The cybersecurity market is large, crowded and mostly built for an adversary that has changed.
That is not a criticism of the companies in it. Most were designed against a real threat model and executed well against it. The problem is that the threat model moved twice in quick succession, and vendor categories move slowly.
Here are seven questions that reveal whether a vendor is built for what is actually coming.
1. Which attacker does this stop, and can you name it?
Start here, because vague answers are diagnostic.
There are two adversaries that matter now. Autonomous AI, operating today, where the cost of a capable attack has collapsed to an open-weight model and an afternoon. And harvest-now-decrypt-later, where nation-state actors collect encrypted traffic today to read once quantum matures.
A vendor that cannot say plainly which of these it addresses is selling a capability rather than an outcome. "Improves your security posture" is not an answer. "Blocks autonomous attacks in seconds" and "applies quantum-safe encryption to every connection" are.
If the answer would read identically for an identity company, a governance company and a compliance company, you are not being told what it does.
2. Does it alert, or does it act?
Nearly every security tool an enterprise owns was designed to alert a person. That was correct when attacks were human-paced.
Enterprise response time is measured in hours. Autonomous attack time is measured in seconds. Any control whose decisive step is "and then an analyst reviews it" is not a control against attacker one: it is investigative tooling, valuable but different.
Ask specifically: when this detects something, what happens next without human involvement? If the honest answer is "it raises a high-severity alert", you know what you are buying.
3. Will I be replacing this in 2027?
This is the question that saves the most money and is asked the least.
CNSA 2.0 mandates post-quantum cryptography from 2027. Canada, the EU, the UK and the UAE follow. No extensions.
Buy an AI security product today that does not touch encryption, and you will run a second programme before the deadline. Buy a cryptographic migration today that does not address autonomous attack, and you are undefended tonight. Either way you buy twice, integrate twice, and carry the gaps between them in the meantime.
Ask directly whether the product will satisfy the 2027 requirement. A specific answer is a good sign; a roadmap slide is not the same thing.
4. What does it require me to rip out?
The most common cause of an unimplemented security strategy is not that it was wrong. It is that it demanded too much disturbance to begin.
Anything requiring re-platforming tends to get scoped, costed, deferred and replaced by something smaller that fits. Ask what stays: existing cloud, existing identity provider, existing applications, existing AI models. If the answer is "all of it, and we sit in the middle", deployment is plausible in weeks. If the answer involves migration phases, plan for quarters and a meaningful chance it stalls.
5. Does it govern machine-to-machine traffic?
Most enterprise traffic no longer has a person in it. Services call services, workloads call APIs, models call tools.
That traffic is usually authenticated with a shared secret in a configuration file: not verified per connection, often over-scoped, frequently unrotated. It is also exactly the path an autonomous attacker moves through, because enumeration finds over-permissioned service accounts quickly.
Ask how the product verifies machine identity, and whether that verification happens per connection or once at provisioning.
6. Where does the evidence come from?
Compliance evidence is usually reconstructed after the fact by correlating logs from several systems with different clocks, formats and retention windows. It is slow, expensive and often incomplete.
A control point that makes decisions can record them as it makes them. The evidence is complete by construction rather than assembled later. With post-quantum compliance arriving in 2027, being able to demonstrate that quantum-safe encryption is applied across an estate (not merely intended) becomes a concrete requirement.
7. Is this one thing, or four things in a bundle?
Vendors increasingly present suites: an AI security module, an identity module, a compliance module, an encryption module. Sometimes that is genuine integration. Often it is four products with shared billing, four sets of coverage gaps at the seams, and four upgrade cycles.
The clarifying question is architectural: is there a single point where all of this is enforced? If every connection passes through one place, then blocking, encryption, identity, policy and evidence happen together by construction. If not, they happen in four places and the gaps between them are yours to manage.
What good looks like
Applying these questions, a vendor worth shortlisting can say something like this without hedging:
Every connection passes through one gateway. Nothing enters, nothing leaves, nothing moves between systems without going through it. There, autonomous attacks are stopped in seconds by agents that detect, block, write the rule, harden the surface and log the evidence. Quantum-safe encryption is applied to every connection. Machine identities are governed per connection. Policy is enforced, not published. Audit evidence is produced as a by-product.
And nothing gets ripped out: it sits in the middle of what you already run, deploys in weeks, and is invisible to users.
One deployment. Not two migrations.
Red flags in vendor answers
The seven questions work best when you also know what an evasive answer sounds like. These are the patterns worth noticing.
"It improves your security posture." This is a sentence that fits any vendor in the market. Apply the test directly: if the claim would read identically for an identity company, a governance company or a compliance company, you have not been told what the product does. Ask again for the specific attacker and the specific outcome.
"AI-powered" as the answer to what it stops. AI in the product is an implementation detail. The question is whether it acts without a human and how quickly. A vendor that answers a threat question with an architecture adjective is describing engineering, not defence.
Post-quantum as a roadmap item. With a 2027 mandate, "on our roadmap" means you will be buying this capability twice: once now and once when the deadline forces it. Ask what is available today and what standards it implements.
Deployment measured in phases without a stated duration. Phasing is normal. Phasing with no committed timeline usually indicates the product requires changes to your environment rather than sitting in front of it. Ask specifically what must change in your cloud, identity provider and applications. The good answer is "nothing".
Evidence described as reporting. Reporting is generated from logs after the fact. Evidence is a record created at the moment a decision was made. If compliance output depends on correlating several systems, expect it to be slow and partially incomplete when audited.
No answer on machine-to-machine traffic. If a vendor's identity story is about users, sessions and devices, it does not cover the majority of enterprise traffic, which is precisely the path an autonomous attacker moves through.
A suite with no single enforcement point. Ask where the modules meet architecturally. If the honest answer is "they share a console", the seams between them are yours to manage, and seams are where coverage gaps live.
One positive signal is worth as much as all seven negatives: a vendor who answers the 2027 question and the rip-out question without hedging is a vendor who has thought about how their product survives contact with a real enterprise.
The bottom line
Vendor selection in this market rewards specificity, and most sales conversations are built to avoid it.
The seven questions all reduce to one: does this stop a named attacker, without a human in the loop, in a way that will still be valid in 2027, without making me rebuild what I already run?
A vendor who can answer that plainly has thought about the problem you actually have. A vendor who answers with posture improvement, architecture adjectives and a roadmap has thought about the sale.
Ask the questions in order. The evasions cluster quickly.



