Module 4: Vendor Evaluation
Module 4: Buying Without Being Snowed
Act 3 begins here. You know what a program is, you know where yours stands, and you know how to talk about it upward. Now the practices — starting with the decision you’ll make most often: buying security from someone else.
Every security vendor you’ll ever evaluate has a deck that says the same four things: they use AI, they stop breaches, they’re SOC 2 compliant, and their competitors are legacy. You can’t out-expertise their sales engineers on their own product. What you can do is ask questions whose answers can’t be faked, read the documents nobody reads, and structure contracts so that being wrong is recoverable.
Four lessons, then practice:
- What a SOC 2 actually says — how to extract signal from an attestation designed to be filed unread
- Build vs. buy — the math, and where it inverts
- Concentration risk — the full treatment lesson 1.6 promised, from Kaseya to CrowdStrike to Okta
- Real vendor or paper vendor — questions that separate an operations floor from a marketing budget
The module closes with a decision scenario — The MDR Contract Nobody’s Happy With — where you live with a purchase across a year, and a printable Vendor Evaluation Worksheet you can use on your next renewal.
What you’ll walk away with
- The three parts of a SOC 2 report worth your time, and the five parts that aren’t
- A build-vs-buy framework that survives contact with your CFO
- A concentration-risk pass you can run across your top ten vendors in an afternoon
- A question list for vendor calls that changes what sales engineers tell you
- Practice managing a vendor relationship — pilot, contract, escalation, renewal — not just picking a logo
Time
~60 minutes. Four lessons, one scenario you can rerun, one worksheet.