I've been in security longer than most job applications ask for. Every security solution is just the same Black Box with a one-trick-pony in it. After the 40th one, they all kinda blur together after awhile. They all have accounts and permissions and reporting and maintenance and update processes and a way to store the data they create...and a single line on a single tab on a single webpage that 'does the trick'. I'm…
> Every security solution is just the same Black Box with a one-trick-pony in it. This is a cultural problem in the information security space and one reason why I've left that space. I call this "checkbox compliance" culture. Most customers want a box they can rack, check the box on a compliance audit, and move on. Very few companies actually give a shit about security as a practice or philosophy, and don't actually…
'I don't know Security, so I'm going to pay an MSSP to do it for me.'
This is not a bad thing, per se, it just means that their controls are ceded to a company who has marketing, shareholders, management layers, and _they_ want to optimize _their_ costs....so the protection of your organization will be 1/n of the response team's attention...where N is the number of other companies they're responsible for monitoring.
It's POSSIBLE that you'll get better support by letting an expert multiply their skills across a larger population of targets...it's just not LIKELY.