Skip to content
The Cyber Security Place

Reference

What suppliers say about themselves, and what it is worth

Every entrant here composed its own description. Read a few hundred of them in sequence and the purchaser's real difficulty stops being abstract: the words that would help you search are the words everybody uses.

Last reviewed August 25, 2026

245 supplier listings, across 11 categories and 19 countries, each carrying the entrant's own account of what it does rather than any assessment. Split at the commas, those descriptions yield 44 distinct claimed capabilities, and the distribution is the finding: the commonest phrase is asserted by 10 businesses at once, so the terms a buyer would search for are exactly the ones that cannot separate two candidates. 243 listings carry a website, which is the only field a reader can check. A capability list states what a supplier wants to be considered for; the useful reading is subtractive, because omitting a popular phrase had to be a decision while including one did not. The shortlist should start from a stated problem rather than a category, since suppliers converge on capability words and diverge sharply on approach. A listing is a record, not an assessment.

What do suppliers call themselves?

Their own words, split at the commas and counted. Press a term to see who claimed it.

From the listings themselvesWhat 241 suppliers said they did

Each firm wrote its own specialty line. Split on the commas and counted, this is what they claimed — and how many of them claimed the same thing.

Nothing here was written for this page. The terms are the suppliers' own words, and the counts are how many used them. Read down the list and the difficulty of buying becomes visible: the phrases at the top are claimed by so many firms at once that they cannot separate any two of them, and the phrases far enough down the list to be distinctive are the ones nobody searches for.

The shape of the buyer's problem

Ranked, the claims form a steep curve, and where you sit on that curve determines whether a search returns everybody or nobody.

Network Security10Penetration Testing9Cyber Security8Cloud Security7Managed Security Services7Application Security6Data Protection6Risk Management6Mobile Security4Security4Vulnerability Management4Cloud3suppliers claiming each phrase, in their own words

The curve is the whole argument. At the summit sit phrases asserted by ten or more houses apiece, and those are precisely the phrases a buyer types into a search box. A search that returns everybody has told you nothing, and it has told you nothing in a way that feels like research.

Further down the curve the terms become specific enough to separate candidates — and nobody searches for them, because knowing which narrow phrase to type requires already understanding the market you are trying to enter. That is the trap: the vocabulary that would help you is only available to somebody who no longer needs it.

None of which is any supplier's fault. An entrant omitting the popular phrases would vanish from every search, so all of them oblige, and the resulting equilibrium is one where the description field cannot do the job it exists for. The conclusion is not that suppliers are dishonest. It is that this document type is the wrong instrument for choosing, and using it that way is a category error rather than a lapse of diligence.

The equilibrium has a name in other trades. Where every seller must display the same badge to stay visible, the badge stops carrying information and becomes an entry fee — a cost everybody pays and nobody benefits from. Restaurant awards, professional memberships and compliance certificates all drift the same way once possession becomes universal, and the honest response is identical in each case: move the judgement to whatever the badge cannot cover.

What a listing can and cannot tell you

Worth separating carefully, because the two categories look similar on the page and behave completely differently in a decision.

It establishes that the business existed, and where. A name, a location, a category, a website. Dull, verifiable, and the foundation of everything else — you cannot evaluate a supplier you cannot find.

It can tell you what they wanted to be considered for. The specialty line is a positioning statement, which is genuinely informative about intent. A practice that advertises forensic response and not managed monitoring has told you which conversations it wants.

It cannot tell you whether they are any good. No directory can. Nothing in a self-written description is evidence, and the fact that all such descriptions sound competent is a property of who wrote them.

It cannot tell you whether the entry is current. Firms move, merge, close and change hands. Every entry here carries the year it was listed for exactly that reason, and the website is the field to follow because it is the one a reader can check in ten seconds.

How should a capability list be read?

Subtractively. An assertion is close to uninformative, since the incentives push everybody towards the identical set; an omission had to be a deliberate choice.

Consider two entries. One lists nine capabilities spanning consulting, monitoring, testing and compliance. The other lists two. The nine-item list is the safe commercial choice and tells you almost nothing. The two-item list is a firm that accepted being invisible to most searches in exchange for being right for a few, and that decision is a real signal about how they work.

The second useful reading is order. People put first what they most want to be hired for, and the last item on a long list is frequently something the firm can do rather than something it does. Reading a list backwards is a reasonable heuristic for finding the parts that were added defensively.

The third is vocabulary. An account phrased in the language of outcomes — what the client ends up able to do — usually comes from somebody who has delivered the work. A description written in the language of technologies is often written by marketing, and the distinction survives contact with the first meeting more reliably than any credential.

A caution against reading too much into any of this. These are heuristics for allocating attention across a long list, not verdicts. A superb practice may carry a dreadful summary because whoever drafted it was busy delivering, and a polished paragraph may belong to a firm that hired an agency. The value of the exercise is deciding which eight of two hundred entries deserve an hour, and that is genuinely all it is for.

One further reading rewards the patient. Compare an entry against the website it points at. Where the two agree closely, somebody maintains both and the operation is tidy. Where the site describes a different business entirely — a narrower niche, a broader platform, a pivot — you have learned something no single document could have told you, namely the direction the company moved after writing that sentence.

How do you shortlist when everyone looks alike?

By abandoning the category as the organising idea and starting from a stated problem, which sounds obvious and is almost never what happens.

The usual sequence is to identify a category, assemble a roster of candidates, weigh their capabilities, and pick. Every step of that is reasonable and the outcome is a choice between firms selected for similarity, evaluated on descriptions written to be similar, using criteria supplied by the category itself.

The alternative sequence starts with a sentence describing something specific that is currently going wrong, in the words the organisation actually uses. Not we need detection and response, but we find out about intrusions when a customer tells us, and we want to find out first. That sentence is not in anybody's capability list, and it is answerable — differently, informatively — by everybody you put it to.

What that does is move the differentiation from the document to the conversation. Vendors converge on capability wording because wording is cheap; they diverge sharply on how they would approach a concrete situation, because approach is expensive to fake and reveals what they have actually done before. The first meeting becomes informative rather than ceremonial.

Is a smaller supplier riskier?

Differently risky, and the honest framing is a choice between two failure modes rather than a ranking.

A large incumbent will not disappear. What it will do is fold your product into a platform, move its pricing into a bundle, and assign you an account manager whose other clients are larger than you. Your requests enter a roadmap process where they compete with everybody else's, and the probability that a specific thing you need gets built is low regardless of how reasonable it is.

A small outfit gives you attention that is real. The people who built the product will answer your questions, changes you ask for may appear in weeks, and the relationship is with people rather than with a process. What you are carrying is the possibility of acquisition, a support function that is three people, and a roadmap that depends on the company continuing to exist in its present form.

Neither risk is avoidable and both are manageable, but by different clauses. Against the large supplier, protect the ability to leave: data export, detections expressed outside the product, no engineered exit penalty. Against the small one, protect continuity: an escrow arrangement if the product is central, and terms that survive a change of ownership.

The mistake worth avoiding is choosing on size as though it were a quality. It is a shape of risk, and the useful question is which shape your contract is written to survive.

There is a middle case that gets overlooked because it has no marketing behind it. An outfit of thirty people that has stayed thirty for a decade is neither the growth company heading for an exit nor the platform vendor with a roadmap process. It chose to remain a size at which the founders still do the work, and it is frequently the best available answer for a narrow problem — while being invisible in every comparison built around scale.

Making the first meeting worth an hour

The default first meeting is a demonstration, which is close to the least informative format available: the product performing tasks chosen by the vendor on data prepared by the vendor.

Describe a problem instead of requesting a demonstration. Ten minutes on something real that is going wrong, then ask how they would approach it. Suppliers who have done the work ask questions back; suppliers who have not move to slides.

Ask what they would not take on. A firm with a genuine specialism can name the situations where somebody else is the better call. A firm that says it can help with anything has told you it has no shape.

Ask about a deployment that went badly. Everybody has one, and the reply separates candour from polish faster than any reference. The good answer names what was misjudged and what changed afterwards.

Ask who will actually do the work. The people in the meeting are frequently not the people who arrive. It is a fair question, it is rarely asked, and the pause before the answer is informative on its own.

Should you buy through a reseller?

It depends entirely on whether the intermediary is doing work or forwarding messages, and the difference is testable before signing anything.

A reseller earns their margin in two situations. The first is when they genuinely operate the product for you, in which case you are buying a service and the underlying licence is an implementation detail. The second is when they aggregate support across several products you own, so one relationship covers a problem that would otherwise involve three vendors blaming each other.

They do not earn it as a purchasing intermediary. If their contribution is forwarding your technical questions to the vendor and forwarding the answers back, you have added a delay and a margin to every interaction you will have for the life of the contract.

The test is a single technical question at the first meeting — something specific about how the product behaves in a situation you care about. A partner who operates the thing answers it. A partner who resells it says they will find out, and that answer is the whole evaluation.

Where an intermediary genuinely adds value and it is worth saying, because this section reads harshly otherwise: for an organisation without the staff to run a product properly, a competent operator is frequently better value than the licence plus an unfilled role. The question is what you are buying, not whether buying it is legitimate.

Getting something out of a reference call

References are selected by the supplier, which everybody knows and almost nobody adjusts for. The call is still worth taking, provided the questions are ones a selected reference can answer honestly without embarrassing anybody.

Do not ask whether they are happy. Anybody willing to take the call is content, and the reply carries no information. The interesting territory is everything that was true and unexpected.

Ask what surprised them after signing. This is the single most productive question available, because every deployment contains at least one surprise and naming it costs the reference nothing. The answers tend to be about scope, integration effort or how much internal work the product assumed.

Ask how long it actually took, against the estimate. Not to catch anybody out: the ratio is what your own planning needs, and it is a number the reference has and the supplier's proposal does not.

Ask what they would scope differently. A reference who has thought about this answers immediately and in detail, which also tells you the deployment was real rather than a pilot that was never finished.

Ask who else they considered, and why not. Frequently the most useful sentence in the call. It surfaces suppliers your own search missed, and the reason one was rejected is often a constraint you also have and had not articulated.

One practical note on arranging these. A reference in the same sector and roughly the same size is worth three that are neither, and it is entirely reasonable to decline a call with an organisation ten times your size on the grounds that their experience will not transfer. Suppliers offer their largest and happiest customers; asking instead for somebody comparable is a normal request that is rarely made.

Where to start on a Monday

Three things, none of which requires contacting anybody.

Write the problem down in one sentence, in your own words. Not the category you think it belongs to. If the sentence contains a product category rather than a situation, it was written after the shortlist rather than before it.

Trace what became of the last three vendors you bought from. Still independent? Same owner? Same product name? Whatever base rate emerges applies equally to whoever you choose next, and it is usually worse than people assume.

Write the failure condition for the pilot before the pilot. One sentence naming what would have to be true, by when, for the answer to be no. A pilot without one concludes with everybody having been impressed and no decision available.

After those three, the harder work is prioritisable: getting exit terms into contracts at signature rather than renewal, deciding which shape of vendor exposure you are equipped to carry, and building the habit of describing problems rather than categories. An organisation that has done the first three can state what it needs in a sentence, which turns out to be the scarce thing in the whole transaction.

A closing observation about sequence. Most purchasing conversations begin with a budget and end with a requirement, which is backwards and produces a specification assembled to justify a figure. Beginning with the sentence, then discovering what addressing it costs, sometimes yields an uncomfortable answer — and an uncomfortable answer arrived at honestly is still a better basis for a decision than a comfortable one reverse-engineered from a number somebody had already approved.

Common questions

What does a directory listing actually tell you?

That the firm existed, roughly what it said it did, and where it was based. The specialty line is the firm's own description of itself, not an assessment, and no directory entry anywhere constitutes evidence about quality.

Why do so many suppliers claim the same capabilities?

Because the phrases buyers search for are the phrases suppliers write. The most-claimed terms here are asserted by ten or more firms apiece out of a few hundred, which means the words that get typed into a search box are among the least capable of separating two candidates.

How should a capability list be read?

As a statement of what a firm wants to be considered for, not what it is good at. The useful reading is subtractive: notice what is absent, because a supplier that lists nine things and does one of them well will have listed all nine.

How do you shortlist when every candidate looks alike?

Stop shortlisting by capability and start with the specific problem stated as an outcome. Suppliers converge on capability words and diverge sharply on how they would approach a concrete situation, which is why the first conversation should describe a problem rather than request a demonstration.

Is a smaller supplier riskier?

Differently risky. A large supplier is unlikely to disappear and likely to fold your product into a platform; a small one gives you attention and might be acquired. Neither risk is avoidable, so the question is which of the two your contract is written to survive.

Should you buy through a reseller or direct?

A reseller is worth their margin when they genuinely operate the thing for you or aggregate support across products. They are not worth it as a purchasing intermediary who forwards your questions, and the test is whether they can answer a technical question without asking somebody else.

What should the first meeting cover?

One real problem you have, described in your own terms, with the supplier asked how they would approach it. A demonstration shows what the product does on the vendor's data, which is the least informative thing available.

What is worth checking before contact?

Whether the company still exists independently, who owns it now, what its published documentation looks like, and whether its support terms are public. Two of those four have changed for a substantial share of any directory more than a couple of years old.

How useful is a pilot?

Very, when it is scoped to answer one question and has a stated failure condition agreed in advance. A pilot with no defined outcome becomes a demonstration that consumes a quarter and concludes with everybody having been impressed.

What should a reference call ask?

Not whether they are happy. Ask what surprised them after signing, what they would scope differently, and how long the deployment actually took against the estimate. References are selected, so the useful questions are the ones a selected reference can still answer honestly.

How current is this directory?

Each entry carries the year it was listed. Firms move, merge and close, and an entry is a record of what was published then rather than a claim about today. The website field is the one worth following, because it is the only part a reader can check for themselves.

Why are some listings missing?

The directory holds entries that can be reproduced from the record. Where an entry cannot be, no page is published for it, because a listing carries a real company's name and details and inventing those would be worse than the gap.

Browse the directory

245 listings across 11 categories. Each entry carries the year it was listed and the firm's own description.

All listings