Live data from Hacker News

Why there are so many cybersecurity vendors and where do we go from here

ventureinsecurity.net

21–30 of 61 posts

Re: Why there are so many cybersecurity vendors and where do we go from here

#21

I'm curious on what keeps the prices for these products so high. You'd think with the kind of competition this industry has (all providing the same type of functionality, kinda), you'd see more of a race to the bottom. But when you go to quote, you start seeing a really bizarre pattern where it's almost the same price per feature across the board. I'm not saying it's price fixing, but something's not right here.

My sense is "you get what you pay for" logic applies here and naturally the vendors will exploit this. I also imagine the internal negotiation between whoever wants to purchase the software and the bean counters inevitably includes "sure it's a lot, but how much would a data breach cost us?"

Re: Why there are so many cybersecurity vendors and where do we go from here

#22
post #3

There is also another issue with cybersecurity vendors that this article doesn't touch on, and that's in the area of cloud security where many of them started targeting a specific use case or set of use cases, and have slowly expanded to overlap with other vendors who were not previously competitors. It's not good enough for a tool to just be used for Cloud Security Posture Management (CSPM) - it also has to do CI/CD…

Too many people do too much. I would rather pay 10 vendors a few K per year than get sucked into one vendor one tool suite. Let people focus dammit.

Re: Why there are so many cybersecurity vendors and where do we go from here

#23
post #18

It's all checkbox driven development. I'm a PM in the space and it's all snake oil. At least we have amazing ACVs compared to other B2B sectors and a captive market. F** Gartner and Forrester for forcing us to concentrate on this instead of actually solving problems

Sure, but there are SOME that aren't selling snake oil. I'm invested in one of them. But yeah, most are. I guess the interesting question for me is how long does it take for the real wheat to stand out from the chaff.

Honestly, I think the wheat becomes chaff.

You might have an amazing product that solves a relevant security issue but Enterprise sales cycles and checkbox driven procurement force you to incorporate half baked features in order to capture the next fad.

Look at the XDR hype train 3 years ago, ZTNA 2 years ago, and the whole CNAPP/CASB/CSPM buzzword BS

Tbf, I am being a bit dramatic about it, but I feel the split persona sales cycles we're forced to deal with incentivizes checkbox driven development.

Re: Why there are so many cybersecurity vendors and where do we go from here

#24

It's all checkbox driven development. I'm a PM in the space and it's all snake oil. At least we have amazing ACVs compared to other B2B sectors and a captive market. F** Gartner and Forrester for forcing us to concentrate on this instead of actually solving problems

Its not all snake oil, but box checking is snake oil.

Yep, and the sales cycles and personas we target force us into incorporating features or messaging due to checkboxes.

Re: Why there are so many cybersecurity vendors and where do we go from here

#25

My startup idea is cybersecurity software that does literally nothing. My competitive advantage would be speed, ease of use, low attack surface area, and perfect false positive rate.

I'm sorry to tell you, but it would fail. Being too fast would preclude creating attachment through the sunk costs required to run it. The ease of use would let users quickly determine that the software can't do what they want. The low attack surface would avoid necessitating widespread organizational buy in. And the zero false positive rate would mean that it wouldn't move the needle on any metrics.

Re: Why there are so many cybersecurity vendors and where do we go from here

#26

I'm curious on what keeps the prices for these products so high. You'd think with the kind of competition this industry has (all providing the same type of functionality, kinda), you'd see more of a race to the bottom. But when you go to quote, you start seeing a really bizarre pattern where it's almost the same price per feature across the board. I'm not saying it's price fixing, but something's not right here.

We prefer to target F1000/enterprise markets. The ACV is quite high and VCs often require this.

Channel sales/VARs is used to target much more price conscious buyers

Re: Why there are so many cybersecurity vendors and where do we go from here

#27

My startup idea is cybersecurity software that does literally nothing. My competitive advantage would be speed, ease of use, low attack surface area, and perfect false positive rate.

That's not far off from a pew pew map[0]. Maybe you could start the first pure-play, best-in-breed security visualization company with AI-enabled[1] executive dashboards[2]

0 - https://www.csoonline.com/article/562681/8-top-cyber-attack-...

1 - disclaimer: not actually AI enabled

2 - pew pew map

Re: Why there are so many cybersecurity vendors and where do we go from here

#28

>Where do we go from here? Take a step back, and look at history. It should be unsurprising that the problem was encountered, studied[0] and solved, decades ago. During the Viet Nam conflict, the Air Force needed to plan missions with multiple levels of classified data. This couldn't be done with the systems of that era. This resulted in research and development of multi-level security, the Bell-LaPadula model[2], an…

AV is a very small part of the Cybersecurity space.

Re: Why there are so many cybersecurity vendors and where do we go from here

#29

My startup idea is cybersecurity software that does literally nothing. My competitive advantage would be speed, ease of use, low attack surface area, and perfect false positive rate.

That's not far off from a pew pew map[0]. Maybe you could start the first pure-play, best-in-breed security visualization company with AI-enabled[1] executive dashboards[2] 0 - https://www.csoonline.com/article/562681/8-top-cyber-attack-... 1 - disclaimer: not actually AI enabled 2 - pew pew map

It's called Cyber Ranges.

SafeBreach, SimSpace, and Cymulate do similar stuff.

That said, there is value to this (testing security policies before pushing to enforcement)

Re: Why there are so many cybersecurity vendors and where do we go from here

#30
GitHub Advanced Security is so expensive. I can’t see the benefit considering we have a SonarCloud instance which is 1/3 of the cost. All our credentials are stored in vaults or IaC, so one of their main selling features we don’t need.

When ever there’s a sales team in front of a service it seems like the service isn’t worth the cost.

Post reply on HN