Data as of Aug 25, 2026 · Based on 305 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
Your brand can be here too.
Calculating Return on Investment (ROI) between a premium, well-known security vendor and a cheaper emerging competitor requires looking past the initial software licensing or service fee. Security ROI isn't just about money saved; it's about risk reduction, operational efficiency, and total cost of ownership (TCO).…
Calculating Return on Investment (ROI) between a premium, well-known security vendor and a cheaper emerging competitor requires looking past the initial software licensing or service fee. Security ROI isn't just about money saved; it's about risk reduction, operational efficiency, and total cost of ownership (TCO).
Here is a structured framework for calculating and comparing the ROI of both options:
The core economic formula for security ROI is:
ROI (%)=Net Security Benefits Total Cost of Ownership (TCO)×100 ROI (%) equals the fraction with numerator Net Security Benefits and denominator Total Cost of Ownership (TCO) end-fraction cross 100 R O I(%)=N e t S e c u r i t y B e n e f i t s T o t a l C o s t o f O w n e r s h i p(T C O)×1 0 0
Where Net Security Benefits equals the value of risk reduced (Expected Loss Avoided) plus operational savings, minus the TCO.
Do not just look at the sticker price. Sum all direct and indirect costs over a 3-to-5-year lifecycle:
Use Quantitative Risk Analysis (such as FAIR - Factor Analysis of Information Risk) to calculate how much financial loss each vendor realistically prevents:
Annual Loss Expectancy (ALE) Reduction=(Single Loss Expectancy×Initial Annual Rate of Occurrence)−(SLE×Mitigated Annual Rate of Occurrence)Annual Loss Expectancy (ALE) Reduction equals open paren Single Loss Expectancy cross Initial Annual Rate of Occurrence close paren minus open paren SLE cross Mitigated Annual Rate of Occurrence close paren A n n u a l L o s s E x p e c t a n c y(A L E)R e d u c t i o n=(S i n g l e L o s s E x p e c t a n c y×I n i t i a l A n n u a l R a t e o f O c c u r r e n c e)−(S L E×M i t i g a t e d A n n u a l R a t e o f O c c u r r e n c e)
Build a side-by-side matrix over 3 years:
| Cost/Benefit Metric | Expensive/Well-Known Vendor | Cheaper Emerging Competitor |
|---|---|---|
| 3-Year Licensing Cost | Higher (X) | Lower (Y) |
| Implementation & Staffing | Lower (Plug-and-play, native skills) | Higher (More custom engineering/tuning) |
| Estimated Risk Mitigation | High (95% risk reduction) | Moderate (80% risk reduction) |
| Compliance / Sales Friction | Low (Instant trust from clients/auditors) | Moderate (May need extra documentation) |
| Calculated Net ROI | ROI A ROI sub cap A R O I𝐴 | ROI B ROI sub cap B R O I𝐵 |
Often, the "cheaper" vendor sees a drop in net ROI if the internal labor required to manage it or the cost of a single missed incident eclipses the initial savings on license fees.
If you'd like, share:
I can help you build a more tailored cost-benefit breakdown for your specific situation.
No sources cited
The key is to **compare expected business value, not vendor price**. For security software, a cheaper product can have a worse economic outcome if it creates more operational work or materially increases the probability or impact of a breach. NIST similarly recommends assessing supplier risk in proportion to the…
The key is to compare expected business value, not vendor price. For security software, a cheaper product can have a worse economic outcome if it creates more operational work or materially increases the probability or impact of a breach. NIST similarly recommends assessing supplier risk in proportion to the criticality and potential impact of the product or service.
Don't compare just annual subscription prices.
Include:
Call this Total Cost of Ownership (TCO).
For example:
| Established vendor | Emerging vendor --- | --- | --- 5-year licensing | $1.5M | $750K Implementation/integration | $200K | $350K Internal labor | $300K | $600K Support/training | $150K | $250K 5-year TCO | $2.15M | $1.95M
The apparent $750K licensing saving has become only $200K of actual savings.
This is the harder—and more important—part.
Estimate the annualized loss expectancy (ALE) without the product and with each product:
ALE = probability of incident × financial impact of incident
Consider:
Then:
Risk reduction value = ALE(before) − ALE(after)
Don't assume the established vendor automatically has superior security. Instead, demand evidence for the difference.
This is where the established-vs-emerging decision becomes interesting.
An emerging vendor might introduce additional uncertainty around:
NIST specifically recommends assessing vendors' security posture and, where appropriate, obtaining third-party attestations and examining their software-development practices.
Instead of saying "the emerging vendor feels riskier," estimate the incremental expected cost.
For example:
Established vendor: estimated probability of a vendor-related disruption over 5 years = 5% Emerging vendor: estimated probability = 12% Financial impact if disruption occurs = $2M The incremental expected risk is roughly:
(12% − 5%) × $2M = $140K
That $140K is economically comparable to a price premium.
A well-known vendor may justify a premium if it saves your people significant time.
Suppose:
Likewise, if the emerging product requires substantially more tuning, troubleshooting, or custom integration, that isn't "free" just because the vendor charges less.
A useful model is:
Risk-adjusted ROI = (Benefits + avoided losses − TCO) / TCO
Where benefits include:
And avoided losses should incorporate the probability-weighted risk differences between vendors.
For a more rigorous investment decision, calculate NPV over 3–5 years rather than relying solely on simple ROI.
This is often the most useful executive metric.
Suppose:
The established vendor is producing $350K/year of incremental economic value.
Its $500K higher five-year cost could therefore be justified if the additional value is sustained for roughly 1.4 years.
Conversely, if you can't quantify at least $500K of incremental value, the premium probably isn't economically justified.
A famous vendor's reputation is useful evidence, but it shouldn't receive an arbitrary ROI multiplier.
I'd score both vendors against the same criteria:
| Factor | Weight | Vendor A | Vendor B |
|---|---|---|---|
| Security efficacy | 30% | ||
| Reliability/resilience | 15% | ||
| TCO | 20% | ||
| Integration/operations | 15% | ||
| Vendor viability | 10% | ||
| Compliance/assurance | 5% | ||
| Innovation/roadmap | 5% |
For critical security systems, I'd also make certain requirements pass/fail rather than weighted. For example, inadequate incident notification, unacceptable data handling, or inability to meet required security controls shouldn't be compensated for by a low price.
NIST recommends contractual security requirements, supplier verification, ongoing monitoring, and revalidation, with the rigor matched to the criticality of the service.
Ultimately, ask:
"How much additional economic value does the established vendor create, and is that value greater than its incremental cost?" If the emerging vendor is $1M cheaper but creates $1.5M of additional expected risk and operational cost, it's actually the more expensive choice.
If the established vendor is $1M more expensive but the evidence suggests only $300K of additional expected value, the brand premium isn't justified.
For a security investment, I'd therefore present the executive decision as three numbers: 5-year TCO, 5-year expected risk-adjusted benefit, and risk-adjusted ROI/NPV—with the assumptions and uncertainty ranges clearly shown. This is consistent with the broader NIST approach of integrating supplier cybersecurity risk into organizational risk-management and acquisition decisions.
Conversely, if you can't quantify at least $500K of incremental value, the premium probably isn't economically justified.
A famous vendor's reputation is useful evidence, but it shouldn't receive an arbitrary ROI multiplier.
I'd score both vendors against the same criteria:
| Factor | Weight | Vendor A | Vendor B |
|---|---|---|---|
| Security efficacy | 30% | ||
| Reliability/resilience | 15% | ||
| TCO | 20% | ||
| Integration/operations | 15% | ||
| Vendor viability | 10% | ||
| Compliance/assurance | 5% | ||
| Innovation/roadmap | 5% |
For critical security systems, I'd also make certain requirements pass/fail rather than weighted. For example, inadequate incident notification, unacceptable data handling, or inability to meet required security controls shouldn't be compensated for by a low price.
NIST recommends contractual security requirements, supplier verification, ongoing monitoring, and revalidation, with the rigor matched to the criticality of the service.
Ultimately, ask:
"How much additional economic value does the established vendor create, and is that value greater than its incremental cost?"
When comparing a premium, well-known security vendor with a lower-cost emerging competitor, a business should avoid treating the decision as a simple “license price vs. license price” comparison. Security ROI is usually about **risk reduction, total cost of ownership, operational impact, and confidence in outcomes**.…
When comparing a premium, well-known security vendor with a lower-cost emerging competitor, a business should avoid treating the decision as a simple “license price vs. license price” comparison. Security ROI is usually about risk reduction, total cost of ownership, operational impact, and confidence in outcomes. A common approach is to calculate a Return on Security Investment (ROSI) rather than traditional revenue ROI.
Start with the full lifecycle cost of each option:
TCO = Acquisition cost + Implementation cost + Operating cost + Maintenance cost
Include:
A cheaper vendor may have a lower purchase price but higher internal labor, weaker integrations, or more management overhead.
Example:
| Cost category | Premium vendor | Emerging vendor |
|---|---|---|
| Annual license | $300,000 | $150,000 |
| Implementation | $75,000 | $100,000 |
| Internal administration | $50,000/year | $120,000/year |
| 3-year TCO | $1.125M | $910K |
The emerging vendor is still cheaper, but the gap is smaller than the license price suggests.
Security investments create value by reducing the likelihood or impact of incidents.
A simplified ROSI calculation:
ROSI = (Expected loss avoided − Security investment cost) ÷ Security investment cost
Estimate:
Expected annual loss (before vendor) = Probability of incident × Cost of incident
Then estimate how much each vendor reduces that risk.
Example:
Risk reduction value:
Now compare those benefits against TCO.
A well-known vendor often commands a premium because of factors that are harder to quantify:
Translate these into financial assumptions where possible.
Examples:
The lower-cost vendor should be evaluated with due diligence, not automatically discounted.
Ask:
You can model this as a probability-adjusted cost.
Example:
Add that expected cost into the TCO.
Create a scorecard weighted by business priorities:
| Factor | Weight | Premium vendor | Emerging vendor |
|---|---|---|---|
| Risk reduction | 35% | 9/10 | 7/10 |
| TCO | 25% | 6/10 | 9/10 |
| Support quality | 15% | 9/10 | 6/10 |
| Integration effort | 15% | 8/10 | 7/10 |
| Vendor stability | 10% | 10/10 | 5/10 |
This prevents the decision from becoming only a price comparison.
Because security ROI relies on estimates, test different scenarios:
A decision may change if:
Choose the premium vendor when:
Choose the emerging vendor when:
The strongest business case is usually not “Vendor A is cheaper” or “Vendor B is famous.” It is: “Vendor A/B produces the highest risk reduction per dollar over the expected life of the investment.”
Choose the premium vendor when:
Choose the emerging vendor when:
Calculating Return on Investment (ROI) when choosing between a premium, enterprise-grade security vendor and a budget-friendly emerging competitor requires looking past the upfront software subscription cost. Cybersecurity ROI accounts for both direct financial savings and the **risk reduction value** of preventing…
Calculating Return on Investment (ROI) when choosing between a premium, enterprise-grade security vendor and a budget-friendly emerging competitor requires looking past the upfront software subscription cost. Cybersecurity ROI accounts for both direct financial savings and the risk reduction value of preventing costly breaches.
Here is a structured framework to calculate and compare the ROI for both options:
TCO goes far beyond the licensing sticker price. For each vendor, estimate costs over a 3-year period:
Use standard quantitative risk assessment formulas to determine how much financial risk each vendor mitigates:
Apply the standard ROI formula using the prevented financial loss minus the total cost of ownership, divided by the total cost of ownership:
ROI=Prevented Loss (Risk Reduction Value)−TCO TCO×100%ROI equals the fraction with numerator Prevented Loss (Risk Reduction Value) minus TCO and denominator TCO end-fraction cross 100 %R O I=P r e v e n t e d L o s s(R i s k R e d u c t i o n V a l u e)−T C O T C O×1 0 0%
Numbers alone don't tell the whole story. Weight these qualitative factors into your final decision:
If you'd like, share:
I can help tailor these calculations or build a customized comparison matrix for your specific budget.
No sources cited
The key is **not to compare vendor prices; compare risk-adjusted total economic value**. NIST recommends considering both implementation/operating costs and the reduction in expected losses, including indirect costs such as staffing, training, maintenance, and productivity impacts. [NIST…
The key is not to compare vendor prices; compare risk-adjusted total economic value. NIST recommends considering both implementation/operating costs and the reduction in expected losses, including indirect costs such as staffing, training, maintenance, and productivity impacts.
For each vendor, calculate:
Security ROI = (Expected loss avoided + other measurable benefits − total cost) ÷ total cost
Where:
1. Total cost of ownership (TCO) Include more than the subscription/license:
NIST specifically recommends looking at the full cost of a security service rather than just its acquisition price.
2. Expected loss avoided
Estimate your baseline annualized risk:
ALE = probability of an incident × financial impact of the incident Then estimate how much each vendor reduces that risk:
Risk reduction benefit = baseline ALE − vendor-adjusted ALE For example:
| Established vendor | Emerging vendor --- | --- | --- Annual TCO | $600k | $300k Baseline annual expected loss | $2.0M | $2.0M Expected loss after controls | $800k | $1.0M Risk reduction | $1.2M | $1.0M Net economic benefit | $600k | $700k Simple ROI | 100% | 233%
In this hypothetical example, the cheaper vendor wins on pure financial ROI, despite providing somewhat less risk reduction.
But that's not necessarily the right decision.
This is where the established-vs-emerging comparison gets interesting.
A well-known vendor may provide economic value that isn't captured by the sticker price:
Conversely, don't automatically assign the established vendor a "trust premium." Test those claims. If the emerging competitor has equal detection effectiveness, excellent support, strong financial backing, and comparable security controls, brand recognition alone shouldn't justify paying twice as much.
NIST's risk-management approach emphasizes selecting controls based on effectiveness, efficiency, constraints, and organizational risk—not simply choosing the most expensive or familiar option.
This is especially important for an emerging vendor because the estimates are likely less certain.
Instead of saying:
"Vendor B reduces incidents by 40%." model a range:
Do the same for implementation costs, downtime, support requirements, and incident-response effectiveness. NIST describes three-point estimation as one way to represent uncertainty in risk-response costs.
Then calculate expected ROI and downside ROI, not just the optimistic case.
Some factors shouldn't be traded away for a higher ROI.
For example, if Vendor B can't meet a mandatory regulatory requirement, lacks a necessary security capability, or leaves an unacceptable residual risk, its attractive price doesn't make it a viable option.
A useful decision structure is:
NIST likewise frames cost-benefit analysis as comparing the cost of a control against the reduction in potential losses, while considering implementation, maintenance, personnel, and other indirect costs.
Rather than asking:
"Is the established vendor worth the extra $300,000?" ask:
"What additional risk reduction and business value do we get for that extra $300,000, and how confident are we that we'll actually realize it?" If the established vendor costs $300k more but reduces expected annual losses by $500k more, it's economically attractive. If it reduces expected losses by only $100k more, the emerging vendor may be the better investment—unless the established vendor's reliability, compliance, support, or failure-risk advantages close that gap.
For a board-level decision, I'd present three numbers for each vendor: 3–5 year TCO, expected annual risk reduction, and risk-adjusted NPV, plus a sensitivity analysis showing what happens if the emerging vendor underperforms expectations. That makes the "brand premium" an explicit, testable business assumption rather than a gut feeling.
NIST's risk-management approach emphasizes selecting controls based on effectiveness, efficiency, constraints, and organizational risk—not simply choosing the most expensive or familiar option.
Calculating Return on Investment (ROI) between a premium, well-known security vendor and a cheaper, emerging competitor requires looking past the surface-level software license costs. Security ROI formulas must account for risk reduction, operational efficiency, and the hidden costs of…
Calculating Return on Investment (ROI) between a premium, well-known security vendor and a cheaper, emerging competitor requires looking past the surface-level software license costs. Security ROI formulas must account for risk reduction, operational efficiency, and the hidden costs of failure.
Here is how a business should break down and calculate the true ROI for each option:
Would you like me to help you build a customized spreadsheet matrix or detail specific risk-weighting factors for your industry?
The key is to **compare risk-adjusted economics, not vendor prices**. A well-known vendor may deserve a premium—but only if you can quantify what that premium buys you. ### 1. Start with 3–5 year TCO Calculate the full cost of each option:
The key is to compare risk-adjusted economics, not vendor prices. A well-known vendor may deserve a premium—but only if you can quantify what that premium buys you.
Calculate the full cost of each option:
TCO = license/subscription + implementation + integration + internal labor + training + support + infrastructure + renewals + switching/exit costs
Include costs that don't appear on the quote. For example, a cheaper platform may require substantially more internal security-engineering time or custom integrations. NIST's current supplier due-diligence guidance likewise emphasizes evaluating suppliers beyond the purchase price, including resilience and foundational security practices.
Estimate the annualized loss expectancy (ALE) for relevant threats:
ALE = probability of incident × financial impact of incident
Do this for risks such as:
Then estimate how much each vendor actually reduces those probabilities or impacts.
For example:
| Established vendor | Emerging vendor | |
|---|---|---|
| 3-year TCO | $900k | $600k |
| Expected annual security loss before solution | $1.2M | $1.2M |
| Expected annual loss after solution | $500k | $650k |
| Annual risk reduction | $700k | $550k |
The emerging vendor is cheaper, but the established vendor produces $150k more annual risk reduction. Whether that's worth the $300k additional TCO depends on the time horizon and other benefits.
For the decision between two vendors, the most useful question is:
What am I getting for the extra $300k?
One useful formulation is:
Incremental ROI = (incremental benefits − incremental cost) / incremental cost
Benefits can include:
A security ROI calculation should be supported by evidence for how the solution changes actual risk, rather than simply assigning a dollar value to having more features.
This is where the established vendor can legitimately justify a premium.
Don't simply assign points for "brand reputation." Instead, translate the difference into measurable risk:
For instance, if a startup has a 10% estimated probability of becoming unable to support the product over your planning horizon and switching would cost $500k, that's a $50k expected switching risk. If your evidence suggests the established vendor's equivalent risk is only 2%, its corresponding expected cost is $10k. The established vendor therefore has a $40k economic advantage from this factor.
This is essentially expected monetary value (EMV): probability × financial consequence. Risk-adjusted vendor scoring is a useful complement to TCO.
A large logo isn't itself an ROI benefit. Ask what the reputation actually provides:
Evidence worth paying for
Weak evidence
NIST recommends supplier due diligence around areas such as provenance, resilience, foundational cyber practices and supply-chain tiers—not simply judging a supplier by its size or familiarity.
For an emerging competitor, a POC can convert uncertainty into data.
Give both vendors the same representative environment and measure things like:
This is particularly important because a cheaper product that requires twice as much human effort may not actually be cheaper. Independent guidance on cybersecurity vendor selection similarly recommends evaluating technical fit, integration, support, vendor stability and financials rather than relying on price.
I'd ultimately build a model like:
Net economic value = risk reduction + operational savings + strategic benefits − TCO − residual vendor risk
Then run sensitivity analysis on the assumptions that matter most.
For example:
"The established vendor is preferable unless the emerging vendor's annual probability of a major security failure is below 3.5%."
That's much more useful to an executive than:
"Vendor A scored 87/100 and Vendor B scored 82/100."
The established vendor is worth the premium when its additional cost is smaller than the additional expected value from lower security, operational, or vendor-continuity risk.
The emerging vendor is preferable when it demonstrates comparable security outcomes and reliability, while delivering materially lower TCO—and the remaining uncertainty can be controlled through a POC, references, SLAs, contractual protections, data portability and an exit plan.
In other words: don't pay for reputation; pay for demonstrably lower risk and lower total cost. NIST's current guidance supports treating supplier selection as a cybersecurity supply-chain risk decision, with due diligence and contractual requirements built into the relationship.
Calculating the Return on Investment (ROI) when choosing between a premium, well-known security vendor and a cheaper emerging competitor requires looking beyond the initial software licensing or service fee. True security ROI factors in risk reduction, operational overhead, and potential loss…
Calculating the Return on Investment (ROI) when choosing between a premium, well-known security vendor and a cheaper emerging competitor requires looking beyond the initial software licensing or service fee. True security ROI factors in risk reduction, operational overhead, and potential loss mitigation.
Use the foundational financial formula adapted for risk management:
ROI=Net Financial Benefit Total Cost of Ownership (TCO)×100%ROI equals the fraction with numerator Net Financial Benefit and denominator Total Cost of Ownership (TCO) end-fraction cross 100 %R O I=N e t F i n a n c i a l B e n e f i t T o t a l C o s t o f O w n e r s h i p(T C O)×1 0 0%
Where:
Do not just compare sticker prices. Sum all direct and indirect expenses over a 3-to-5-year lifecycle for both options:
Quantify how effectively each vendor reduces the probability and impact of a security incident:
Assign a weighted risk factor to the emerging competitor:
To synthesize the comparison, build a weighted scorecard:
If ROI established ROI sub established end-sub R O I e s t a b l i s h e d is higher after factoring in labor and risk, the premium price is justified by risk mitigation and operational efficiency. If the emerging vendor provides 90% of the capability at 30% of the cost and your internal team has the bandwidth to manage the operational delta, the budget option yields a higher financial return.
If you'd like, let me know:
I can tailor this calculation with more precise operational cost estimates.
Calculating Return on Investment (ROI) between a premium, well-known security vendor and a cheaper emerging competitor requires looking past the sticker price. Security ROI is fundamentally about **risk reduction** and **cost avoidance** , not direct revenue…
Calculating Return on Investment (ROI) between a premium, well-known security vendor and a cheaper emerging competitor requires looking past the sticker price. Security ROI is fundamentally about risk reduction and cost avoidance , not direct revenue generation.
Here is how a business should structure that calculation:
If you'd like, let me know:
I can help you plug in estimated metrics or build out a tailored cost-comparison framework.
The key is **not to calculate ROI as “security benefit ÷ license price.”** Compare the vendors on **risk-adjusted total economic value**. NIST’s approach is explicitly risk-based, considering effectiveness, efficiency, and constraints rather than simply selecting the lowest-cost control. CISA likewise recommends using…
The key is not to calculate ROI as “security benefit ÷ license price.” Compare the vendors on risk-adjusted total economic value.
NIST’s approach is explicitly risk-based, considering effectiveness, efficiency, and constraints rather than simply selecting the lowest-cost control. CISA likewise recommends using measurable security outcomes to justify investments and says that, when offerings are otherwise similar, procurement should favor the more secure supplier.
For each vendor, estimate:
TCO =
A cheaper vendor can lose its advantage if it requires substantially more engineering or administration.
Estimate the annualized loss expectancy (ALE) before and after deployment:
ALE = probability of incident × financial impact of incident
Then:
Expected annual risk reduction = ALE(before) − ALE(after)
Include impacts such as:
Do this separately for meaningful threat scenarios rather than assigning one arbitrary “security score.”
This is where the established vendor versus emerging competitor gets interesting.
Give each vendor an evidence-based estimate for things such as:
| Factor | Established vendor | Emerging vendor |
|---|---|---|
| Demonstrated detection/prevention | Strong historical evidence | May have less evidence |
| Product maturity | Usually higher | Potentially less mature |
| Support/SLA | More predictable | Verify carefully |
| Financial/company stability | Often easier to assess | Higher uncertainty |
| Integration effort | Known | Could be higher |
| Innovation | May be slower | Could be faster |
| Switching risk | Usually lower | Potentially higher |
| Security assurance | More third-party evidence may exist | Validate independently |
Don't automatically assign the emerging company a penalty simply because it's young. Price the uncertainty based on evidence. NIST specifically treats third-party and supply-chain risk as something to identify, assess and mitigate throughout the vendor lifecycle.
A useful simplified model is:
[ ROI = \frac{\text{Risk reduction} + \text{other measurable benefits} - \text{TCO}}{\text{TCO}} ]
For a more sophisticated comparison, calculate NPV over 3–5 years, including the probability-weighted costs of vendor failure, security incidents, migration, and major service disruption.
For example:
Then:
They're economically equivalent before considering uncertainty and strategic benefits. If the established vendor provides materially better evidence of reliability, support, compliance, or incident response, its extra $200k may be justified.
An emerging vendor may offer benefits that are harder to quantify:
Conversely, the established vendor may provide valuable but less obvious benefits:
Treat these as separate assumptions, rather than quietly baking them into a subjective vendor score.
This is particularly important because cyber-risk probabilities are uncertain.
Ask:
How wrong would our assumptions have to be for the cheaper vendor to stop being the better investment?
For example, if the emerging vendor wins unless its probability of a serious security incident is more than 30% higher, that's a very different decision from one where the business case depends on a highly uncertain 2% difference.
I'd present management with three cases:
Conservative / Base / Optimistic
and show the 3–5 year NPV and ROI for each vendor under each case.
Ultimately, don't ask:
“Is the established vendor worth the 40% premium?”
Ask:
“Does the additional $X we spend buy enough additional risk reduction, operational reliability, and business value to exceed $X?”
If the answer is yes, choose the established vendor. If not, the emerging vendor may have the superior ROI—even if its brand is less established.
And for either choice, make the assumptions contractual where possible: security requirements, SLAs, incident notification, vulnerability disclosure, support response, audit rights, data handling, exit assistance, and remediation obligations. CISA's guidance emphasizes measurable security outcomes and vendor-selection criteria rather than simply relying on reputation.