# 0. Introduction: Setting the Scene
Sid, Claude, and I were talking:
We work in a cybersecurity industry that is filled with over-promises and under-delivery. Being a CISO, CTO, or leader working inside a "regular" company, whether that's healthcare, manufacturing, finance, or simply a local business that doesn't have all the resources, it is becoming more and more impossible to understand what questions to ask vendors to work out if they are lying, exaggerating, or simply chasing the next topic of the week.
So, with that scene set, a leader at a company faced with working out who's good and why, this series works through sets of questions to ask across the industries, technologies, and solutions that are most top-of-mind in security and technology right now. Each topic gives you 12-15 pointed questions, a "what good looks like" answer, a red flag to watch for, and an honest observation from people who have sat on both sides of the table.
The audience is leadership, technical management, and practitioners in the industry. Where a question is more of an "ask" than a question, the format adapts to fit. Where topics overlap, they cross-reference rather than repeat. The goal throughout is the same: help you cut through the noise, hold vendors accountable, and make better decisions with the budget and time you actually have.
The Series: 20 Topics (So Far)
- AI-Powered Security Tools
- EDR, XDR, MDR: Endpoint and Extended Detection
- SIEM, SOAR, Log Management
- SOC and NOC Automation: Autonomous Analysts and AI Co-Pilots
- Vulnerability Management, ASM, EASM
- Identity: IAM, PAM, ITDR
- Cloud Security: CSPM, CNAPP, CWPP
- Cloud vs. On-Premises: What Goes Where?
- Email Security and Phishing Protection
- Pen Testing, Red Team, Offensive Services
- vCISO and Managed Security Services
- GRC and Compliance Platforms
- Threat Intelligence: What Does Good Look Like?
- Zero Trust, SASE, SSE
- Backup, Recovery, and Cyber Resilience
- Third-Party Risk Management
- Governing and Measuring Your Security Service Providers
- Cyber Liability Insurance
- DevSecOps, Application Security, Software Supply Chain
- Welcome to 2026: What Do We Actually Do With Frontier Models?
A few notes before you dive in:
The questions in this series are a starting point, not a script. The best security leaders adapt them, combine them with their own sector knowledge, and update them as the landscape evolves. If a vendor can't answer the questions marked as non-negotiable in each topic, that tells you something important before you sign anything.
More topics are in development. The series will grow.
Prepared collaboratively with: Chris Roberts, Sid, GPT 5.5, Kimi 3, Claude (Anthropic) | 2026