| | SEPTEMBER - 20189The other vendor is larger than you, significantly larger in fact and a publicly traded entity.Boeing runs a rigorous POC bake-off and decides to grant you their business.Incredible win! The team is pumped. And you've effectively plugged a hole that Boeing's legacy security suite was not protecting. This is known in the industry as a best-of-breed solution.CISOs like plugging holes with best-of-breed offerings.For many CISOs, it's a simple, three-step approach:1. Purchase and deploy a platform suite from one of the major vendors.2. Fill in gaps with best-of-breed point solutions.3. Protect the enterprise.And your company fits in this formula well, firmly positioned as a best-of-breed offering. You lack the presence of an incumbent platform, yet you maintain more scale and stronger tech than your younger competitors.A week later, you find yourself in another bake-off against the same two competitors. The outcome? You and the Series A startup lose; the incumbent wins.CISOs like sticking with brand name incumbents. You notice over the next few months that this appears to be a recurring theme. Your POC win-rate has begun to decline, and the large incumbent continues to take market share.Remember now, you decisively chose (not once, but twice) to pass on being acquired early on. However, as you made this decision, Palo Alto, McAfee and the rest of the 800-pound security gorillas were busy gobbling up your smaller competitors.So the adage goes... If they don't buy you, they'll buy your competitor. And it makes sense. Because these incumbents are so slow-moving, they are coerced to be acquisitive. They simply don't have the agility necessary to be innovative, so they instead focus on their bread and butter, while utilizing M&A to diversify their offerings.Since these security incumbents brandish proven go-to-market engines and an abundant number of channel partners through which to sell their offerings, they don't need to buy the winner in a category.They only need to buy a player.This is critical. When a customer has already purchased a network firewall, SWG, and DLP solution from the same vendor, it remains easier for that customer to stay with the brand they know and trust for upcoming security purchases.This is known in the industry as bundling out, and it works because:1. CISOs don't like switching / integration costs, which are expensive from a time and resource perspective.2. Legacy vendors can acquire practically any player in a nascent space and bundle this into their offering for little to no additional cost.We witnessed this to a tee in the CASB (Cloud Access Security Broker) space. Startups emerged. Rampant M&A occurred. Standalone vendors were bundled out.Microsoft acquired Adallom, Palo Alto Networks acquired CirroSecure, Cisco acquired CloudLock, Oracle acquired Palerra, Blue Coat acquired Elastica and Perspecsys, Symantec acquired Blue Coat, and McAfee acquired Skyhigh.Suffice it to say -- if you're part of a CASB startup that still hasn't been acquired, the above are some big names to compete against on a daily basis.And thus there exists a tension between platforms and point solutions in that:1. Although many CISOs would prefer the ease of having their entire infrastructure protected by one vendor, large platform vendors can't offer the best solution in every category. This forces CISOs to purchase best-of-breed solutions.2. Although many CISOs romanticize deploying best-of-breed solutions to fill all their vulnerability gaps, managing some 30+ vendors is incredibly difficult. This forces CISOs to stick with bundles offered through their existing platform vendor. If they don't buy you, they'll buy your competitor. And it makes sense. Because these incumbents are so slow-moving, they are coerced to be acquisitiveKareem Aly
<
Page 8 |
Page 10 >