Security
Access, secrets, compliance and audits.
Nothing matches that yet
Try a broader category, or add the product you were looking for.
Add a productWhat this shelf covers
Keeping systems and accounts from being taken over: identity and access, endpoint protection, vulnerability management, secrets, monitoring for suspicious activity and the response when something happens.
Products range from a single control to platforms covering an entire estate. What matters is coverage of the paths attackers actually use, which is far narrower than the marketing suggests.
Credential storage for teams sits in password management. Audit evidence and frameworks belong in compliance and GRC.
Buy in the order that matches real risk
Most incidents in small and mid-sized companies start in one of three places: a stolen password, an unpatched system exposed to the internet, or somebody being persuaded to do something by mail.
That order tells you what to buy first. Multi-factor authentication on everything, especially mail and administrative accounts. A managed way to keep systems patched. Endpoint protection with central visibility rather than a licence sitting unwatched on each laptop.
Advanced platforms are worth having later. Bought first, they generate alerts nobody has the time to read, which produces cost without protection.
Identity is the perimeter now
Access control has become the main defence, because the network boundary stopped meaning much once work moved to browsers and phones.
- Single sign-on, so accounts are created and removed in one place.
- Provisioning, tying access to employment rather than to memory.
- Strong second factors, with phishing-resistant options for administrators.
- Least privilege, including short-lived elevation instead of standing rights.
- Session control, so a stolen token has a limited life.
Ask how the product handles the accounts that fall outside single sign-on. Every organisation has some, and they are the ones that get forgotten when somebody leaves.
Endpoints, vulnerabilities and the boring maintenance
Endpoint protection has moved from blocking known threats to recording behaviour and letting you investigate afterwards. The useful question is what an analyst can actually do: isolate a machine, retrieve a file, see the process history, roll something back.
Vulnerability management is less exciting and closes more holes. What matters is not the length of the report but whether it prioritises by exploitability and reachability, and whether fixes can be tracked to completion rather than listed forever.
Patching cadence beats almost every other control in this category. A tool that tells you what is missing without helping you apply it moves the work rather than reducing it.
Watching, and who does the watching
Log collection and alerting only help when somebody responds.
Before buying a platform, decide who reads the alerts at two in the morning and what authority they have. If the honest answer is nobody, a managed service is the better purchase, since it converts a tool into a response.
Then set the noise expectations. Ingest volume drives cost and false positives drive fatigue, so tuning is ongoing work rather than a setup task. Ask what tuning looks like in the product and how alert quality is measured.
People, and the cheapest control available
Training and simulated phishing get mocked and still work, because the attack they address is the most common one.
Keep it short, frequent and specific to the situations your staff actually meet. Pair it with a reporting route that takes seconds, and treat a reported suspicious message as a success rather than an interruption.
Pricing across this category runs per endpoint, per user, per ingested volume or per scan, with managed services charging separately for the human attention. Model the total including that attention rather than the licence alone, alongside the habits described in what pricing pages hide.
What good looks like at three sizes
For a company under twenty people, good means every account protected by a second factor, laptops encrypted and patched, credentials in a vault, and one person who owns the subject. That is achievable without a security team.
At a hundred people, good adds identity management, joiner and leaver automation, endpoint detection, and a documented response plan somebody has actually rehearsed.
Beyond that, the questions become organisational rather than technical: who watches alerts, how quickly a compromised account can be contained, and whether the answers hold at two in the morning on a public holiday.
The pattern worth noticing is that spending rarely fails because a tool was too cheap. It fails because nobody owned the output, which is a staffing decision rather than a purchasing one.
Questions people ask
- What should a small company buy first?
- Multi-factor authentication everywhere, a password manager, and endpoint protection with central visibility. Those three prevent more real incidents than any advanced platform bought before them.
- What is the difference between endpoint protection and detection and response?
- Protection blocks known threats. Detection and response records behaviour, spots suspicious patterns and lets you investigate and contain a machine remotely. The second assumes something will get through.
- Do we need a security operations service?
- If nobody is watching alerts outside working hours, a managed service is more useful than another tool. Alerts nobody reads are an expense, not a control.
- How is security software priced?
- Per endpoint, per user, per ingested volume, or per scan. Log ingestion is the meter that grows fastest, and it grows because of noise rather than because of risk.
- Does a certificate mean we are secure?
- It means a set of controls was assessed against a standard at a point in time. That is useful evidence for customers and no substitute for the practices, which have to keep operating between audits.
Written about this category
- Knowledge base software: how to choose oneKnowledge base software comes in three shapes and six pricing models, and the wrong pairing is where the budget goes. What each one costs and what to test.
- Software for small business, and how to pick oneWhat software for small business actually costs each month, in what order to buy it, and the real prices behind accounting, payroll, CRM and ERP tools.