How Senior CISOs Actually Vet Security Vendors

Interviews with senior CISOs on the questions they ask, the shelfware they're trying to avoid, and what they're really filtering for beneath the features and marketing.

Published on Aug 11, 2026
Mirren McDade Written by Mirren McDade
How Senior CISOs Actually Vet Security Vendors

The security vendor market is full to bursting, with more than 1,500 cybersecurity companies tracked in Momentum Cyber’s latest market map and the average enterprise running anywhere at 13. All that choice, yet the vendor offers tend to sound similar. Seemingly every product claims to be “AI-native”, assuring you that it will “reduce complexity”, and integrate cleanly with the tools you already have in place.

A good CISO needs to be able to cut through the claims and recognize the true indicators of value. Across the last year of interviews with senior security leaders, I have asked each one to explain their methodology for deciding which vendors to buy from and found that even when they came at the issue with different questions, putting their frameworks side by side revealed a shared logic. When you boil it down, they are all filtering for the same three things: trust, outcomes, and integration.

“How Can I Trust You?”

The first, and perhaps most essential question. Trust is the heart and the backbone of all good cybersecurity tooling.

For Lena Smart, former CISO at MongoDB and now AIUC-1’s first Ambassador, vendor evaluation starts with this question: How can I trust you?

Trust is the first hurdle because, according to Smart, much of the oversaturated market isn’t worth engaging with. “So many snake oil merchants out there these days,” she told me, “it’s hard to tell.”

Jeremy Powell, CISO at Sumo Logic, brings the same trust-first approach to a newer category: agentic AI vendors. Powell, who spent years on the vendor side (most recently as CTO at LockThreat GRC), evaluates them adversarially. “Show me the model, show me how it explains its reasoning, and show me how it makes a decision on a recommendation.” If you can’t trace the model’s reasoning back to a defensible source, Powell said, “it’s essentially just noise without signal.”

Fail this filter and the vendor doesn’t get to demonstrate anything else. Not the product, not the pricing, not the integration.

CISOs Buy Outcomes, Not Products

The second filter is outcomes, and Powell’s years on the vendor side gave him an inside view of how CISO buying decisions really get made.

“CISOs don’t buy features. They don’t buy technology. They buy outcomes. Full stop.”

The CISO thought process, Powell said, is: How do I reduce risk? How do I get time back? How do I become defensible to a board or an auditor?

The cost of buying features instead of outcomes is measurable. Osterman Research data on security spending puts shelfware as high as 28% of every security dollar, with up to 60% of security software going completely unused in some environments.

Powell, who has seen the pattern up close, knows that serious money is at stake: “Walk into any security program and you’ll see a quarter-of-a-million-dollar product that was implemented successfully but isn’t producing what the security organization or the CISO actually needs.”

Rob Black, founder of Fractional CISO, translates the outcome test into board language. “Just saying something is ‘high risk’ is very boring,” he told me. “The CEO hears about ‘high risk’ things all the time. But if you say, ‘there’s a 10% chance of a $5 million loss,’ that hits very differently.” Black’s framing works for vendor decisions too. If you can’t articulate the outcome a vendor is promising in dollars and probability, the CEO can’t approve the spend. And neither should you.

The Twelve-Tool Problem

Conor Sherman, who is now the Global CISO at Sysdig and was CISO in Residence when we spoke, gathered 15 security leaders at a Sysdig Cyber Advisory Board session. His conversations with these security leaders revealed a pattern in their observations, which was that the average enterprise now runs roughly a dozen security tools across code design, build pipelines, cloud infrastructure, and production workloads. That’s a dozen tools that all have to work with each other, and each one creates an opening for something to go wrong.

Vorlon’s 2026 CISO Survey found a nearly identical number: 13 dedicated security tools across SaaS and AI environments. Both Vorlon and Sherman are measuring a specific slice of the security stack, not everything.

When you count every category of security tool an enterprise runs, not just the SDLC-to-runtime slice, a Gartner survey of 162 large enterprises put the average at 45 tools. Panaseer’s 2026 Security Leaders Peer Report puts it at 61.

Whichever number you go by, the issue remains that most enterprises are running more security tools than they can meaningfully manage. 82% of the security leaders Panaseer surveyed said monitoring and addressing the failure of existing controls would be more impactful than adding new tools.

“The goal isn’t to give security more tasks,” Sherman said. “It’s to provide them with a platform that evolves with the business and enables them to deliver real outcomes.”

He also named what “good” looks like on the integration side. “I need my engineering counterparts to experience security as a seamless extension of their workflow, not a separate, brittle layer.”

The integration filter isn’t about technical compatibility. It’s about whether the tool lives inside the workflow of the people who actually use it, or bolts on the side.

Why The Bar Keeps Rising

CISOs didn’t raise the bar by choice. They raised it because defenders can’t afford the same room for error that attackers can.

The Verizon 2026 DBIR calls it “the collapse of the defender’s timeline.” Attacker time-to-exploit on known vulnerabilities has shrunk from months to hours. For critical edge-device vulnerabilities, the median time between publication and mass exploitation is now zero days.

“We can’t just use some random untested AI, like the attackers can,” Matthew Rosenquist, who built Intel’s first SOC and now sits on 16 advisory boards, told me. “We can’t risk bringing an untested, unvetted tool into the environment, because if we bring down the environment, executive management goes, ‘Wait, you’re worse than the attackers! We’re paying you. You can’t do this.'”

For Greg Schaffer, founder of vCISO Services and the first CISO for Nashville’s Metropolitan Government, there’s another failure mode to watch for: treating vendor tools as the solution itself. He sees it most clearly in the SMB market he works in. “There are too many times where SMBs feel that if they just get the right tool in place, they’re secure,” he said. “They spend a lot of money on this, and there’s a whole industry of MSSPs encouraging that spend. But you could have every security tool in place and still get hacked if your processes, policies, and people aren’t up to snuff.”

Schaffer’s warning is that the vendor market rewards the illusion of a problem solved. For the CISOs I spoke to this isn’t enough, and they aren’t buying it — literally, or figuratively.

Three Gates Before You Buy

Three gates stand between the vendor and your spend. Each one has to be cleared before the next opens.

  • Gate 1 opens on trust – The vendor answers “How can I trust you?” and “What pain point are you solving for me?” in specifics (Smart). For agentic AI vendors, they also show their reasoning trace (Powell). Fail this one and the second meeting doesn’t happen.
  • Gate 2 opens on outcomes – The vendor states what they’re delivering in dollars and probability (Black). Fail this one and the pilot deployment doesn’t happen.
  • Gate 3 opens on integration – The vendor proves their tool lives inside your team’s workflow, not bolted on the side (Sherman), and they aren’t selling the illusion that their product replaces process, policy, or people (Schaffer). Fail this one and the contract doesn’t happen.

Different questions on the surface, but beneath that, three considerations: can they be trusted? Will they deliver? Will they fit in?

So What?

Scrutiny when it comes to vendor spend is essential.

CISOs who use frameworks like the ones discussed in this article save budget by cutting shelfware before it happens, build stronger programs by resisting fragmentation, and can defend their vendor choices to the board in the business language boards actually speak.

The vendor market rewards CISOs who ask the harder questions. Ask these questions now or answer for shelfware later.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Mirren McDade
Mirren McDade Senior Journalist & Content Writer

Mirren McDade is a senior writer and journalist at Expert Insights, spending each day researching, writing, editing and publishing content, covering a variety of topics and solutions, and interviewing industry experts.

She is an experienced copywriter with a background in a range of industries, including cloud business technologies, cloud security, information security and cyber security, and has conducted interviews with several industry experts.

Mirren holds a First Class Honors degree in English from Edinburgh Napier University.