Having recently completed a security tooling evaluation for a multi-cloud (AWS & GCP) environment, our team engaged with Cybereason as part of the process. While the technical capabilities of their EDR/XDR platform were generally well-regarded by my security counterparts, the sales experience introduced significant, and I believe unnecessary, friction due to their strictly partner-led model.
The initial contact was straightforward, but we were quickly handed off to a designated partner. This immediately created a layer of indirection. Concrete issues we encountered:
* **Technical Dilution:** Every detailed architectural question—regarding sensor deployment at scale via Terraform, log ingestion volumes to our SIEM, or integration specifics with our existing Kubernetes security tooling—had to be routed through the partner. The answers often came back delayed and occasionally lost nuance, requiring multiple cycles to get clarity on API rate limits and IAM policy requirements.
* **Pricing Opaqueness:** The partner was reluctant to provide a clear, modular price breakdown. Our request was specific: we wanted to understand the cost driver for endpoint agents versus cloud workload components, and how the pricing scaled with elastic cloud infrastructure. The quotes arrived as monolithic "per endpoint" bundles, making it difficult to map cost to value for our heavily automated, ephemeral serverless and container workloads.
* **Proof-of-Value Hurdles:** Setting up a meaningful, constrained POV in our staging VPCs became a protracted negotiation. The partner's standard deployment playbook didn't align with our infrastructure-as-code (IaC) practices, leading to delays as we worked to translate their manual steps into something we could pilot via our CI/CD pipeline.
This model feels increasingly anachronistic in a cloud-native context. When I can evaluate, provision, and scale other security services directly through AWS Marketplace or with a vendor's technical sales engineer who can speak to CI/CD integration, the partner gatekeeper becomes a tangible slowdown.
My question to this community is whether this is a consistent experience. For those who have adopted Cybereason:
1. Did the partner model ultimately provide deeper, localized value that outweighed the initial friction, perhaps during implementation or support?
2. Were you able to establish a direct technical channel to Cybereason's own solutions architects post-sale, or does the partner remain the permanent interface?
3. In operational terms, how does this model impact the speed of adding new cloud accounts or regions under protection, given the need for potential partner engagement?
The calculus for any platform includes not just the sticker price and feature list, but the total cost of integration and operational agility. I'm concerned that a rigid partner layer inherently reduces agility, and I'm keen to hear if real-world operational experiences bear this out or prove it wrong.
That's a great point about pricing opaqueness. I'm just starting to learn about these vendor evaluations, and I've heard similar things about "bundled" pricing that's hard to break down. Did you ever get a straight answer on the cost drivers, or did you have to just accept the total package quote? I'd be worried about scaling costs later if you don't know what each part costs.