Live data from Hacker News

Why there are so many cybersecurity vendors and where do we go from here

ventureinsecurity.net

31–40 of 61 posts

Re: Why there are so many cybersecurity vendors and where do we go from here

#31
Because the people with purchasing authority know nothing about security, they are unable to distinguish real, good security practices and products from defective, over-hyped, and/or pointless "security" products constantly shilled at them.

In other words, "cybersecurity" is a "Market for Lemons": https://en.wikipedia.org/wiki/Market_for_lemons

   A lemon market will be produced by the following:
    
   1.    Asymmetry of information, in which no buyers can accurately assess the value of a product through examination before sale is made and all sellers can more accurately assess the value of a product prior to sale
   2.    An incentive exists for the seller to pass off a low-quality product as a higher-quality one
   3.    Sellers have no credible disclosure technology (sellers with a great car have no way to disclose this credibly to buyers)
   4.    Either a continuum of seller qualities exists or the average seller type is sufficiently low (buyers are sufficiently pessimistic about the seller's quality)
   5.    Deficiency of effective public quality assurances (by reputation or regulation and/or of effective guarantees/warranties)

Re: Why there are so many cybersecurity vendors and where do we go from here

#33

Earlier quoted context omitted.

That's not far off from a pew pew map[0]. Maybe you could start the first pure-play, best-in-breed security visualization company with AI-enabled[1] executive dashboards[2] 0 - https://www.csoonline.com/article/562681/8-top-cyber-attack-... 1 - disclaimer: not actually AI enabled 2 - pew pew map

It's called Cyber Ranges. SafeBreach, SimSpace, and Cymulate do similar stuff. That said, there is value to this (testing security policies before pushing to enforcement)

No, not really. Cyber ranges are a very distinct concept/product category than threat visualization maps like you might see here: https://livethreatmap.radware.com/ or here: https://isc.sans.edu/data/threatmap.html

Cyber Ranges (and pew pew maps) are also very different than control validation tools like Cymulate or Safe Breach…

Re: Why there are so many cybersecurity vendors and where do we go from here

#34

Earlier quoted context omitted.

It's called Cyber Ranges. SafeBreach, SimSpace, and Cymulate do similar stuff. That said, there is value to this (testing security policies before pushing to enforcement)

No, not really. Cyber ranges are a very distinct concept/product category than threat visualization maps like you might see here: https://livethreatmap.radware.com/ or here: https://isc.sans.edu/data/threatmap.html Cyber Ranges (and pew pew maps) are also very different than control validation tools like Cymulate or Safe Breach…

Fair enough! I skimmed the comment and didn't read the entire thing. It's also not the segment I specialize in within the space

Re: Why there are so many cybersecurity vendors and where do we go from here

#35
post #18

Earlier quoted context omitted.

Sure, but there are SOME that aren't selling snake oil. I'm invested in one of them. But yeah, most are. I guess the interesting question for me is how long does it take for the real wheat to stand out from the chaff.

Honestly, I think the wheat becomes chaff. You might have an amazing product that solves a relevant security issue but Enterprise sales cycles and checkbox driven procurement force you to incorporate half baked features in order to capture the next fad. Look at the XDR hype train 3 years ago, ZTNA 2 years ago, and the whole CNAPP/CASB/CSPM buzzword BS Tbf, I am being a bit dramatic about it, but I feel the split pers…

Such is as it's always been. A few years ago, I worked for a B2B enterprise data security firm. We didn't sell snake oil at all -- but our customers were so used to hearing snake oil salesmen talk that they had very odd demands that didn't improve their security. And in some cases, reduced it.

Dealing with those expectations was always an issue.

Re: Why there are so many cybersecurity vendors and where do we go from here

#36
post #6

Earlier quoted context omitted.

Most times, you would get ten times the value by taking the money you would spend on these tools, hiring a security engineering department, and letting them build you tools backed by open source software.

If those security engineers are even remotely qualified for their jobs they will not build their own tools.

crazy statement, probably crypto(graphy) related?

Re: Why there are so many cybersecurity vendors and where do we go from here

#37
post #6

Earlier quoted context omitted.

Most times, you would get ten times the value by taking the money you would spend on these tools, hiring a security engineering department, and letting them build you tools backed by open source software.

What logic did you use to come up with that statement? Tools like Nessus and Burpsuite Pro cost around 6-8k/year. Good luck hiring a security engineering department on a 8k/year budget that will build and maintain you tools of similar quality lol.

Tools like Nessus and Burpsuite Pro are not the ones I'm talking about.

Go take a look at the CSPM or CASB or CNAPP space and check the costs on some of these tools.

Re: Why there are so many cybersecurity vendors and where do we go from here

#38
post #31

Because the people with purchasing authority know nothing about security, they are unable to distinguish real, good security practices and products from defective, over-hyped, and/or pointless "security" products constantly shilled at them. In other words, "cybersecurity" is a "Market for Lemons": https://en.wikipedia.org/wiki/Market_for_lemons A lemon market will be produced by the following: 1. Asymmetry of informa…

The purchasers increasingly have the knowledge, but not necessarily the budget. Those who have the budget can justify implementing in-house.

Re: Why there are so many cybersecurity vendors and where do we go from here

#39
post #35

Earlier quoted context omitted.

Honestly, I think the wheat becomes chaff. You might have an amazing product that solves a relevant security issue but Enterprise sales cycles and checkbox driven procurement force you to incorporate half baked features in order to capture the next fad. Look at the XDR hype train 3 years ago, ZTNA 2 years ago, and the whole CNAPP/CASB/CSPM buzzword BS Tbf, I am being a bit dramatic about it, but I feel the split pers…

Such is as it's always been. A few years ago, I worked for a B2B enterprise data security firm. We didn't sell snake oil at all -- but our customers were so used to hearing snake oil salesmen talk that they had very odd demands that didn't improve their security. And in some cases, reduced it. Dealing with those expectations was always an issue.

Agreed! I was a bit dramatic with the whole "snake oil" statement, but managing buyer expectations and competitive pressures is definetly a grating experience.

Re: Why there are so many cybersecurity vendors and where do we go from here

#40

It's all checkbox driven development. I'm a PM in the space and it's all snake oil. At least we have amazing ACVs compared to other B2B sectors and a captive market. F** Gartner and Forrester for forcing us to concentrate on this instead of actually solving problems

I work at one vendor currently and have worked at a few prior. The difference is astounding - my previous gigs, including one of the biggest vendors ever was exactly as you said. My current gig is exactly the opposite - strong focus on real security insights and value, none of the box-ticking bs, and a great roadmap. It is rare, but when everyone at the org, and especially the product side really know how attacks play out - you can make a real impact on the world.
Post reply on HN