Notes on decisions our buyers are making.
One for each area we cover, and nothing that is already on a vendor's blog. Each one separates a decision rather than defining a category.
Three questions, sold as one
Attack surface management, vulnerability management and control validation answer three different buying questions. Owning one does not remove the need for the other two.
Identity securityThe directory is the floor everything else stands on
A directory drifts through ordinary administration, not through mistakes. That is why a point-in-time audit and continuous assessment are different products.
Human layerThe half that gets cut
Training a user to report creates a queue. Most programmes buy the training and never staff the queue, which teaches people that reporting achieves nothing.
Secure workspaceEvery application moved into the browser. The management did not.
Every business application opens in a browser, and company data now leaves through it into models nobody procured. Three routes are open, and two are migrations.
Endpoint securityDeciding before you know
An executable nobody has seen before is about to run. Every endpoint product is an answer to that one moment, and they differ in what they do without an answer.
Threat intelligenceA feed is not intelligence. The question is who reads it.
A global feed is raw material an analyst turns into a decision. Who is going to read it decides which of two very different products you need.
DeceptionAn alert with nothing left to judge
Every other detection source produces a probability an analyst has to assess. What a source costs to triage matters as much as what it finds.
Data and cryptographyResidency is written about storage and tested on the key
Residency rules are written about where data sits and enforced on who can produce the key. A tender asks the second question in the words of the first.