by Mandy Andress

Buying products with the most bells and whistles

How-To
Aug 28, 20064 mins

Don’t buy based on features you’ll never use, focus on the core problem that you’re trying to fix . . .

The market for information-security products is huge today, with vendors competing hard for your IT dollars. The problem is that amid all the hype and all the competing products, customers frequently lose sight of the real goal: managing risk and protecting data.

I participate in company briefings and product demonstrations all the time, and I see the focus shifting from core functionality to the sexy bells and whistles. I like colorful graphs and geeked-out features as much as the next person, but the core functionality should be the top priority in any product selection.

Frequently, I see companies select products based strictly on user interface, reporting and promises of future functionality. Of course, none of this matters if you are purchasing a product that does not fit in your environment or doesn’t function as promised. Reports are critical for most security-related products, but a product with pretty reports and useless data is useless.

Just another pretty face

For example, I spoke with executives at a company that had recently purchased a security configuration-management tool and was complaining that it wasn’t working for them. The tool wasn’t providing the information and functionality they really needed to accomplish the job.

I asked how they arrived at their purchase decision and found they went with the best-looking dashboard, even though they never use this component of the product. They have daily reports e-mailed to them, ready for review first thing in the morning.

In the end, they purchased a product with the best-looking dashboard and excellent-looking reports, but functionality that did not work in their company, because it did not support the method they needed to use to communicate with all their servers. It also could not create all the reports they were looking for.

Buyer’s remorse

I also spoke with a company that purchased a new intrusion-prevention system. On the surface the company’s product-selection process looked pretty sound, but it was not happy with the result.

After digging a little deeper, I discovered that the company purchased a product very strong in processing large amounts of network traffic and included a number of other network-related features it was not using. The company failed to look at all aspects of the product in its environment and ended up with something that could not integrate into its enterprise alert/paging system.

Before evaluating products, define all of your requirements and acceptance criteria. If a product does not meet these basic requirements, do not buy the product, regardless of how many alert systems, RSS feeds or default reports it includes.

I also see companies focusing on all features, not just those they will use. People tend to be overly ambitious and think a product or set of tools will solve all their problems.

The reality is that most people use a small percentage of all the features available in any given product. If you keep this in mind during the selection process, you will focus on the aspects of the product you will use, look at the functions you might use, and weigh them accordingly in the final decision.

Bait and switch

Also, I see many companies falling for tried-and-true sales techniques. We all know what they are — shifting focus from poor areas of the product, speaking ill of competitors, providing box seats to the big game.

Most companies can sell themselves well, but the real test is to get the product in-house for an evaluation or find a trusted resource that has tested the product and rely on their analysis.

Once you prove the base requirements are there and will function well in your environment, you can start looking at the other features. If you have two products that meet all your requirements, you can start looking at the bells and whistles that may add value or you see yourself using at a later time.

Cost is always an issue, so in the end you may be forced to select a product that does not meet all of your requirements but may meet most of them. You at least made an informed decision and know exactly what you are getting.

Don’t get caught up in all the hype and mesmerized by the new toys. Stay focused on what you need and you will end up with a more useful set of tools in your security infrastructure.

Andress is president of ArcSec Technologies, a firm focusing on security assessments, product reviews and analysis. She can be reached at mandy@arcsec.com.