Why Security Products Cost So Much

Kazuya Hiradate, CEO, Pentacon Research, Inc.··10 min read
Contents

People say security products are expensive.

The capabilities are sophisticated. They are made overseas. Exchange rates move against you. All of that is true.

But after a long time on the side that puts together proposals, what struck me is how much of the cost sits somewhere other than the product itself.

Before a foreign vendor's product reaches a Japanese customer, it passes through the local subsidiary, a first-tier distributor, sometimes a second-tier distributor, a firm that handles deployment and operations, and a systems integrator or carrier.

My rough sense is that each company in the chain adds something like 1.2 to 1.3 times. It varies by deal, and it is not a published statistic. Even so, across several layers it stops being a rounding error.

So why are all those companies there?

Writing the whole thing off as middlemen skimming misses what is actually happening.

Selling to a large enterprise takes a lot of work beyond the product

A security product is not something you can hand over as a licence and walk away from.

Putting one into a large enterprise raises questions of who deploys it, who does the initial configuration, who owns day-to-day operations, who takes the first call when something breaks, and who consolidates the contracts and the invoicing.

Cutting out the integrator or the managed service provider does not make that work disappear. It comes back to you.

If you have people who can run it, that is a perfectly reasonable choice. Some companies do buy directly from a first-tier distributor.

For a company that cannot carry all of that in-house, the fact that someone in the chain takes it on is worth paying for.

I do not think of what those layers add as a simple handling fee.

The problem is what comes next.

The enterprise sales model is what you are paying for

Enterprise deals are not won on technical merit alone.

You have to be able to walk through contract terms. You need a clear escalation path when something breaks. You need to show what support looks like. Depending on the customer, you may have to explain yourself to legal, risk, procurement and finance, not only to the IT department.

Answering all of that takes people and defined procedures.

The foreign vendor's local subsidiary and the first-tier distributor are not just passing paperwork along either. They hold the sales and maintenance-support relationship. This is a product business, and a product business needs margin.

So a large share of what a security product costs is the apparatus for selling safely to large enterprises.

For a company that needs that apparatus, it is a rational cost.

Not every company needs the same thing, though.

This is what has bothered me for a long time.

In the supply-chain security conversation, requirements flow down from large enterprises to their suppliers. Yet the companies receiving those requirements are usually the ones without a dedicated security person and without much budget.

Meanwhile most of the services and sales channels on the market were built around selling to large enterprises.

The companies with the least capacity end up having to buy the whole apparatus along with the product.

I think that is one of the reasons security products look expensive.

Some of the cost is invisible to the buyer

There is another cost you will not find on a quote.

Sales and marketing.

Getting the product known, generating leads, having salespeople explain it, sitting through evaluations, closing the deal. In the end that is recovered through the selling price.

I have looked at a great many quotes from the proposal side, and I have never once seen a line item for advertising.

Of course not. It is dissolved into the product price and the maintenance fee.

This part behaves differently from deployment and operations.

Drop the integrator and the integrator's work returns to you. Drop a layer of sales and marketing spend and no work comes back to you at all.

From the buyer's side, it is simply hard to see what you are paying for.

What AI changes most may be the selling, not the product

I do not expect this arrangement to hold indefinitely.

The part most likely to move is demand generation and pre-sales.

Until now a person searched for information, a person heard a pitch at a trade show or from a rep, and a person compared options and chose. That carries a lot of sales and marketing cost.

Once buyers start telling an AI to find and compare products against their own constraints, the cost structure there could change substantially.

The same holds for deployment and operations. Initial configuration, investigation, report writing, routine checks — work that used to require a person can already move into software.

Complex integration with an existing estate, one-off explanations, judgment calls during an incident: those still need people.

What changes is that the human work and the software-replaceable work become separable.

That thinking is why we build PentaTrail ourselves and sell it directly. There is no deployment project after sign-up; checking externally exposed assets and tracking daily change happens in software. ASM is ¥40,000/month and CTEM is ¥68,000/month.

If you need the full enterprise support model, use a company that provides it.

The question is whether companies that do not need it should still have to buy through the same channel.

When I think about what security products cost, that is what I look at, more than the feature list.

PentaTrail figures are our own published prices.

Visualize your attack surface with PentaTrail CTEM/ASM

From discovery to vulnerability validation and remediation — all powered by the CTEM framework.

Get Started

See pricing/Compare and choose