The Business of Cyber Security

Demand and How Buyers Buy

Demand in cybersecurity is manufactured externally, by criminals and regulators (see 15, 16), but it is spent by an individual buyer under pressure. How that buyer behaves is a central force shaping the industry's structure and a foundation under valuations. (Book: Part I, Ch. 3.)

Buyer fatigue and vendor consolidation

The dominant condition in enterprise security buying is fatigue, not appetite. The typical large enterprise has accumulated 50–100+ security tools over a decade of reactive buying — overlapping, half-deployed, generating more alerts than any human can triage. This produces a significant counter-movement: vendor consolidation — buyers actively cutting vendor count (e.g., 70 → 30) and standardizing on a few platforms, trading marginal capability for operational simplicity.

Platformization as a demand-side phenomenon

Platformization is usually told as something vendors do to the market. In reality, buyers are pulling the market toward consolidation as hard as vendors are pushing it. The platforms are competing for the right to be the survivor in a market where customers have decided most vendors must be culled. - Interoperability now outranks capability: ~70% of buying decisions weight fit-with-the-existing-stack above raw features. A superior standalone product that doesn't fit the chosen platform is commercially already losing. - Implication for investors: the consolidation thesis rests on something structural (buyer exhaustion), not contingent (vendor cleverness). It will not abate while the attack surface grows and talent stays scarce.

The visible buyer is not the representative buyer

A structural trap in reading cyber demand: the buyers you hear from are not the buyers who represent the spend. As Ross Haleliuk argues, the most visible voices — LinkedIn posters, podcast guests, conference panelists, the ~1–2% of "plugged-in" CISOs founders and VCs actually reach — are a thin, unrepresentative slice. Many of the best security leaders aren't on LinkedIn, have never been on a podcast, and haven't been to RSAC/Black Hat in years. Inside Fortune 500 / Global 2000 teams the real preoccupations are "boring problems" — identity sprawl, asset inventory, third-party risk, change management, compliance, complexity at scale; mid-market and SMB buyers outside the major hubs are still working on MFA, not agentic identities or AI-SPM. When the same ~300 people talk to the same ~300 founders, everyone hears the same answers and builds the same product, so entire categories of genuine demand stay under-served. Security isn't one market — it's hundreds of vertical/size/geography markets (Venture in Security, Jun 23 2026).

Two buyers in every deal

Buyer Role Failure mode if ignored
Technical buyer (architect/practitioner) Evaluates whether it works & integrates; can say no Wins enthusiasm, no revenue
Economic buyer (budget-owning exec) Only one who can say yes; weighs against everything else Stalls in "champion without budget"

The transformed senior buyer

The CISO has moved from a mid-level technical manager to a board-facing, often personally-liable executive (driven by the regulation of 16). When the buyer is partly buying down their own legal/career risk, the vendor is selling protection against a catastrophic event, not features — which raises urgency and willingness to pay, and tilts buying toward platforms and relationships over point tools.

Budget politics

The security budget is set in an annual contest inside a finance org that views security as cost. It is political at the level of the individual purchase: a competitor's breach loosens it; a quiet year tightens it; a regulation with a deadline carves out a protected line item. Two consequences: 1. The vendor who wins often arms the champion to win the internal budget fight (board-ready justification, regulatory mapping, breach-cost-avoidance case). 2. A consolidated platform purchase is a cleaner story to the finance committee than a sprawl of point tools — a budgeting reason platforms win, on top of the operational one.

The motion this selects. How the buyer buys picks the go-to-market that wins (GTM). Platformization pull rewards land with a platform SKU, expand by module over a best-of-breed point pitch. The two-buyer split forces a champion-plus-economic-buyer play — technical proof to the architect, board-ready ROI and risk-buydown to the budget owner. Interoperability-first selection rewards ecosystem and co-sell motions over standalone features. And budget politics rewards the vendor that arms the champion to win the internal fight. The buyer's behavior, not the vendor's preference, sets the motion.

The stack the buyer is consolidating (reference architecture)

To ground the demand picture in what a CISO is actually choosing between, the modern enterprise security stack maps roughly to these layers — and the buyer is trying to collapse them onto as few platforms as possible:

Layer What it protects Consolidating onto
Identity Who/what can access Okta / Entra / CyberArk (now Palo Alto)
Endpoint/XDR Devices & workloads CrowdStrike / Microsoft / SentinelOne
Network/SASE Access & traffic Palo Alto / Zscaler / Fortinet / Cisco
Cloud (CNAPP/DSPM) Cloud workloads & data Wiz/Google / Palo Alto / CrowdStrike
SecOps (SIEM/SOAR/MDR) Detection & response Sentinel / Google SecOps / CrowdStrike / Splunk
Data / email / app / GRC Data, inboxes, code, compliance Varonis, Proofpoint, Snyk, Vanta, etc.

Selection criteria (in priority order, per the buyer): interoperability with the existing stack (~70% weight it first) → consolidation/platform fit → demonstrated outcomes/ROI → then raw capability. A best-of-breed tool that doesn't fit the chosen platform loses on the first criterion, regardless of merit. This is the architecture-level reason aggregation wins at the point of sale (see 01, 33, 26).

The buyer behind the buyer: cyber insurance

Insurers increasingly mandate specific controls (MFA, EDR, backups, IR plans) as a condition of coverage — steering demand toward categories and vendors on a timeline the insured doesn't control. A third involuntary demand engine; see Cyber Insurance.

A deep dive follows in Demand Engines: Threat & Regulation, covering the three engines (threat, regulation, insurance) that make cyber spend non-discretionary, how each converts an external event into a mandated control and a budget line, and why demand the buyer did not choose is the deepest moat in the market.

Cross-references: Threat Economy, Regulation, Cyber Insurance, Vendors, Economics, Go-to-Market & Channels, Channel & Distribution.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.