Your threat-feed renewal costs the same as twenty EDR seats - how do you make the call?
answer
- allocation question, not a procurement one
- funnel, lead time, then named cases
- telemetry is owned, curation is rented
- halve it rather than renew or cancel
- do not launder an anecdote into a rate
basics
~20 sBring the measured funnel - unique, matched, acted on - and the verdicts that came out differently, then weigh them against what the same money buys in telemetry you own. Halving to the collection that worked is often the right answer.
solid answer
~50 sI go in with three things: the ninety-day funnel showing unique contribution, matches against our own telemetry and verdicts acted on; the lead-time distribution; and the named cases. Then I frame it as an exchange, not a spend. Endpoint seats buy telemetry we own and that keeps producing after the contract ends; a feed buys someone else's curation, whose value ages in days and disappears the moment we stop paying. If the only evidence is one saved case, I say so plainly - in a small team one prevented session-token theft can still be worth the money, but I will not dress an anecdote as a trend. The usual landing spot is not renew-or-cancel but halve: keep the single collection that produced the unique hits, drop the aggregated bulk, and require the vendor to price that slice.
go deeper
You will not own this decision, but know that a feed's price competes with other security spending and that indicator counts are a sales figure rather than a measure of usefulness.
Be able to produce the evidence someone else will decide on: the overlap funnel, the lead-time figures, and a clear statement of which indicators actually matched your own telemetry.
Show that you would run the measurement before the renewal window rather than during it, and that you can distinguish a feed that is unproven in your estate from one that is proven useless.
Own the allocation argument - rented curation against owned telemetry - name the anecdote as an anecdote, and be ready to land on a halved contract with a review date rather than a binary renew-or-cancel.
## The decision, stated honestly A feed renewal in a small security team is not a procurement question, it is an allocation question: this money is already committed to something else - endpoint coverage, a log source you are not collecting, an analyst's hours. So the case has to be made in the currency of what is given up, and the vendor's ten-million-indicator headline is not in that currency at all. ## What you bring into the room **The funnel.** Over a fixed window: delivered, unique to this source, unique and matched against your telemetry, matched and acted on. The last number is usually small and sometimes one, and stating it before the vendor does is what makes the rest of your argument credible. **The lead-time distribution.** Not against other vendors, against your own exposure. "On the artefacts several sources carried, this one was first by a median of a few hours, and on one occasion it carried a credential-harvesting landing domain before the first message reached a mailbox" is a specific, checkable claim. **The named cases.** One or two investigations, with timelines, where the verdict came out differently. This is the part everyone remembers, and it is also the part you must be most careful with - it is an anecdote, and if you present it as a rate you will be caught. **The counterfactual.** What would the same money buy? Endpoint or identity telemetry is an asset you keep: it produces detections you write, it supports hunts and it survives the vendor. A feed is a subscription to someone else's collection whose contents are stale within weeks and whose value ends with the contract. That asymmetry is the strongest structural argument, and it usually matters more than the funnel numbers. ## Reading the vendor's pitch Volume claims (indicator counts, sources monitored, languages covered) are inputs the vendor controls and cannot be verified from outside. What you can ask for is: which collections are original rather than aggregated; the price of the original slice on its own; a scoped trial where *you* run the overlap harness; and reference customers with an estate shaped like yours. A vendor who will not price a collection separately is telling you the bulk is where the margin is. ## The options, not two but four - **Renew as-is.** Justified when the funnel shows repeated matches, not one, and the lead time lands inside your exposure window. - **Halve it.** The common right answer: keep the one collection that produced the unique, matched indicators; drop the aggregated remainder that duplicates free sources. This is where the measurement pays for itself. - **Change the tier.** Sometimes the value is real but the delivery is wrong - an API or streaming tier for a fast-moving artefact class costs less than the full platform, and matches how you actually consume it. - **Cancel.** Justified when unique-and-matched is zero across a long window and the collection does not plausibly cover threats that reach you. ## The arguments against your own recommendation A principal-level answer names these before someone else does. - **Small-sample honesty.** Ninety days in a small estate may simply not contain the rare event the feed exists to catch. Absence of matches is weak evidence, and a longer window or a wider replay against stored telemetry strengthens it. - **You lose the counterfactual.** Once cancelled, you cannot measure what you would have caught. Keeping a minimal tier purely to preserve the comparison is sometimes worth it, and sometimes an expensive way to avoid a decision. - **Asymmetric loss.** One missed adversary-in-the-middle session theft in an identity-and-SaaS estate can cost far more in response hours than the subscription. If the feed's collection is genuinely aimed at that class of activity, a low match count is not automatically a cancel. - **The team's capacity.** A feed you have no one to operate - nobody normalising it, nobody wiring the matches into the alert record - will produce nothing whatever its quality. Buying intelligence you cannot deliver into a chair is the most expensive way to have none. ## Handling the vendor conversation Give them the funnel and the window, and invite them to dispute the method rather than the conclusion; a good account manager will point out real flaws, such as collections you never ingested or matching you only ran against fired alerts. Offer the halved contract as your opening rather than a cancellation threat, because you probably do want the one collection that worked. And put a review date in the calendar with the harness still running, so the next renewal is decided on twelve months of data rather than on whoever argues best in the room. ## What separates a good answer Not the decision - either way can be right. It is refusing to launder an anecdote into a metric, naming what the money is being taken from, and knowing that an artefact list is a rented asset while telemetry is an owned one.
- Your only evidence is a single case where the feed changed a verdict. How do you present that?As exactly what it is - one case, with its timeline, and no claimed rate behind it. I would say that in a team our size a single prevented session-token theft plausibly repays the subscription, and in the same breath that one observation cannot distinguish a good feed from luck. Then I let the structural argument carry the weight: what the same money buys in telemetry we own, and whether that collection plausibly covers the threats that reach us.
- The vendor disputes your overlap numbers. What do you concede and what do you hold?I concede method flaws readily - collections we never ingested, matching run only against fired alerts rather than stored telemetry, a window too short for a small estate - and I will rerun with those fixed. What I hold is the frame: the decision is made on unique indicators that matched our environment and changed something, not on indicators under management. If they can move the first number, they have won the argument fairly.
saying these in an interview costs you the question
- Decides on vendor indicator counts or brand reputation
- Presents one saved case as a measured hit rate
- Treats renew or cancel as the only two options
- Ignores that cancelling destroys the ability to measure the counterfactual
- Never names what the same budget is taken from
- Buys intelligence the team has no capacity to deliver into tooling