Security Insights

What the most self-sufficient security teams still outsource

What the most self-sufficient security teams still outsource

What the most self-sufficient security teams still outsource

Zain Rizavi

Co-Founder & CEO

3 min

No headings found on page

Highlights

  • The most self-sufficient security team we've talked to still won't build its own training platform

  • Detection compounds and behavior don't, which is the real build-versus-buy line

  • No engineer wants a career maintaining phishing content, and that is the whole point

Ask any well-funded security team what they build versus what they buy, and you will get the same proud answer: we build what matters; we buy what is commodity. It is a good story about identity, but it hides a stranger and more useful pattern underneath.

This week, in a conversation with the head of security at a large consumer technology company, that pattern showed up cleanly. His team has replaced a major vendor platform with something built entirely in-house. They run their own risk ranking across every digital identity in the company: employees, contractors, service accounts, even AI agents. And yet the one thing they have never seriously tried to build themselves is the software that trains employees not to click.

The thesis

The instinct is to call this a gap, a corner nobody has gotten to yet. It is not a gap. It is a boundary, and the boundary is real: infrastructure compounds, behavior does not. An engineering team can absorb a category once the problem is specified enough to sit still, be modeled, and be automated over. Detection rules, provisioning, log pipelines: these are terrain. Map them once and you own them for years.

Human behavior is closer to weather. It will not sit still long enough to be mapped the same way, which is why the confidence of we build everything that matters sits so close to a precipice. The moment engineering absorbs a problem that is not actually infrastructure, the roadmap discovers a ceiling nobody warned it about.

Why nobody wants the content job

His reasoning was blunt, and once you hear it, obvious: nobody on his team wants a career maintaining a content platform. Not because the work is beneath them. Because there is no ceiling to climb. A detection engine gets measurably better and you can point to it on a roadmap. A phishing template goes stale the moment employees recognize the pattern, and the fix is not a smarter algorithm. It is a person writing a new deception, convincingly enough that other people fall for it once more.

That is a craft problem, renewed on a schedule, with no compounding advantage for the team that already solved it last quarter. The build versus buy line does not run along company size or engineering budget. It runs along whether the work compounds.

The narrow claim

The mistake spreading across the industry right now is treating the human layer as a solved, buyable commodity, something you plug in once and forget, while all the sophistication gets reserved for detection. It is the opposite. The human layer is the part that most needs continuous reinvention, and the vendors serving it deserve to be judged the way engineers judge their own build decisions: not by how much access or automation they have stacked up, but by whether the work keeps getting harder in a way that means someone, or something very attentive, still has to show up and do it by hand every week.

Key Takeways
  • Stop treating human risk training as a commodity that gets plugged in once and forgotten.

  • Judge human-layer vendors by how often they're forced to reinvent their content, not by how much automation they've stacked up.

  • When weighing build versus buy, ask whether the problem compounds like infrastructure or resets like weather, and decide accordingly.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.