- CISO Series Newsletter
- Posts
- Even With All These Security Vendors We Still Have Glaring Gaps
Even With All These Security Vendors We Still Have Glaring Gaps
Defense in Depth
Even With All These Security Vendors We Still Have Glaring Gaps
There are thousands of cybersecurity vendors across categories. If there's a gap in the market, it's likely not for technical reasons. So, how do you actually find vendors that are a good fit rather than one that just meets technical requirements?
Check out this post by Joe Head of REFLEX Solutions for the discussion that is the basis of our conversation on this week’s episode, co-hosted by me, David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Ajit Girn, CIO, Employment Development Department (EDD).
Listen to the full episode here.
Built for vendors, not users
Security tools keep failing users not because of technical failings but because of how they're conceived. "Most security tools are still designed from the top down," said Rayve Malhotra of EFT Consultants. "They reflect what vendors want to control, not what users actually experience. That's why so many of them feel clunky, overbuilt, or disconnected from real workflows." The alternative is a different philosophy, security that feels like "clarity: quiet, adaptive, and built to guide, not overwhelm. The tools aren't the problem. The philosophy is." John Denham of Judge.me pointed to a specific version of that mismatch in the small business market. The biggest issue is "the slavish regurgitation of popular security frameworks and controls that, while entirely valid, are simply overkill for a lot of small startup businesses, resulting in rolled eyes and disinterest." The pitch too often fails to understand business appetite.
Signal versus noise
The tool problem is also about how they fail to work together. "Integration and orchestration become key," said Martin Kuppinger of KuppingerCole Analysts. The question is how tools can integrate more easily "instead of creating new siloes of security data." Security telemetry pipelines, shared signals, and orchestration will determine whether organizations can manage the tools they already have and those being added. John Germain of Security Moments cut to what actually needs fixing, saying, "We invest too much energy reacting to alerts and trying to fight through all the noise," he said. The foundations that matter most are identity and access management, vulnerability management, and training and awareness. "There is no reason why we should not push back on vendors to make more secure products and stop allowing them to transfer the responsibility for fixing them back to the consumer."
Priced out
Small and midsize businesses are critical to the economy and to critical infrastructure supply chains, yet the security industry largely treats them as an afterthought. "I work with partners and SMB customers all the time who feel utterly priced out, overwhelmed, and frustrated with the space," said Mark Fermin of Ingram Micro. "SMB is the majority of businesses in this country, they are crucial vendors in critical infrastructure supply chains. Yet there's only a handful of companies that focus on these customers." Kris Jones of AI Acquisition identified that mid-market organizations carry enterprise-level security needs but lack the budgets to hire the experts or maintain the tools those needs requirem, saying "Consolidation and simplification are the name of the game here."
The elegance gap
Security's complexity isn't an inherent feature of the domain. "It comes down to poor lazy design," said Jai Balasubramaniyan of StrikeReady. He pointed to networking as the counterexample: Ethernet congestion handled through binary backoff, reliable transmission through TCP/IP, routing through link-state and distance-vector protocols. "With security, everything is a point solution with many configuration options left to the user," he said. "The story repeats everywhere," he added. "Forget SMB, even enterprise and SOC administrators struggle daily and crave for simplicity."
Please listen to the full episode on your favorite podcast app, or over on our blog, where you can read the full transcript. If you’re not already subscribed to the Defense in Depth podcast, please go ahead and subscribe now.
Huge thanks to our sponsor, ThreatLocker
Subscribe to Defense in Depth podcast
Please subscribe via Apple Podcasts, Spotify, YouTube Music, Amazon Music, Pocket Casts, RSS, or just type "Defense in Depth" into your favorite podcast app.
Super Cyber Friday
Join us next Friday for “Hacking M&A”
No Super Cyber Friday this week, but join us on Friday, July 10, 2026, for : “Hacking M&A: An hour of critical thinking about the questions nobody asks before signing.”
It all kicks off at 1 PM ET / 10 AM PT, when David Spark will be joined by Geoff Belknap, co-host, Defense in Depth, and Karl Mattson, founder and managing director, Squared Circle Ventures, for an hour of insightful conversation and engaging games. And stick around for our always-popular meetup, hosted right inside the event platform.
Or register once for every upcoming Super Cyber Friday event. No need to sign up week to week.
Help us get the word out! Share next week’s Super Cyber Friday registration link on LinkedIn, tag me (David Spark) and CISO Series, and you'll be entered for a chance to win an item from our prize store. We'll randomly pick one winner from everyone who shares.
Cybersecurity Headlines - Department of Know
Our LIVE stream of The Department of Know happens every Friday at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.
Friday’s episode will feature Howard Holton, outgoing CEO, GigaOm, and David Cross, CISO, Atlassian. Join us on YouTube and catch up on what shaped the week in security.
Thanks to our Cybersecurity Headlines sponsor, Silent Push
Which podcast host would you let AI edit out?
Has AI already changed how you consume content? Or not yet?
Some of the biggest names in cyber media dug into that topic on our latest Defense in Depth episode, with David Spark, the producer of CISO Series, Dave Bittner, producer and host, The CyberWire, Graham Cluley, host of Smashing Security podcast, and Leo Laporte, founder of TWiT (This Week in Tech) and host of Security Now podcast.
Give it a listen, then tell us what you think. Listen to the full episode here.
Big thanks to our sponsor, Palo Alto Networks
Participate! Add our live shows to your calendar
Learn more about all of the fun ways you can participate, and add our events to your calendar.
Google Calendar, iCalendar, Outlook, or export an .ics file
Cyber chatter from around the web...
Jump in on these conversations
"Snyk laid off up to 30% of their staff today" (More here)
"Bad cybersecurity by Secret Service agents put US officials at risk, inspector general says" (More here)
"Do businesses actually care about cybersecurity?" (More here)
Cybersecurity Headlines - Daily News Shorts
Subscribe to the CISO Series YouTube channel, for daily shorts videos from CISO Series reporter, Rich Stroffolino. You can find all of the stories he’s covered, plus new content every weekday, at the Cybersecurity Headlines Shorts YouTube playlist.
Thank you for supporting CISO Series and all our programming
We don’t just say we appreciate your feedback; we incorporate it into our programming. Learn more about all of the fun ways you can participate.
We love all kinds of support: listening, watching, contributions, What's Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.






