Laporte in part focuses on the evolution of threats, vulns and security with a smattering of news and trends. On the air since 2005.</span></li><li><strong><a href="https://7ms.us/" target="_blank">7-minute Security Podcast</a></strong><span style="color:rgb(42, 42, 42)">&nbsp;</span>has been talking about pentesting, blue teaming, and building a career in security since 2004. Bonus: Check out host Brian Johnson's&nbsp; <a href="https://www.brianjohnson.tv/portfolio/music#cryptolockerd" target="_blank">original song, CryptoLocker'd</a>, inspired by a client experience in 2017.</li><li><a href="https://www.garymcgraw.com/technology/silver-bullet-podcast/" target="_blank"><strong>&#8203;</strong></a><span style="color:rgb(42, 42, 42)"><strong><a href="https://www.social-engineer.org/category/podcast/" target="_blank">Social-Engineer Podcast</a></strong>&nbsp;(broken link in 2020) is about the risks humans create in interacting with technology.&nbsp;</span></li><li><strong><a href="https://danielmiessler.com/podcast/" target="_blank">Unsupervised Learning Podcast</a> </strong>features&nbsp;Daniel Miessler providing perspective on the human impact of technology and security. It's Daniel's summary of 20 hours of reading each week.&nbsp;</li></ol><br />Let us know if you have any podcasts to add!&nbsp;<br /><br /><br /><strong style="color:rgb(42, 42, 42)">About Ann</strong><br /><br /><span style="color:rgb(42, 42, 42)">&#8203;</span><span style="color:rgb(42, 42, 42)">Ann Grove, president of Logical, is Logical&rsquo;s lead consultant. Logical's clients include security and compliance vendors as well as penetration test consultants.&nbsp;</span><br /><br /></div>]]></content:encoded></item><item><title><![CDATA[Amazon Web Services: Permission No Longer Required to Test Security for 8 Services]]></title><link><![CDATA[https://www.logicalwriters.com/blog/amazon-web-services-permission-no-longer-required-to-test-security-for-8-services]]></link><comments><![CDATA[https://www.logicalwriters.com/blog/amazon-web-services-permission-no-longer-required-to-test-security-for-8-services#comments]]></comments><pubDate>Sun, 03 Mar 2019 20:41:36 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.logicalwriters.com/blog/amazon-web-services-permission-no-longer-required-to-test-security-for-8-services</guid><description><![CDATA[By Ann Grove, Logical's PresidentAmazon recently changed its policies so that customers and their security consultants can perform security assessments without pre-approval on customer-owned AWS resources that make use of eight key services:Amazon EC2 instances, NAT Gateways, and Elastic Load BalancersAmazon RDSAmazon CloudFrontAmazon AuroraAmazon API GatewaysAWS Lambda and Lambda Edge functionsAmazon Lightsail resourcesAmazon Elastic Beanstalk environmentsTeri Radichel alerted the security comm [...] ]]></description><content:encoded><![CDATA[<div class="paragraph">By Ann Grove, Logical's President<br /><br />Amazon recently changed its policies so that <a href="https://aws.amazon.com/security/penetration-testing/" target="_blank">customers and their security consultants can perform security assessments without pre-approval on customer-owned AWS resources </a>that make use of eight key services:<ul><li><span style="color:rgb(51, 51, 51); font-weight:400">Amazon EC2 instances, NAT Gateways, and Elastic Load Balancers</span></li><li><span style="color:rgb(51, 51, 51); font-weight:400">Amazon RDS</span></li><li><span style="color:rgb(51, 51, 51); font-weight:400">Amazon CloudFront</span></li><li><span style="color:rgb(51, 51, 51); font-weight:400">Amazon Aurora</span></li><li><span style="color:rgb(51, 51, 51); font-weight:400">Amazon API Gateways</span></li><li><span style="color:rgb(51, 51, 51); font-weight:400">AWS Lambda and Lambda Edge functions</span></li><li><span style="color:rgb(51, 51, 51); font-weight:400">Amazon Lightsail resources</span></li><li><span style="color:rgb(51, 51, 51); font-weight:400">Amazon Elastic Beanstalk environments</span></li></ul><br />Teri Radichel alerted the security community to the change <a href="https://twitter.com/TeriRadichel/status/1101228943128969218" target="_blank">on Twitter on March 1</a>. Amazon has since acknowledged the change.<br />&nbsp;<br />Previously, penetration testers looking for security weaknesses on AWS had to request permission a week before testing, and AWS sometimes requested additional information.<br /><br />This follows Microsoft's lead. Microsoft decided to <a href="https://docs.microsoft.com/en-us/azure/security/azure-security-pen-testing" target="_blank">drop pre-approvals in 2017 for Azure</a>. No pre-approval is required when penetration testing Azure resources.&nbsp;<br /><br /><font color="#001000">Both organizations test the security of their own cloud infrastructure, and allow customers to conduct certain types of additional testing.<span style="font-weight:400"> Although pre-approvals are no longer required, testers still need to follow any other rules or conditions for testing.</span></font><br /><br /></div>]]></content:encoded></item><item><title><![CDATA[Newsflash: That Thing You Just Created Already Has a Brand]]></title><link><![CDATA[https://www.logicalwriters.com/blog/newsflash-that-thing-you-just-created-already-has-a-brand]]></link><comments><![CDATA[https://www.logicalwriters.com/blog/newsflash-that-thing-you-just-created-already-has-a-brand#comments]]></comments><pubDate>Tue, 12 Feb 2019 18:09:58 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.logicalwriters.com/blog/newsflash-that-thing-you-just-created-already-has-a-brand</guid><description><![CDATA[       By Ann Grove, Logical's PresidentNote from Ann: I wrote a draft of this article in 2012 and just stumbled across it today. Still true! &nbsp;Whatever you are bringing to the market, you really don&rsquo;t need to create a brand &hellip; because whatever you want to brand, even if it is "brand new," already has some brand attributes.&nbsp;A brand is simply the feelings or themes associated with an item or experience. When people think of you, your company, or your products or services, the [...] ]]></description><content:encoded><![CDATA[<div><div class="wsite-image wsite-image-border-none " style="padding-top:10px;padding-bottom:10px;margin-left:0;margin-right:0;text-align:center"> <a> <img src="https://www.logicalwriters.com/uploads/1/0/5/2/105297913/brands-that-pop-security-compliance-writing-analyst-writer_orig.jpg" alt="Picture" style="width:auto;max-width:100%" /> </a> <div style="display:block;font-size:90%"></div> </div></div>  <div class="paragraph">By Ann Grove, Logical's President<br /><br /><em>Note from Ann: I wrote a draft of this article in 2012 and just stumbled across it today. Still true! </em><br />&nbsp;<br />Whatever you are bringing to the market, you really don&rsquo;t need to create a brand &hellip; because whatever you want to brand, even if it is "brand new," already has some brand attributes.<br />&nbsp;<br />A brand is simply the feelings or themes associated with an item or experience. When people think of you, your company, or your products or services, they probably already have some adjectives in mind. That is a brand.<br />&nbsp;<br />What can have a brand? Practically any noun has a brand. Your dog, cockroaches, a bridge you travel, your mother-in-law, the governor, and Homeland Security, to name a few. Each evokes a certain connotation when mentioned. Even some experiences such as sky diving have a brand.<br />&nbsp;<br />Examples:<br /><br /><ul><li>An employee says, &ldquo;That team is difficult to work with.&rdquo; That team&rsquo;s brand includes the theme &ldquo;not helpful.&rdquo;</li><br /><li>A user says, &ldquo;Rather than improve my efficiency, this piece of software is making me less productive.&rdquo; That software product&rsquo;s brand includes the theme &ldquo;not intuitive&rdquo; or &ldquo;buggy.&rdquo;</li><br /><li>An employee who has a great reputation for getting things done. That person&rsquo;s brand includes the theme &ldquo;productive.&rdquo;</li><br /><br /></ul> So what about a completely new company, product, or service? Surely that doesn&rsquo;t have a brand, right? Well, brand attributes are transferable. For instance, customers could hear about a new offering and say: &ldquo;I am not going to buy that because once you sign a contract with that type of offering or company, you don&rsquo;t get the promised support.&rdquo; A new company takes on additional attributes from its founders.<br />&nbsp;<br />So really your goal in a branding exercise is to better manage or even change your brand&rsquo;s themes and messages and also to differentiate your brand so that it is distinguishable from other brands. You want to influence the picture that pop&rsquo;s into people&rsquo;s heads when they think of your brand. That&rsquo;s not always as simple as adjusting your messaging; in fact often, especially with mature brands, upleveling brand perception requires a dedicated effort to deliver that delightful customer experience the brand already aspires to.<br />&nbsp;<br />Yes, it can be hard work. But since the market consistently moves to commoditize every product and service to create a race to the bottom for costs and fees, brand management and brand differentiation are absolutely necessary for brand success.<br />&nbsp;<br /><strong>Other thoughts</strong><br />&nbsp;<br />Here are some related topics I might hit in future articles:<br /><br /><ul><li>Branding is about perception, not reality.</li><li>Be willing to hear about negative things people say about your brand, so you can address them.</li><li>Brand magic: Be who you say you are.</li><li>Why do some brands succeed in the short-term and fail in the long-term?</li></ul> <strong>About Ann</strong><br />&nbsp;<br />Ann has been writing about branding since at least 2007 when she created a job hunter boot camp, titled &ldquo;Personal Marketing 101: The Brand Called You.&rdquo; She would love to work with you on your next white paper project or any other compliance or security documentation you need.&nbsp; Reach Ann using the <a href="https://www.logicalwriters.com/reach.html" target="_blank">Contact page</a>.&nbsp;&nbsp;</div>]]></content:encoded></item><item><title><![CDATA[Win Ratios as High as 75%]]></title><link><![CDATA[https://www.logicalwriters.com/blog/win-ratios-as-high-as-75]]></link><comments><![CDATA[https://www.logicalwriters.com/blog/win-ratios-as-high-as-75#comments]]></comments><pubDate>Sat, 09 Feb 2019 23:00:06 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.logicalwriters.com/blog/win-ratios-as-high-as-75</guid><description><![CDATA[By Ann Grove, Logical's President      Photo credit: Unsplash   True story: I once helped a client go from winning an average of one out of 10 Requests for Proposal (RFPs) to winning 12 out of 15. In other words, they went from a 10% win ratio to 75%. For my three crazy months with them, we won won won.&nbsp;Another success: a different client had an existing customer that issued an RFP specifically written to my client&rsquo;s perceived weaknesses. After reviewing our response, the customer can [...] ]]></description><content:encoded><![CDATA[<div class="paragraph"><span style="color:rgb(42, 42, 42)">By Ann Grove, Logical's President</span><br /></div>  <div><div class="wsite-image wsite-image-border-none " style="padding-top:10px;padding-bottom:10px;margin-left:0px;margin-right:0px;text-align:center"> <a> <img src="https://www.logicalwriters.com/uploads/1/0/5/2/105297913/win-rato_orig.jpg" alt="Picture" style="width:auto;max-width:100%" /> </a> <div style="display:block;font-size:90%">Photo credit: Unsplash</div> </div></div>  <div class="paragraph">True story: I once helped a client go from winning an average of one out of 10 Requests for Proposal (RFPs) to winning 12 out of 15. In other words, they went from a 10% win ratio to 75%. For my three crazy months with them, we won won won.<br />&nbsp;<br />Another success: a different client had an existing customer that issued an RFP specifically written to my client&rsquo;s perceived weaknesses. After reviewing our response, the customer canceled the RFP and continued retaining my client.<br />&nbsp;<br />More typically, I help organizations that have a 10 to 15% win ratio; together we increase the win ratio to 35 to 50%.<br />&nbsp;<br /><strong>A good foundation</strong><br />&nbsp;<br />Of course, these organizations have a good foundation to build on. They typically have an understanding of their own strengths and the strengths of competitors, a system to identify opportunities, and a system to make good go-no go decisions to ensure they aren&rsquo;t shooting blind. They also have some great, willing client references. Still the win ratio doesn&rsquo;t align with these strengths.<br />&nbsp;<br /><strong>Incorrect focus</strong><br />&nbsp;<br />The most common problem that depresses an organization's win ratio is that it values holding down expenses more than it values increasing sales. It saves money by not hiring a skilled RFP writer or perhaps not hiring enough of them or not deploying technologies that allow a team to scale. Therefore, a significant portion of RFP responsibilities fall to others such as sales, business development, administrative, and technical personnel. Although some organizations believe that sales and business development professionals are well positioned for proposal development because they are intimately familiar with clients and sales messaging, these people are talkers, not writers. Because the gold is still in the phone for the most part, let&rsquo;s keep those people talking and find someone else to do the writing. But don&rsquo;t look to technical and administrative parties to pick up the slack; they are unlikely to get exceptional results due to the burdens of their primary (sometimes billable) roles.<br />&nbsp;<br /><strong>Some bad math</strong><br />&nbsp;<br />The irony is that making do in this case doesn&rsquo;t actually make sense mathematically. How much is an organization saving if the lack of a solid proposal generation infrastructure is keeping the win ratio at 10 to 15% instead of 35 to 50%? Besides suppressing revenue, this approach holds down the average deal size, significantly limits the number of RFPs an organization can pursue, and distracts the organization.<br />&nbsp;<br /><strong>Win more often</strong><br />&nbsp;<br />Even without a dedicated writer, it is possible to win more often by doing what that top-notch writer would do. He or she would help the proposer differentiate and stand apart from competitors based on factors in addition to price.<br />&nbsp;<br />Think about the RFP process &ndash; it is designed to create a level playing field so that the buyer can compare apples to apples. An RFP demands a structured response that drives buyers and proposers to view offerings as commodities with a heavy emphasis on price. In fact, the RFP system is founded on the belief that all offerings are roughly equivalent.<br />&nbsp;<br />The only way to combat this push toward commoditization is differentiation. The winning offer stands out from the pack, demonstrating that the winner is proposing not merely an apple but a superior fruit. The response points out how the buyer will not be well served by an apple. This doesn&rsquo;t eliminate consideration of price but it does demote its importance by placing it within the context of other factors. I&rsquo;m not talking about using slippery sales language. I&rsquo;m talking about helping the buyer understand its true needs. For instance, my responses often include follow-up questions that the buyer may want to put to short-listed vendors, to deepen the buyer&rsquo;s understanding of proposed offerings.<br />&nbsp;<br /><strong>Conclusion</strong><br />&nbsp;<br />Let&rsquo;s get to the bottom line. What is required to win more often? An organization begins winning more when it realizes that the RFP response and any short-list presentation are opportunities to address the requirements hidden behind the stated RFP requirements.<br />&nbsp;<br /><strong>About Ann</strong><br />&nbsp;<br />Ann Grove, president of Logical Writing Solution, Inc., helps security teams and security vendors with all sorts of communication including RFP responses, proposals, and statements of work. She also helps enterprises with security policies and documentation. Learn more at&nbsp;<a href="https://www.logicalwriters.com/" target="_blank">https://www.logicalwriters.com</a>&nbsp;or call Ann at <a href="tel:17178913282">+1.717.891.3282</a>.&nbsp;<br /></div>]]></content:encoded></item></channel></rss>