Live data from Hacker News

Why there are so many cybersecurity vendors and where do we go from here

ventureinsecurity.net

11–20 of 61 posts

Re: Why there are so many cybersecurity vendors and where do we go from here

#13
post #6
post #2

It's a gross industry designed to milk big dollars out of clueless customers. Listening to these 'security experts' talk makes me roll my eyes roll so hard that I'm afraid they'll get stuck in the back of my head.

Most times, you would get ten times the value by taking the money you would spend on these tools, hiring a security engineering department, and letting them build you tools backed by open source software.

What logic did you use to come up with that statement?

Tools like Nessus and Burpsuite Pro cost around 6-8k/year.

Good luck hiring a security engineering department on a 8k/year budget that will build and maintain you tools of similar quality lol.

Re: Why there are so many cybersecurity vendors and where do we go from here

#15
post #6
post #2

It's a gross industry designed to milk big dollars out of clueless customers. Listening to these 'security experts' talk makes me roll my eyes roll so hard that I'm afraid they'll get stuck in the back of my head.

Most times, you would get ten times the value by taking the money you would spend on these tools, hiring a security engineering department, and letting them build you tools backed by open source software.

If those security engineers are even remotely qualified for their jobs they will not build their own tools.

Re: Why there are so many cybersecurity vendors and where do we go from here

#16
The proliferation of security vendors is similar to the proliferation of weight loss clinics and gyms. There are plenty of fads, with new businesses popping up to either chase or create the interest. The people buying these services desperately want something which can plug into their existing habits without significant changes.

Similarly, the solutions for cybersecurity are simple but not easy. It involves operational and administrative discipline. Businesses which lack this discipline collide with security problems and spend a great deal of money downstream of this problem. Vendors sell what businesses want to buy, not necessarily what is most effective.

Re: Why there are so many cybersecurity vendors and where do we go from here

#17
It's all checkbox driven development. I'm a PM in the space and it's all snake oil. At least we have amazing ACVs compared to other B2B sectors and a captive market.

F** Gartner and Forrester for forcing us to concentrate on this instead of actually solving problems

Re: Why there are so many cybersecurity vendors and where do we go from here

#18

It's all checkbox driven development. I'm a PM in the space and it's all snake oil. At least we have amazing ACVs compared to other B2B sectors and a captive market. F** Gartner and Forrester for forcing us to concentrate on this instead of actually solving problems

Sure, but there are SOME that aren't selling snake oil. I'm invested in one of them. But yeah, most are. I guess the interesting question for me is how long does it take for the real wheat to stand out from the chaff.

Re: Why there are so many cybersecurity vendors and where do we go from here

#19

I'm curious on what keeps the prices for these products so high. You'd think with the kind of competition this industry has (all providing the same type of functionality, kinda), you'd see more of a race to the bottom. But when you go to quote, you start seeing a really bizarre pattern where it's almost the same price per feature across the board. I'm not saying it's price fixing, but something's not right here.

If you’re selling snake oil you don’t want your oil cheaper than others’ or it’s obviously snake oil.

So you end up all on a line (costing more would be ridiculous, of course).

Re: Why there are so many cybersecurity vendors and where do we go from here

#20

It's all checkbox driven development. I'm a PM in the space and it's all snake oil. At least we have amazing ACVs compared to other B2B sectors and a captive market. F** Gartner and Forrester for forcing us to concentrate on this instead of actually solving problems

Its not all snake oil, but box checking is snake oil.
Post reply on HN