Case studies | Governance, risk and compliance success stories | Protecht

James Hardie vendor assurance case study | Protecht

Written by Protecht | Aug 21, 2026, 2:01:33 AM

A manual, questionnaire-led process made vendor security reviews slow for James Hardie’s cybersecurity team and frustrating for the wider business. With VISO TRUST, the team introduced greater automation, improved consistency and cut review turnaround from weeks to minutes.

A global business needs a scalable process

James Hardie is a global manufacturer of exterior home and outdoor living products. Its portfolio is marketed and sold across North America, Europe, Australia and New Zealand, supported by more than 5,000 employees and 19 manufacturing facilities.

For Jeff Deakins, CISO and Vice President of IT at James Hardie, this scale made a repeatable approach to vendor assurance essential.

The company needed to understand the security risks introduced by third parties without creating a process that slowed the business down. Yet its initial approach depended heavily on manual questionnaires, follow-up calls and specialist review.

James Hardie’s vendor assessment results to date

James Hardie uses VISO TRUST to analyze vendor security evidence, replacing a slow, questionnaire-led review process with faster, more consistent assurance.

Started with vendor evidence, not another lengthy questionnaire The team can upload existing evidence, such as a SOC 2 Type II report, for VISO TRUST to analyze, reducing the follow-up and interpretation required before a meaningful review can begin.
Cut vendor security-review turnaround from weeks to minutes Reviews that previously took five to eight weeks can now typically be completed in around 15 minutes, helping the cybersecurity team respond at the pace the business needs.
Focused specialist attention on the exceptions that matter VISO TRUST highlights areas requiring further attention, so cybersecurity specialists can concentrate on applying context, investigating gaps and making informed risk decisions.
Created a more consistent and scalable assurance process By automating routine evidence analysis, James Hardie can handle vendor reviews more consistently without relying on additional manual effort simply to keep pace with demand.

About Protecht and VISO TRUST

Protecht acquired VISO TRUST in 2026 to help customers assess vendors faster, reduce the manual work behind assurance and focus specialist attention on the risks that matter most. VISO TRUST brings AI-powered analysis of vendor security evidence to a process that too often still depends on lengthy questionnaires and manual review.

The hidden work behind a vendor assessment

The process began with the cybersecurity team creating and distributing a questionnaire that could contain more than 100 questions.

The questionnaire might initially reach a vendor’s salesperson rather than someone with detailed knowledge of the company’s security controls. The team would then wait for a response, follow up on incomplete answers and try to establish whether the information provided was accurate.

Even those responses that appeared to be complete still required interpretation. Security specialists had to work through the answers and make a judgment about whether the vendor presented an acceptable level of risk.

For the business team waiting to use a new vendor, those timelines were difficult to reconcile with the pace at which it needed to operate.

“They want a decision within their lifetime,” Jeff says. “They don’t want to wait six, seven or eight weeks for an answer.”

Time was consumed at every stage: distributing the questionnaire, waiting for the right person to respond, clarifying answers, reviewing evidence and deciding what the findings meant.

“There’s no way to sustain it long term as a manual questionnaire and process. Think about the entire process, that could be a five, six, seven-week process…and then you’re making some life decisions as to whether this vendor is okay.”

Jeff Deakins
CISO, James Hardie

Looking for efficiency and effectiveness

Jeff and his team evaluated around half a dozen third-party risk management tools.

They needed more than a digital version of the existing questionnaire process. The selected solution had to provide a high level of automation, support faster decisions and remain straightforward for people outside the cybersecurity team.

Ease of use was particularly important when introducing third-party cyber risk processes to business users who were not accustomed to participating in them.

“If users aren’t used to doing third-party cyber risk, you have to make sure the process is very easy for them,” Jeff explains.

VISO TRUST stood out for its level of automation. It offered a way to improve both the efficiency of the process and the effectiveness of the assessment without creating another complicated step for the business.

Starting with evidence, not another questionnaire

With VISO TRUST in place, the team can begin with a vendor’s existing security evidence rather than defaulting to a lengthy questionnaire.

Where a vendor has a SOC 2 Type II report, for example, the team uploads it to VISO TRUST. The platform analyzes the evidence and typically returns its findings within five to ten minutes, highlighting exceptions that require further attention.

This gives the team a structured initial risk view. Instead of manually reading every document and interpreting every questionnaire response, cybersecurity specialists can concentrate on the areas that require human judgment.

The team can then perform additional due diligence based on the vendor’s circumstances and communicate its conclusions to the relevant business stakeholders: the risks identified, what they mean and what the business should consider before proceeding.

Automation handles the repetitive evidence analysis. Jeff and his team remain responsible for applying context and making the risk decision.

Reviews in 15 minutes, not five to eight weeks

A vendor security review that previously took five to eight weeks can now typically be completed in around 10-15 minutes. Within that time, the team can receive the automated findings, examine relevant exceptions and begin communicating a risk view to the business.

“We’re faster and more consistent,” Jeff says.

The improvement also changes the resource equation. Without automation, increasing assessment volumes would require more people simply to maintain the process.

By reducing the effort required for routine evidence analysis, James Hardie can direct scarce cybersecurity expertise toward the gaps, context and decisions that genuinely require it.

“Without VISO TRUST, we would need 10 or 15 people. And are you really going to get the budget for 10 or 15, when you have a need in identity or incident response or somewhere else?”

Jeff Deakins

A wider opportunity for TPRM teams

The savings on manual work that Jeff describes are not unique to James Hardie.

VISO TRUST analyzed 36,856 vendor assessments across 93 organizations to find exactly where the time goes and what it’s costing in The TPRM Efficiency Index report. The research estimates that AI-assisted workflows reduced artifact-review time by 66%, saving an average of 17 hours for each assessment.

Across the complete dataset, this represents an estimated 630,563 TPRM labor hours reclaimed.

These aggregate findings show how much specialist capacity can be tied up in collecting, reading, mapping, validating and following up vendor evidence. Releasing that capacity gives teams more time to investigate control gaps, apply business context and make informed risk decisions.

Find out more and request a demo

The TPRM Efficiency Index

Explore the hidden cost of manual vendor assurance and the potential time savings of AI-assisted evidence analysis.

Download now

VRM solution

See how Protecht and VISO TRUST help teams accelerate vendor assurance, focus on material relationships and connect vendor intelligence with enterprise risk action.

Find out more

See it all in action

Request a demo to see how AI-powered evidence analysis can help streamline vendor security reviews.

Request a demo

About James Hardie

James Hardie is an industry leader in exterior home and outdoor living solutions, with a portfolio spanning fiber cement, fiber gypsum, composite and PVC decking, and railing products. Its brands are marketed and sold across North America, Europe, Australia and New Zealand. James Hardie employs more than 5,000 people globally and operates 19 manufacturing facilities.

About Protecht and VISO TRUST

Protecht helps organizations manage enterprise risk, resilience and compliance in a connected way. VISO TRUST brings AI-powered analysis of vendor security evidence to third-party risk processes, helping teams reduce the manual effort behind vendor assurance and focus specialist attention on the exceptions that require it.

Together, Protecht and VISO TRUST help organizations make faster, more informed decisions about vendor risk and connect those insights to enterprise risk action.