How can security practitioners make sense of the vendor landscape and separate those who talk a good game from those who can execute, perform, and solve real problems for enterprises?

Every now and again, I feel that the voice of the security practitioner – those in the trenches day-in and day-out defending their enterprises – needs to be heard.  I’m not sure why exactly, but as I write this piece, today just seems like one of those days.  Lately, a few things going on around the industry have caused me to believe that the time is right for me to put on my cranky security analyst hat and put a few things down on paper.

It is not news that the security vendor landscape is crowded – perhaps even overcrowded.  With this comes quite a bit of confusion – everyone seems to market the same way, use the same words, make the same ...

