Intro

Situation 1: A security engineer, reading another zero-day disclosure and analysis paper, starts drafting a new detection rule for it, wondering if the work they do brings any value to the company.

Situation 2: A company executive, eager to secure the business, goes into a vendor selection process. Looking through the identical offers, they resort to reviews from an analytical company. Settling on the vendor, requesting the proposal and seeing the final invoice, they decide they had been doing fine without protection.

Situation 3: A presale of a cybersecurity company converses with the client to find the most suitable solution. They are forced to bundle a couple of unneeded products on top of the core offering – sales directive. They know the solution is technically sound and works – but it requires multiple integrated modules, which makes the invoice prohibitively expensive, forcing the client to stick with the bare essentials and degrading the efficiency below the threshold.

Hopefully, none of the above sounds familiar to you. It does to me, which prompted me to stop and look back, trying to understand how we arrived at a point where even a need as simple as ‘we want security’ remains unfulfilled.

The Critique

To address the elephant in the room: we are not selling snake oil. Cybersecurity is (un)fortunately required.

But it is my opinion that currently it suffers from structural erosion due to induced opaqueness and product sprawl, creating an unmet client need and developing chronic disillusionment since the value between the parties involved is almost never fairly exchanged.

Opaqueness

Security through obscurity is a known anti-pattern developed in cryptography, with best practice being ‘system design should be known, verified and improved’ while the key - its exact configuration - remains a secret, ensuring security. In an almost poetic way, the cybersecurity industry did exactly the opposite, with obscurity being put on a pedestal as long as it drives sales and profits.

There is no simple way to compare vendors and/or their products. From my experience, word of mouth, personal connections and third-party analytics are the things that currently work. Until a more transparent, open comparison is made possible, cybersecurity will reap the dubious monetary premium, simultaneously damaging the customers’ goodwill in the long run. The step in the right direction, although not perfect, was made with MITRE ATT&CK evaluations, which are supposed to work as a benchmark for EDR-class products.

Harder still is the inherent industry opaqueness. Cybersecurity to me seems utility-like, akin to a healthcare system: you never notice it while everything works, but urgently need it when something breaks. I doubt I’m the first one to use that analogy. The constant background maintenance without clear feedback is what creates the juxtaposition of visible costs and invisible value. This is a given and cannot be realistically solved.

Furthermore, you can’t reliably predict the first link to fail. What will it be? Is it your heart? Your liver? Lungs, perhaps? When you’re picking health insurance, you need to cover as much as you can, just in case. Which brings us to the next topic: product sprawl.

Sprawl

Cybersecurity is not a novel area. It went from inception in the 80s, through puberty in the 90s and adolescence in the 00s, to adulthood in the 10s and seeming maturity in the 20s - so where’s the unified approach?

Frequent shifts in the IT landscape produce novel classes of threats that completely undermine previously established security baselines. Thus new solutions are required, feeding the sprawl. There is rarely a cut-off, however. More often than not, companies gradually accumulate a zoo of cybersecurity products, ranging from legacy solutions that are no longer used to novel, unproven technologies, each adding another layer of complexity to an already fragmented security stack.

The usual lack of qualified management (because it’s hard to retain skilled people long enough to gain the needed experience without them switching over to more lucrative and healthy/relaxed fields like AI/SWE) exacerbates this problem further, preventing a clear strategy of matching means to ends with the company’s resources.

This is further worsened by the asymmetric, pulse-like nature of security work: to justify constant cybersecurity spending, managers and teams have to constantly come up with ways to show the value they bring, which usually leads to uncontrolled proliferation of security products inside the company, as it is the simplest visible metric. That’s how we arrive at sprawl from the client side.

Well then why can’t we consolidate and maintain just a few core companies and products? Ultimately, that is where we’re moving. It won’t necessarily solve the problem though, as having a select few vendors does not mean their solutions are better or more cost-effective. Once a company carves a niche with a baseline solution, it’s only natural to try and re-use it for adjacent markets without going through the full R&D cycle all over again. Yes, it will likely be worse than the dedicated alternative in that niche, but as long as some clients are captured – the incentive is there. And that’s how we arrive at tool overload from the vendor side. And the longer the product exists, the more commercially exploitative it becomes to drive the company’s revenue and profit, nullifying its original value.

Furthermore, proper consolidation, in my opinion, is prevented by structural reasons. Similar to software development, almost no barrier to entry means startups coming up with solutions faster or even better compared to established companies. Government regulation and compliance keep legacy vendors afloat and lock down niches from newcomers. The muddied intersection of cybersecurity and government interests also introduces some barriers to entry to local markets and props up national champions. The industry by its nature is incentivized to remain fragmented.

Writing this, I realize how strikingly similar cybersecurity looks compared to the AI craze given similar opaqueness and sprawl.

The Solution

Naturally, the question arises: can we improve? We should strive to reach a proper equilibrium of fulfilled business needs for a fair cost.

To combat the opaqueness, we should welcome transparency through benchmarks, demos, comparisons and pricing. We need to win customers by the quality of our offerings and not by the deals under the table and predatory monetization.

To combat the sprawl, we need skilled management. It’s a tight rope to walk: addressing the real risk with constrained resources while making executives understand how and where the money is being spent and what value is being received. Understanding where value is made and where it is merely transferred is the first and most important step. Knowing what kind of risk the business is facing and how it is best addressed is the value created; the compliance checkboxes, redundant tools and analyst reports are the value transferred to someone else’s pocket. Spending review and aggressive cuts to obsolete and legacy threats and tooling with focus on novel research should be common sense.

It’s neither going to be easy nor fast. But I sincerely hope one day the security-aware company executive uses an available transparent metric to find the most suitable cybersecurity company, reaches out to them and receives a fair, cost-effective offer of minimally required solutions to mitigate the risk, enabling security personnel to carry on their duties with a clear vision of their worth.

P.S.: Worth the read