A real-world case study from a board-level cybersecurity leader
We interviewed a board-level cybersecurity professional in a multinational financial organisation to understand how suppliers are evaluated and what builds trust. Their account highlights where risk is rising, buying groups are broadening, and vendor credibility increasingly depends on proof rather than promotion. Relevant findings from our survey of 300 IT decision makers in the US and UK accompany each theme, providing broader context.
A faster, identity-led threat landscape
Our interviewee described a market reshaped by AI, identity attacks and geopolitical pressure. “Identity [is] becoming a new perimeter,” they said, as attacks increasingly begin with valid credentials. “AI has actually industrialized the attack surface,” enabling phishing, deepfakes and faster reconnaissance. The strategic implication is clear: “AI governance [is] becoming a board-level risk item, not just a technology concern.”

Vendor choice is moving from products to platforms
Buyer expectations are shifting. Beyond functionality, integration, cost and vendor roadmaps, the direction is towards “fewer, broader, more capable platforms.” Scrutiny is also widening to identity security, AI-native capabilities, third-party risk and “the security posture of the vendor itself, not just the product.” Decisions increasingly span a wider committee: “Finance needs ROI, legal needs obviously compliance, IT needs integration clarity. The board needs governance confidence.”

Shortlisting is structured; final selection is about reducing risk
Longlists are stripped of outliers that are “too expensive or suspiciously cheap,” poorly integrated or strategically misaligned. Buyers then score platform fit, M&A risk, compliance and whether AI capabilities are “true” or “hype,” narrowing the field to three to five suppliers. At that point, proof matters most. “When you do proof of concept with your actual data and environment, this is a single most reliable differentiator.” The focus then shifts from product fit to relationship risk: “…which partnership is the lowest risk over the next three to five years.”

Large vendors win through structural advantage as well as capability
The largest cyber brands benefit from more than technical quality. Our interviewee pointed to bundling, ecosystem reach, acquisitions, existing cloud commitments and switching costs. “The top vendors dominate through structural advantages that go well beyond either marketing or product features.” Marketplace purchasing can “remove procurement friction entirely,” while platform economics make suppliers sticky. Genuine technical capability remains “the necessary entry ticket,” but buyers must avoid mistaking convenience for strategy.

Trust is shifting towards peers, customers and authentic expertise
Awareness increasingly comes from peer networks, review platforms, technical research, conferences and AI-assisted discovery. “The most credible awareness sources, they share one characteristic. They’re perceived as independent of vendor commercial interest.” For marketers, the recommendation was direct: “Get their existing customers to speak publicly on their behalf in the channels where the buyers actually research.” Our interviewee was equally sceptical of generic AI content: “AI works best when it supports visible expertise and accountability rather than attempting to replace them.” Buyers want the “real voice of the customer, real stories, real data.”

Want the wider picture?
Explore How Brands Know, our quantitative research among 300 US and UK IT leaders on what drives trust, consideration and confidence in tech buying today.
