I will thread my answer here. Quick background for perspective: went to school 11 years after high school. Worked for a service provider as on of three employees total. Worked in a SOC for a global ICS manufacturer. Worked in every major vertical. Here's my thoughts on why:
First, we need to understand the myriad of businesses. They HATE spending money on security. Unless you are a security reseller, security is a cost sink. Yes it is insurance in the form of risk reduction, but to most CFOs and SMBiz owners, its a painful budgetary line item.
And this split into hyper specialists and hyper generalists has been and will continue to be amplified by budgets. In the land of OpEx, services get deducted. FTEs don't.
These orgs don't understand security. I don't expect them to. C level execs are hyper specialists themselves. If your lucky a CISO has a seat at the table. Else you hope the CLO understands the value of measured risk reduction.
Anyone who's worked at a large enough org knows you don't want to deploy any sec vendor's all in one suite. Everyone does something well. And any company with an All in One suite will absolutely do some things crap.
You can follow @DefenderExiled.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.