Skip to content

Buying & Evaluation

A security purchase crosses more internal boundaries than almost any other software buy, and almost nobody writes about it from inside the room. This desk covers the mechanics: who is really in the committee, what triggers a budget line, whether a POC earns its cost, how questionnaires get used as a weapon, and how to retire a tool without leaving a hole.

8 pieces

PlaybookBuyingAugust 28, 2026

Killing a Tool: The Murder Board Nobody Runs

Security teams buy well and retire badly, which is how a stack reaches thirty tools. A murder board is the two-hour structure that makes a retirement decision defensible before it happens.

Decision BriefBuyingAugust 28, 2026

Should You Run a POC or Trust the Reference Call?

A proof of concept costs weeks of engineering time you are not accounting for. Two good reference calls cost ninety minutes. The choice turns on one question: is the failure you care about visible from outside?

Benchmarks on this desk

Tools

  • Security Tool Overlap Analyzer

    Enter your stack, see which tools cover the same control, and get an estimate of the spend sitting in the overlap.

  • POC Scorecard

    Score a vendor POC against fourteen weighted criteria, see the shape rather than just the total, and export a defensible summary.

Common questions: buying

How many people sit on a security buying committee?
Gartner's published range for a modern B2B buying group is five to sixteen people across as many as four functions. No analyst publishes a separate figure for cybersecurity specifically, and the widely repeated eight-to-fifteen claim is a third-party synthesis rather than measured data. Security purchases sit toward the upper end structurally, because the tool pulls in legal, procurement, privacy, and an architecture reviewer.
Who actually kills a security deal?
Most often a technical evaluator who never appears on a sales call. Security engineers and architects are asked for a private read on a product, they answer honestly in an internal channel, and the deal dies without the vendor ever hearing why. The economic buyer signs, but the technical evaluator holds the veto.
Is a proof of concept worth running for every security tool?
No. A POC earns its cost only when the failure mode you care about is invisible from outside: performance under real data volume, integration friction, or operational noise. For anything a reference customer can describe accurately, two well-chosen reference calls are faster, cheaper, and produce a better signal than a rushed thirty-day trial.