Cybersecurity is one of the categories where the gap between a confident sales pitch and an actual security posture is widest, and where getting it wrong has the highest downside. Most executives evaluating a security vendor are not security engineers, and vendors know it.
Certifications are a floor, not a conclusion
SOC 2 and ISO 27001 are the two credentials that come up most often, and they are worth asking for. But a certification confirms that a vendor passed an audit against a defined set of controls at a point in time. It does not confirm the vendor is right for your environment, your data sensitivity, or your regulatory obligations. Ask when the certification was last renewed, and ask to see the actual report, not just the badge on the website.
The questions that matter more than the feature list
What happens during an incident. Not "do you have an incident response plan," which every vendor will say yes to, but a specific walkthrough: who gets notified, how fast, and what your organisation is responsible for versus what they are. Vendors who can answer this in detail, unprompted, have actually run through the scenario. Vendors who go vague have not.
Who else uses them at your scale. Not a logo on a website. A named reference you can actually call, ideally someone who was there for onboarding and for at least one real problem. A vendor confident in their own delivery will offer this without being pushed.
Why this evaluation gets skipped
The honest reason most organisations under-vet a security vendor is time. A proper reference call, a real review of the audit report, and a specific incident-response conversation take hours per vendor, multiplied across every option under consideration. Under deadline pressure, that gets compressed into "they seem credible" and a signature.
That compression is exactly where a private sourcing process earns its keep: the reference calls and document review happen before a shortlist ever reaches you, not after.