Most vendor evaluation processes are built to survive procurement, not to protect you eighteen months after go-live. Here’s the gap almost nobody catches before signing.
Outlining The Problem
The majority of security technologies need 90 days just to establish an accurate behavioural baseline and fair comparison.
Please remember your existing solution has learnt about you over years ! With the average proof of concept window offered at 14 days, is this genuinely going to be sufficient for a realistic comparison โ specifically if you have a concern over detection and response responsiveness.ย
Sit with that for a second.ย ย
During your vendor selectionย process, you’reย being asked to make a multi-year, budget-defining decision based on a test window thatย isn’tย long enoughย truly measure real world performance, not a scripted example incident or investigation, you could beย makingย a decisionย on partial insights.ย ย
And yet, somehow, thousands of contracts get signed every year on exactly that basis.ย Driven by sales volumes and targets, notย real-worldย customer experiences.ย Start any process with sufficient time that does not make a renewal point in time your main decision criteria!ย
Many Customers still reference selecting aย globally recognised security partnerย rather than the best fit for your organisation.ย Thatโsย not a lapse in judgementย but with the global accelerationย of AI offensive and defensive capabilities,ย does it have a sound basis. It’s often the more defensible decision in the room. Find out more about AI Cybersecurity.ย
If something goes wrongย or gets throughย later, at least you can point to a logo everyone recognises, a trusted brand. Vendors know it,ย justย like they know changing or transitioning between solutions creates work and risk,ย which is exactly why brand recognition sells soย wellย and they push for longer contract commitments.ย ย
Frankly, no-one should be agreeing to contracts greater than 24 months โ the world of security is changingย so quickly.ย
Technologies alone do not protect organisations from major Cyber events.ย ย
The Vendor Selection Process Gap Nobody Prices In
Thereย areย gapsย between how vendors sell,ย how solution capabilities performย over timeย and how attackersย actually operateย and exploit. Attack evasion is one of the key tactics and techniques adopted at presentย and that gap exposes aย vendor evaluation processย thatย hasn’tย kept paceย or focuses on only specific protection areas.ย ย
Whilst responsiveness is a keyย considerย metric,ย many solutions package their service as a closed box solution. Proprietaryย andย one way APIย integrations, constrainsย the ability of security solutions to correlate and analyse autonomously.ย ย
We want to walk you through what gapsย looks like, because once you see them,ย you know what to go looking for.ย And ifย you’veย got a renewal quote sitting in your inbox right now, this is worth ten minutes of your time before youย considerย signingย anything.ย
Attackers Don’t Care About Your Vendor’s Logoย
Think like an attackerย –ย Brandย recognition means almost nothing to the person trying to breach you.ย They want your data,ย perhaps moneyย via ransom or avoiding a potential breach, and the least difficult pathway to achieving this โ evenย whilst using generative AI to speed up and complete the heavy lifting parts.ย ย
The gaps between solutions in users, processes, agentic workflows andย indirect injections, jailbreaking, promptย leakingย and stolen credentials (usernames, process IDโs, APIย keysย and tokens) are where most attacks will originate.ย ย
Far more any observability and alerting!ย
Threat actors are more sophisticated, more persistent and will pivot many more times than you think, generative AI drivenย attacks, in whole or part, whether discovery or executionย focused, is more readily understand in attack graphs than logic.
The pointย is,ย the attacker mindset really does not put any focus onย which vendor’s logo is on your dashboard.ย
Take long tail attacks as an example. Malicious code gets inserted into trusted package managersย inย variousย software marketplaces. They obfuscate initial detection because the code verification tools do notย identifyย these behaviours in rapid soak testing.ย ย
The issuesย bypassย securityย checks andย then sits dormant. It might notย emergeย for monthsย and when it does, it isย very lowย level and offers on IOC characteristics which is how most of the security vendor toolsย seekย to verify activity, destination hosts and services and pattern analysis.ย ย
When it finally doesย trigger suspicion, the questionย isn’tย “did we buy the right brand?”ย It’sย “how quickly can we tell a true positive from noise, and howย effective is our response and how do we identify data exfiltration or persistence?”.ย ย
Now โ did you ask these questions in your Demo?ย
The realย world is a combination of how well technology, people,ย agentsย and processesย combine, specificallyย under pressure.ย Agents as they become increasingly autonomous, will need to support the investigation interaction state, with context of decision points and reasoning, something AI is notย very goodย at.ย ย
Again โ did you ask this during your Demo?ย
Theย POCย Trapย
POCโs areย very powerful, but provingย newย security outcomes can be complex and lengthy.
A purchasing led process where technologies with processes, logic and customisationย must beย tested,ย will require a more nuanced multiple disciplinary approach.ย So why do smart, experienced buyers keep running aย vendor evaluation processย thatย isn’tย long enoughย or solelyย commerciallyย focused?ย
- Longer POCโs need resourcing on both sides โ shorter cycles suit theย sellerย but you must resource any POC appropriately to test and achieve your objectivesย
- Longer POCโs do not fit neatly into a sales team’s quarterly targetsย so be prepared to position and confirm this based on your requirements.ย ย
- Aย clean, scripted demo ofย aย vendor’sย best features in a narrow, controlled environmentย will not meetย the majority ofย user requirements.ย ย
Know your security gaps and use this as a basis to measure closure testing during POC. Rememberย most behavioural analysis tools need around 90 days just to start baselining accuratelyย and autonomous decision making inย investigation,ย responseย and containment.ย ย
There’sย a deeper issue underneath this. Increasingly,ย it’sย genuinely difficult to tell the difference between technologyย that’sย been rapidly built with generative AI and adaptation techniques, and technologyย that’sย been properlyย establishedย and stress tested over years. Slickย doesn’tย mean solid. Fastย doesn’tย mean fieldย proven.ย ย
ย
Additional Questions to Ask in any Demoย
The UK’s incoming Cyber Security and Resilience Billย is expected to extend regulatory accountability further into supply chains and managed service relationships, meaning the resilience of the vendors you choose increasingly becomesย yourย liability, not justย theirs, particularlyย if you operate inย financial services,ย utilities, or theย public sector, where scrutiny is highest.
A rushed vendor evaluation processย doesn’tย just risk buying the wrong tool,ย it risks inheriting aย compliance gapย youย didn’tย knowย you’dย signed up for.ย
VMwareย customers had over a decade of stable operations before Broadcom’s acquisition suddenly put their entire relationship, and their ability to remain a customer at all, into question.ย ย
Think about this in terms of change of ownership is this can fundamentally change your service.ย If the vendor will not support a change of ownership clause, and many do not, then this is a broader consideration but with high impact.ย
It’sย becoming aย pattern across the cybersecurity market, where the largest vendors have grownย substantially throughย acquisition rather than organic development.ย
That growth comes with a cost that rarely makes it into the sales deck: integration debt.ย ย
When a vendor buys another company, that new capabilityย doesn’tย always get properly folded into the core platform.
Sometimesย it’sย bolted on as a side bundle.ย Sometimes the transition is poorlyย executedย or the acquired talent suddenlyย departs.ย The product team can become defocused, spread across a growing portfolio instead of concentrated on the thing youย actually bought.ย ย
And customer success, the part of the relationshipย that’sย supposed to help you adopt and embed the technology, can quietly slip down the priorityย listย or disappear to be integrated or replaced by the acquirer.ย
Larger organisations tend to have bigger marketing budgets, and bigger marketing budgetsย don’tย correlate with faster innovationย or better solutions.ย Look at the ratio of marketing budget as percentage of overall revenueย andย compared to R&D budgets.ย
This is a leading indicator of where any cyber organisation is prioritising.ย If anything, the opposite is often true.ย ย
So,ย whenย you’reย weighing up vendor size as a proxy for safety, ask yourself whatย you’reย really buying: a strong product roadmap, or a strong brand with a lot of moving parts youย can’tย see from the outsideย or a brand which may be consumed and not in a good way!ย
The Four Questions Almost Nobody Asksย
Most vendor conversations focus on what the technology doesย and unit price. Almost none focus on what happens afterย you’veย signed.ย Time to think differently, andย it’sย an easy fix.ย
Before your next demo, or before you renew anything, ask these four questions and pay close attention to howย they’reย answered, not justย what’sย said.ย
Question 1:ย What do the first 90 daysย actually lookย like?ย ย
Not the end state, the onboardingย and initial service.ย What’sย requiredย from your team? What does “go live” genuinely mean, and when does it happen? A vague, brochure style answerย here is a warning sign. A vendorย who’sย honest about the time and effort involved is one worth trusting.ย
Question 2:ย Can you walk me through a real incident that looks like something we might face?ย
Demos are clean by design. Real incidents are messy.
Ask how response timesย actually getย measured, how communication flows between you and the vendor, and how escalation works when something genuinely nuanced comes up. Are all aspects ofย Incident Response included in the service, isย aย Tabletop Exerciseย with a prospective vendorย in POC available?
All of whichย will tell you more than any slide deck.ย ย
This is where you find out ifย there’sย a single point of dependency sitting in your organisation thatย nobody’sย accounted for.ย
Questionย 3:What’sย the most common reason customers like usย don’tย renew with you?ย ย
Nobody enjoys being asked this.ย Thatโsย exactly whyย itโsย worth asking.ย ย
An honest answer, one that names real failure modes like poor alert tuning, alert only escalationย or management gaps,ย areย green flags.ย You need to see and review the proposed RACI service delivery matrix.ย ย
Deflection is a red flag, and it tells you something important about how that vendor handlesย difficult conversations, which is exactly whatย youโllย need from them during an incident.ย
Question 4:ย What happens when we go our separate ways?ย ย
This is the question everyone forgets, andย it’sย arguably theย most important one in a security context. Will you keep your dataย and reports? What does the offboarding process look like? Can you export your full incident history?ย
If youย can’t, you lose your baseline, and a new platform coming in,ย has toย start learning from scratch.ย It also needs to be in placeย some timeย before service decommissioning.ย Continuous improvement and your key security metricsย don’tย disappear just becauseย you’veย switched providers. Losing that trend data is a real, lasting gap.ย
Get the Gap Analysis Done Independentlyย
Beforeย you’reย even in the room with a vendor, yourย vendor evaluation processย needs to start with an honest,ย independent assessmentย of what your organisationย actually needsย and where the current gaps are.ย
An independent consultancy, or a solution provider who wants to be your partner for the next decade rather than your account for this quarter, brings something a vendor never can: a broad, enterprise level view of how technology actually gets adopted, and the realism to tell you where it’s likely to go wrong.ย
That word, adoption, is worth sitting with. It is a shared responsibility but the onus remains firmly with the customer. Guardrails, Training, Continual Awareness, Data readiness, Governance, Oversights, Outcome measurement, Cost optimisations, Security testing, these are the foundational business responsibilities. ย
It’sย usually associated with something far more human and considered than softwareย or model versions, andย there’sย a reason for that. Bringingย a new technologyย into your organisation properly, so it becomes business as usual rather than an expensive thing sitting on a shelf, is a genuinely involved process.ย
If any representative is using business data, whether it is a corporate paid for tool or shadow IT/AI, the business isย ultimately accountable.ย ย
Treating it as a checkbox at the end of procurement is exactly how gaps stay open even after the contract is signed.ย They are unmonitored with no defined accountability and with such a high rate of change, gaps will grow very quickly.ย ย
What This Actually Means for Youย
Ifย there’sย one thing worth taking away from all of this,ย it’sย this:ย Adoption, not size,ย unit price,ย modelย versionย orย brand. Security should never be an annual event, be that a penetration or responsiveness test or procurement activity.ย ย
Suitability has a shelf life.ย ย
A vendor genuinelyย operatingย with continuous improvement should make you feel more confident about staying, not less, well before your renewal date arrives.ย ย
Ifย you’reย locking intoย three-yearย contracts becauseย that’sย just how theย vendor positions it, or complex cost of change,ย you’reย notย necessarilyย buying certainty.ย So,ย ifย you’veย got a renewal quote in your inbox right now,ย don’tย start by reading it.ย ย
Start by going back to basics.ย ย
What’sย the actual organisational need or gap you were originally trying to close?ย What will challenge your business over the next 6 months.ย
How is itย changing? Baseline your current provider, and any alternative, against that gap honestly, ideally with someone who has no stake in which technology you choose.ย
Then ask them the four questions above. Watch how they answer, not just what they say.ย And get it in writing.ย ย
If your current provider can’t give you straight answers on onboarding, real incident handling, churn, and exit, that’s not a reason to panic. It’s information.
And it’s exactly the kind of information that should have shaped your decision theย first-timeย round.ย
We’d rather you made that decision with your eyes open, whoever you end up choosing. If you want aย second, independentย pair of eyesย on your current gap analysis before your renewal date arrives, that’s a conversation we’re always happy to have.ย
