skip to content

Do you fund a fourth security console after three products saw the intrusion and none stopped it?

level: principalimportance: nice to knowfreq 41%

answer

  1. attribute the miss before pricing it
  2. four stages: telemetry, rule, human, response
  3. buy independence, not capability
  4. a console costs a queue and an owner
  5. unique contribution over a quarter

basics

~20 s

Not until you know which stage failed: telemetry missing, no rule, nobody acted, or the response never landed. Only the first is a control-class gap a new product can fill; the rest are configuration, ownership or contract problems.

solid answer

~50 s

I reconstruct the miss against the specific technique and attribute it to one of four stages: the telemetry never arrived, no detection expressed the behaviour, no human acted on what fired, or the response did not land. A new console only fixes the first, and only if it observes a surface nothing I own can see. So the buying test is independence — which technique would this product decide correctly while my existing three are blind — plus the running cost: licence, integration, another queue, and an owner for it at three in the morning. Often the honest answer is that an existing product already has the surface but not the configuration, or the provider's contractual scope excluded it. And the funding often comes from retiring an overlapping product whose unique verdict contribution over a quarter was near zero, rather than tuning it.

go deeper

for a junior

Understand that buying another product does not by itself add visibility, and that a control can only decide on data it receives.

for a middle

Be able to separate the four ways a detection effort fails — no telemetry, no rule, no analyst action, no effective response — and say which of them a purchase could address.

for a senior

Show that you would reconstruct the specific miss and check existing products' configuration, coverage and data feeds before declaring a capability gap.

for a principal

Own the portfolio economics: judge candidate controls on independence rather than capability, cost the queue and the owner alongside the licence, and be willing to fund a real gap by retiring an overlapping product whose verdicts changed no decisions.

## The question behind the question An executive asking "we own three security products, they all saw this and none stopped it — what do we buy?" is really asking two things: *was this a gap in what we can see, or in what we did?* and *what will another line item change?* Answering with a product name first is the failure mode. Answering with an attribution of the miss is the job. ## Attribute the miss to a stage before pricing anything Every missed intrusion fails at one of four stages, and they have completely different remedies: 1. **The telemetry never arrived.** No control class in the estate observes the surface the technique touches, or it observes it for some hosts and not this one. *This is the only stage a new product can fix.* 2. **No detection expressed the behaviour.** The records existed; nothing looked for that pattern in them. Remedy: detection content on a surface you already own — cheap by comparison, and it does not add a console. 3. **Nobody acted.** It fired and was closed, deprioritised, or sat in a queue nobody owned. Remedy: ownership and workload, not licences. 4. **The response did not land.** Someone decided, and the action failed, was scoped wrongly, or was blocked. Remedy: response engineering. For a channel carried inside a legitimate collaboration platform's API, the honest attribution is usually stage 1 for the *platform's own audit trail* — nobody was ingesting it — and stage 2 for asset context, because nothing asked why a build agent was talking to a collaboration workspace at all. Neither is fixed by a fourth endpoint or network product. ## The buying test: independence, not capability Vendors demonstrate capability. Capability you already have three times over is worth nothing. The two questions to put to any candidate console are: - **Which surface does it observe that nothing I own can see?** If it decides on the same inputs your existing controls decide on, it will share their blind spot and will have agreed with them on this very event. - **Which technique would it therefore decide correctly while the others are blind?** Name the technique. If the answer is a technique two existing products already cover, you are buying overlap. Overlap is not worthless — it buys resilience when one product is down, misconfigured or evaded — but it is a *reliability* purchase, and it should be priced as one, not sold as depth. ## Price the whole cost, not the licence A console is never just its licence. It brings integration and data-egress work, an alert queue, tuning, a renewal negotiation, an on-call owner at three in the morning, and a permanent tax on every future investigation: one more verdict to reconcile, one more chance to tally votes instead of weighing surfaces. A product whose verdicts nobody has time to adjudicate is worse than absent, because its benign outputs will be read as assurance. ## Where the money comes from: retire rather than tune The strongest move available in this conversation is usually not "buy", it is "swap". Measure, per product over a quarter, the **unique contribution**: escalations where that console produced a verdict no other console produced, and where that verdict changed what was done. A product whose unique contribution is near zero is not merely underperforming; it is paying for a surface someone else already covers, and it costs reconciliation time on every disputed event. Retiring it, rather than tuning it, does three things at once: it funds the real gap, it removes a voice from every future adjudication, and it makes the remaining portfolio's blind spots easier to state honestly. Tuning a redundant product improves a signal you do not need. The measurement has to be done carefully. Unique contribution is not "how many alerts did it raise" — volume rewards noise. And it is not "did it fire recently" — the point is whether anything would have been *decided differently* without it. Sample real escalations from the quarter and check, for each, which console was load-bearing. ## Do not forget the boundary of the contract In a co-managed estate, one of these three consoles belongs to a provider. Before concluding a control class is missing, check whether it exists and was simply outside scope — the provider was not fed the SaaS audit trail, or a host class was never onboarded to their tooling. A scope amendment is a fraction of the cost of a new platform, and it fixes a stage-1 gap without adding a console. ## What to actually say to the executive Something close to: *three products behaved correctly within what each observes; none of them observes the channel this adversary used. The missing surface is the platform's own audit trail, we are ingesting it now, and we propose funding it by retiring the product whose verdicts changed no decision last quarter. A fourth console with the same inputs would have agreed with the other three.* That answer names the gap, names the remedy, names the funding, and does not ask for money to buy the same view a fourth time.

  • How would you measure a product's unique contribution without rewarding noisy tools?
    Sample real escalations from a quarter and ask, per case, which console was load-bearing: did it produce a verdict no other console produced, and did that verdict change what was done? Counting alerts rewards volume, and counting recent firings rewards activity. Only decision-changing verdicts distinguish a product that covers a surface from one that duplicates one.
  • The provider says the gap was outside their contracted scope. Does that change your recommendation?
    Substantially. If the surface exists but was not in scope or not fed to them, that is a scope amendment and an ingestion change, not a platform purchase, at a fraction of the cost. Check that before concluding a control class is missing — an unonboarded host class or an unshipped audit trail is the most common cause of an apparent capability gap.
  • When is buying an overlapping product actually the right call?
    When you are buying resilience rather than depth and you say so: a second control on the same surface protects against the first being down, misconfigured, or specifically evaded, and it matters most for a control whose failure is silent. Price and justify it as availability engineering, not as coverage of new techniques.

saying these in an interview costs you the question

  • Names a product before attributing the miss to a stage
  • Counts capability in a demo as coverage the estate lacks
  • Ignores the queue and the on-call owner a new console requires
  • Tunes a redundant product instead of retiring it
  • Assumes a missing control class rather than checking contractual scope

context