Discussion about this post

User's avatar
Cyril Simonnet's avatar

The moat thesis is the part that stuck with me, because a moat cuts both ways. The same lock-in that makes a provider defensible is exactly what turns them into your concentration risk, and the cost numbers nobody pitches are usually the cost of not being able to leave. My own piece argues the same thing from the buyer side, that your security provider is a bigger single point of failure than you are, so I read your moat framing as the vendor's version of the risk I keep flagging. We land in the same place from opposite ends of the contract.

https://cyrilsimonnet.substack.com/p/your-security-provider-is-a-bigger

No posts

Ready for more?