RJ Friedman is a 10x CISO, 3x MSSP founder, board member, and CEO of NecessityWorks.
I’ve spent my career on both sides of the cybersecurity vendor conversation. I’ve worked in sales for security companies, served as the CISO for more than 10 organizations and eventually started my own managed security service provider (MSSP) before founding a software company. That path has given me an unusual vantage point: I know how vendors think, and I know what buyers actually need.
One of the reasons I started my first MSSP was frustration with what I kept seeing. Clients were buying products based on a marketing slide, only to find the tools didn’t perform as promised, and someone else would have to come in to clean up the mess. The problem is that most security leaders are too busy to scrutinize every vendor claim, and cybersecurity marketing teams tend to tell buyers exactly what they want to hear. Salespeople often know the highlights and not much more, and they may be working against a quota.
That doesn’t mean every vendor is acting in bad faith. But it does mean buyers need to pay close attention to the process.
Red Flags
Even before you evaluate a product, pay close attention to the buying process itself. Long-term lock-in contracts are one of the clearest warning signs. Three- or five-year deals serve the vendor’s accounting needs, not yours. The shift toward usage-based pricing, where you pay for what you actually use, reflects a more honest relationship. When I’m selling software, I’d rather a customer come back when the timing is right than lock them into something that ends up not being used. A vendor pushing a multiyear commitment is signaling a lack of faith in their own product.
Vague technology claims are another signal worth noting: a refusal to demo, a hand-waved proof of concept or unclear answers about how AI is actually implemented inside the product. Everyone claims to have AI now, but what does that mean for the specific tool you’re evaluating? Understanding how a vendor actually applies it matters for your own third-party risk management practices.
Green Flags
Any vendor worth your time can explain how their technology works and connect it directly to your specific needs and environment. Willingness to run a real proof of concept is also a positive sign. I know a proper POC takes time and effort, and smaller organizations often don’t have the bandwidth. But when a vendor offers it, grab the chance.
The most overlooked but possibly most important sign of a good vendor is one that tells you they’re probably not the right fit. A vendor that says, “This probably isn’t the best fit right now; let’s revisit in six months,” is thinking beyond their next closed deal. You can even test for this by planting a question or two you already know the answer to and see whether the salesperson is willing to be honest if the answer reflects poorly on their product. It’s the cybersecurity equivalent of a car salesman steering you away from the wrong (but expensive) vehicle.
Research Smarter
AI has made it far easier to cut through marketing language and get to what a product actually does. Anyone with access to a capable model can do meaningful adversarial research. Most vendors publish public API documentation, which you can pull into an LLM and compare against the vendor’s marketing materials. Ask the model to flag discrepancies in these and also any inconsistencies in follow-up emails and meeting notes. Describe your environment and ask what alternatives you should actually be considering.
Peer networks are still important, too. CISOs and CIOs who have used the product firsthand are more valuable than any reference a vendor handpicks. Events like Black Hat, DEF CON and BSides are good places to find honest conversations about what’s working and what isn’t.
Ask The Hard Question First
Even as a software CEO, I will still say that between people, processes and technology, the latter is usually the least urgent of the three. Undertrained staff and unworkable processes will undercut even the best tool. More often than not, when an organization buys a solution before it’s operationally ready, it creates additional work and potentially introduces new vulnerabilities.
Before you listen to any vendor’s pitch, ask yourself what the gap in your security posture really is. Is it a technology problem, or is it more of a people or process problem? That question will tell you more than most vendor conversations ever will, which is why CISOs who make smart purchasing decisions ask it before entering any evaluation.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


