Throughout the years, enterprise IT buyers have held on to a common belief: “Nobody ever got fired for buying IBM.” As Cisco emerged as a prominent networking and email security provider in the early 2000s, the belief transformed into “Nobody ever got fired for buying Cisco.” The reputation of a big name justified the higher price tag. However, in the realm of email cybersecurity, relying solely on brand recognition can be risky. A well-known vendor does not guarantee superior protection, support, or defense against modern threats.
In fact, the popularity of a security vendor can work against organizations. Cybercriminals often target solutions with the largest user base – such as Microsoft Exchange, which holds a significant portion of the world’s corporate mailboxes and is a prime target for attackers.
Critics have long argued that popularity does not always equate to performance. For today’s security leaders, the crucial question is not:
“Will I face backlash for choosing this vendor?”
Instead, it is:
“Can I justify this decision following a successful phishing attack?”
When a breach occurs, boards and executives are concerned about the effectiveness of the chosen solution rather than the vendor’s reputation. They want assurance that the solution was thoroughly evaluated, tested, configured correctly, and capable of safeguarding the business. If a different solution could have offered better protection, the vendor’s name becomes insignificant.
In the realm of modern email security, the best choice may not always be the most well-known one. Organizations should prioritize factors like detection accuracy, response automation, user protection, operational efficiency, and integration with their overall security framework.
If, after careful evaluation, a market leader emerges as the top choice, that’s acceptable. But if not, that’s also okay. What truly matters is having a comprehensive analysis, testing, and decision-making process to back the choice.
Ultimately, no one should be penalized for selecting a vendor. However, they should be questioned if the decision was made without a solid rationale.
