Security vendor management

Most organisations own more security tooling than they use and renew it without ever asking what it caught. The spend is rarely the problem. The absence of anyone independent reviewing it is.

Why this needs to be independent

Almost everyone offering to review your security tooling also sells security tooling, or earns a margin on what they recommend. That does not make their advice wrong, but it does mean you cannot tell.

Solusec does not resell products and takes no commission on any platform. We have nothing to gain from you buying anything, which means the recommendation is occasionally that you should spend less, cancel something, or keep the tool you already have and configure it properly. That answer is difficult to get from a reseller.

Reviewing the estate you already have

We start with what you own rather than what you might buy. Every tool is assessed on what it is genuinely doing, which is a different question from what it is licensed to do.

  • Overlap. Paying three vendors for the same capability is common, usually because tools arrived from different budgets at different times.
  • Shelfware. Licensed, deployed, and producing nothing anyone reads. Frequently bought to satisfy a questionnaire.
  • Unused capability. The feature you already pay for that would replace the thing you are about to buy. This is the finding that most often pays for the review.
  • Configuration. Whether the tool is in a mode that actually does something, or in the monitoring mode it was put into during deployment and never taken out of.

Renewals

Renewals arrive with a date attached and get approved because the alternative is a gap. We work backwards from the renewal with enough time to have options: what it delivered over the term, what the realistic alternatives are, what the market rate looks like, and whether the requirement still exists. Knowing you are willing to leave is worth more at a renewal than any argument about features.

Overseeing managed providers

If you outsource security monitoring or IT to a provider, someone has to check whether the contract is being honoured, and the provider is not a neutral party to that question. We review what is actually being delivered against what was agreed: response times against the incidents that happened rather than the service level document, coverage against your real estate, what is escalated and what is quietly closed, and whether the reporting reflects reality.

This is normally the piece of work that returns the most, because it is the one nobody in the organisation is positioned to do.

Selecting something new

Where you do need to buy, we help define the requirement before anyone sees a demonstration, keep the evaluation to criteria that came from your environment rather than from a vendor battlecard, and sit in on the technical sessions. Vendors give better answers when someone in the room can tell whether the answer was a real one.

Common questions

Do you resell any of the products you review?

No. Solusec sells services, not software, and takes no commission, referral fee or margin from any vendor. It is the reason this advice is worth taking.

Will you manage the vendors for us day to day?

No, and we would be cautious of anyone who offered. Ownership of the relationship should stay with you. We provide the review, the challenge and the technical judgement at the points where they matter, which is renewal, escalation and selection.

How do you charge for this?

On time, as consultancy, either as a defined piece of work or as part of an ongoing fractional arrangement. We do not charge a percentage of anything we save you, because that creates an incentive to recommend cutting things.

What if we are happy with our current provider?

Then the review says so, and you have independent evidence for the board rather than an assumption. Confirming that a provider is doing what you pay for is a legitimate and common outcome.

Is this the same as a fractional CISO?

It is one part of it. A fractional CISO engagement covers strategy, risk and governance as well, with vendor oversight as one of the responsibilities. Where you only need the tooling question answered, this stands on its own.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.