Home > Security Tips > Network Security Tactics > How to buy security products: Eight steps to not losing your shirt
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

How to buy security products: Eight steps to not losing your shirt


Mike Rothman
10.16.2007
Rating: -3.50- (out of 5)


Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Buying products or services is either the best or the worst part of being a security professional. In any kind of competitive market -- like information security -- the competition is brutal and the vendors will bend (dare I say, break) the truth in order to get the sale.

I get a little frustrated when I hear about organizations dropping six figures on a product they've never tested, or when they spend seven figures on a product that gathers dust on the shelf. Even in this day of multi-billion-dollar behemoths, it turns my stomach to see outrageous sums squandered because neither technologists nor business managers understand how to buy enterprise security products.

I've outlined an eight-step strategy for how to buy security products, which is designed to return control of the buying process to the security pro. Sales professionals are trained to seize control of the process and convince their prospects that they need what the vendor is selling. Reps do their best to lead the prospective customer through a structured sales cycle to achieve that goal.

Sometimes these sales cycles align with what customers want to accompli



sh, but most often, they don't. So my process is built around the security manager's needs, to make sure an organization buys the right product, at the right time, for the right price.

This process will not work in every case. If an organization is an early adopter type and there is only one vendor that can meet its needs, then it has no leverage. Likewise, there are times where politics trumps functionality and the best price.

But in most cases, when a security team is looking to solve a business problem in the most expedient and cost-effective way, following these eight steps can help it achieve its goals and avoid costly mistakes.

About the author:
Mike Rothman is president and principal analyst of Security Incite, an industry analyst firm in Atlanta, and the author of The Pragmatic CSO: 12 Steps to Being a Security Master. Rothman is also SearchSecurity.com's expert-in-residence on information security management. Get more information about the Pragmatic CSO at http://www.pragmaticcso.com, read his blog at http://blog.securityincite.com, or reach him via e-mail at mike.rothman (at) securityincite (dot) com.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions,   Information Security Management,   Business Management: Security Support and Executive Communications,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Network Security Tactics
Screencast: Samurai offers pen-testing nirvana
Firewall rule management best practices
Chained Exploits: How to prevent phishing attacks from corporate spies
Rootkit Hunter demo: Detect and remove Linux rootkits
Enterprise UTM security: The best threat management solution?
Making the case for network security configuration management
An inside look at security log management forensics investigations
How to find sensitive information on the endpoint
How to perform Microsoft Baseline Security Analyzer (MBSA) scans
How to spot attacks through Apache Web server log analysis

Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
Sophos CEO on Symantec, McAfee after Utimaco acquisition
EMC adds configuration management with Configuresoft acquisition
Know when you need IDS, IPS or both
Symantec acquires Mi5 Networks, bolsters Web security
RSA Conference 2009 shines spotlight on security vendor innovation
Oracle to buy Sun Microsystems for $7.4 billion
Entrust to be acquired by investment firm
Enrique Salem takes charge at Symantec
Countdown: Top 5 most important questions to ask endpoint security vendors
Flaw disclosure debate polarizes SOURCE Boston panel

Business Management: Security Support and Executive Communications
RSA council addresses growing security risks in the cloud
How to write a risk methodology that blends business, security needs
Risk management must include physical-logical security convergence
New partnerships, creative thinking help security bust recession
How to align an information security framework to your business model
Service-focused security offers best value to organization
Cybersecurity Act of 2009: Power grab, or necessary step?
Information security skills must include communication, expert says
Mimic the IBM approach to security at RSA
Sell the business on virtualization security

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
snake oil  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts