Most vendor evaluation processes are built to survive procurement, not to protect you eighteen months after go-live. Here’s the gap almost nobody catches before signing.
Outlining The Problem
The majority of security technologies need 90 days just to establish an accurate behavioural baseline and fair comparison.
Please remember your existing solution has learnt about you over years ! With the average proof of concept window offered at 14 days, is this genuinely going to be sufficient for a realistic comparison – specifically if you have a concern over detection and response responsiveness.Â
Sit with that for a second. Â
During your vendor selection process, you’re being asked to make a multi-year, budget-defining decision based on a test window that isn’t long enough truly measure real world performance, not a scripted example incident or investigation, you could be making a decision on partial insights. Â
And yet, somehow, thousands of contracts get signed every year on exactly that basis. Driven by sales volumes and targets, not real-world customer experiences. Start any process with sufficient time that does not make a renewal point in time your main decision criteria!Â
Many Customers still reference selecting a globally recognised security partner rather than the best fit for your organisation. That’s not a lapse in judgement but with the global acceleration of AI offensive and defensive capabilities, does it have a sound basis. It’s often the more defensible decision in the room. Â
If something goes wrong or gets through later, at least you can point to a logo everyone recognises, a trusted brand. Vendors know it, just like they know changing or transitioning between solutions creates work and risk, which is exactly why brand recognition sells so well and they push for longer contract commitments. Â
Frankly, no-one should be agreeing to contracts greater than 24 months – the world of security is changing so quickly.Â
Technologies alone do not protect organisations from major Cyber events. Â
The Vendor Selection Process Gap Nobody Prices In
There are gaps between how vendors sell, how solution capabilities perform over time and how attackers actually operate and exploit. Attack evasion is one of the key tactics and techniques adopted at present and that gap exposes a vendor evaluation process that hasn’t kept pace or focuses on only specific protection areas. Â
Whilst responsiveness is a key consider metric, many solutions package their service as a closed box solution. Proprietary and one way API integrations, constrains the ability of security solutions to correlate and analyse autonomously. Â
We want to walk you through what gaps looks like, because once you see them, you know what to go looking for. And if you’ve got a renewal quote sitting in your inbox right now, this is worth ten minutes of your time before you consider signing anything.Â
Attackers Don’t Care About Your Vendor’s LogoÂ
Think like an attacker – Brand recognition means almost nothing to the person trying to breach you. They want your data, perhaps money via ransom or avoiding a potential breach, and the least difficult pathway to achieving this – even whilst using generative AI to speed up and complete the heavy lifting parts. Â
The gaps between solutions in users, processes, agentic workflows and indirect injections, jailbreaking, prompt leaking and stolen credentials (usernames, process ID’s, API keys and tokens) are where most attacks will originate. Â
Far more any observability and alerting!Â
Threat actors are more sophisticated, more persistent and will pivot many more times than you think, generative AI driven attacks, in whole or part, whether discovery or execution focused, is more readily understand in attack graphs than logic.
The point is, the attacker mindset really does not put any focus on which vendor’s logo is on your dashboard.Â
Take long tail attacks as an example. Malicious code gets inserted into trusted package managers in various software marketplaces. They obfuscate initial detection because the code verification tools do not identify these behaviours in rapid soak testing. Â
The issues bypass security checks and then sits dormant. It might not emerge for months and when it does, it is very low level and offers on IOC characteristics which is how most of the security vendor tools seek to verify activity, destination hosts and services and pattern analysis. Â
When it finally does trigger suspicion, the question isn’t “did we buy the right brand?” It’s “how quickly can we tell a true positive from noise, and how effective is our response and how do we identify data exfiltration or persistence?”. Â
Now – did you ask these questions in your Demo?Â
The real world is a combination of how well technology, people, agents and processes combine, specifically under pressure. Agents as they become increasingly autonomous, will need to support the investigation interaction state, with context of decision points and reasoning, something AI is not very good at. Â
Again – did you ask this during your Demo?Â
The POC TrapÂ
POC’s are very powerful, but proving new security outcomes can be complex and lengthy.
A purchasing led process where technologies with processes, logic and customisation must be tested, will require a more nuanced multiple disciplinary approach. So why do smart, experienced buyers keep running a vendor evaluation process that isn’t long enough or solely commercially focused?Â
- Longer POC’s need resourcing on both sides – shorter cycles suit the seller but you must resource any POC appropriately to test and achieve your objectivesÂ
- Longer POC’s do not fit neatly into a sales team’s quarterly targets so be prepared to position and confirm this based on your requirements. Â
- A clean, scripted demo of a vendor’s best features in a narrow, controlled environment will not meet the majority of user requirements. Â
Know your security gaps and use this as a basis to measure closure testing during POC. Remember most behavioural analysis tools need around 90 days just to start baselining accurately and autonomous decision making in investigation, response and containment. Â
There’s a deeper issue underneath this. Increasingly, it’s genuinely difficult to tell the difference between technology that’s been rapidly built with generative AI and adaptation techniques, and technology that’s been properly established and stress tested over years. Slick doesn’t mean solid. Fast doesn’t mean field proven. Â
Â
Additional Questions to Ask in any DemoÂ
The UK’s incoming Cyber Security and Resilience Bill is expected to extend regulatory accountability further into supply chains and managed service relationships, meaning the resilience of the vendors you choose increasingly becomes your liability, not just theirs, particularly if you operate in financial services, utilities, or the public sector, where scrutiny is highest.
A rushed vendor evaluation process doesn’t just risk buying the wrong tool, it risks inheriting a compliance gap you didn’t know you’d signed up for.Â
VMware customers had over a decade of stable operations before Broadcom’s acquisition suddenly put their entire relationship, and their ability to remain a customer at all, into question. Â
Think about this in terms of change of ownership is this can fundamentally change your service. If the vendor will not support a change of ownership clause, and many do not, then this is a broader consideration but with high impact.Â
It’s becoming a pattern across the cybersecurity market, where the largest vendors have grown substantially through acquisition rather than organic development.Â
That growth comes with a cost that rarely makes it into the sales deck: integration debt. Â
When a vendor buys another company, that new capability doesn’t always get properly folded into the core platform.
Sometimes it’s bolted on as a side bundle. Sometimes the transition is poorly executed or the acquired talent suddenly departs. The product team can become defocused, spread across a growing portfolio instead of concentrated on the thing you actually bought. Â
And customer success, the part of the relationship that’s supposed to help you adopt and embed the technology, can quietly slip down the priority list or disappear to be integrated or replaced by the acquirer.Â
Larger organisations tend to have bigger marketing budgets, and bigger marketing budgets don’t correlate with faster innovation or better solutions. Look at the ratio of marketing budget as percentage of overall revenue and compared to R&D budgets.Â
This is a leading indicator of where any cyber organisation is prioritising. If anything, the opposite is often true. Â
So, when you’re weighing up vendor size as a proxy for safety, ask yourself what you’re really buying: a strong product roadmap, or a strong brand with a lot of moving parts you can’t see from the outside or a brand which may be consumed and not in a good way!Â
The Four Questions Almost Nobody AsksÂ
Most vendor conversations focus on what the technology does and unit price. Almost none focus on what happens after you’ve signed. Time to think differently, and it’s an easy fix.Â
Before your next demo, or before you renew anything, ask these four questions and pay close attention to how they’re answered, not just what’s said.Â
Question 1: What do the first 90 days actually look like? Â
Not the end state, the onboarding and initial service. What’s required from your team? What does “go live” genuinely mean, and when does it happen? A vague, brochure style answer here is a warning sign. A vendor who’s honest about the time and effort involved is one worth trusting.Â
Question 2:Â Can you walk me through a real incident that looks like something we might face?Â
Demos are clean by design. Real incidents are messy.
Ask how response times actually get measured, how communication flows between you and the vendor, and how escalation works when something genuinely nuanced comes up. Are all aspects of Incident Response included in the service, is a Tabletop Exercise with a prospective vendor in POC available?
All of which will tell you more than any slide deck. Â
This is where you find out if there’s a single point of dependency sitting in your organisation that nobody’s accounted for.Â
Question 3:What’s the most common reason customers like us don’t renew with you? Â
Nobody enjoys being asked this. That’s exactly why it’s worth asking. Â
An honest answer, one that names real failure modes like poor alert tuning, alert only escalation or management gaps, are green flags. You need to see and review the proposed RACI service delivery matrix. Â
Deflection is a red flag, and it tells you something important about how that vendor handles difficult conversations, which is exactly what you’ll need from them during an incident.Â
Question 4: What happens when we go our separate ways? Â
This is the question everyone forgets, and it’s arguably the most important one in a security context. Will you keep your data and reports? What does the offboarding process look like? Can you export your full incident history?Â
If you can’t, you lose your baseline, and a new platform coming in, has to start learning from scratch. It also needs to be in place some time before service decommissioning. Continuous improvement and your key security metrics don’t disappear just because you’ve switched providers. Losing that trend data is a real, lasting gap.Â
Get the Gap Analysis Done IndependentlyÂ
Before you’re even in the room with a vendor, your vendor evaluation process needs to start with an honest, independent assessment of what your organisation actually needs and where the current gaps are.Â
An independent consultancy, or a solution provider who wants to be your partner for the next decade rather than your account for this quarter, brings something a vendor never can: a broad, enterprise level view of how technology actually gets adopted, and the realism to tell you where it’s likely to go wrong.Â
That word, adoption, is worth sitting with. It is a shared responsibility but the onus remains firmly with the customer. Guardrails, Training, Continual Awareness, Data readiness, Governance, Oversights, Outcome measurement, Cost optimisations, Security testing, these are the foundational business responsibilities. Â
It’s usually associated with something far more human and considered than software or model versions, and there’s a reason for that. Bringing a new technology into your organisation properly, so it becomes business as usual rather than an expensive thing sitting on a shelf, is a genuinely involved process.Â
If any representative is using business data, whether it is a corporate paid for tool or shadow IT/AI, the business is ultimately accountable. Â
Treating it as a checkbox at the end of procurement is exactly how gaps stay open even after the contract is signed. They are unmonitored with no defined accountability and with such a high rate of change, gaps will grow very quickly. Â
What This Actually Means for YouÂ
If there’s one thing worth taking away from all of this, it’s this: Adoption, not size, unit price, model version or brand. Security should never be an annual event, be that a penetration or responsiveness test or procurement activity. Â
Suitability has a shelf life. Â
A vendor genuinely operating with continuous improvement should make you feel more confident about staying, not less, well before your renewal date arrives. Â
If you’re locking into three-year contracts because that’s just how the vendor positions it, or complex cost of change, you’re not necessarily buying certainty. So, if you’ve got a renewal quote in your inbox right now, don’t start by reading it. Â
Start by going back to basics. Â
What’s the actual organisational need or gap you were originally trying to close? What will challenge your business over the next 6 months.Â
How is it changing? Baseline your current provider, and any alternative, against that gap honestly, ideally with someone who has no stake in which technology you choose.Â
Then ask them the four questions above. Watch how they answer, not just what they say. And get it in writing. Â
If your current provider can’t give you straight answers on onboarding, real incident handling, churn, and exit, that’s not a reason to panic. It’s information.
And it’s exactly the kind of information that should have shaped your decision the first-time round.Â
We’d rather you made that decision with your eyes open, whoever you end up choosing. If you want a second, independent pair of eyes on your current gap analysis before your renewal date arrives, that’s a conversation we’re always happy to have.Â
