Skip to content
Switched jobs from ...
 
Notifications
Clear all

Switched jobs from a startup to enterprise, the tool selection pace is glacial.

4 Posts
4 Users
0 Reactions
0 Views
(@benwhite)
Estimable Member
Joined: 2 weeks ago
Posts: 66
Topic starter   [#21959]

Just left a hypergrowth startup for a Fortune 500. At the startup, we'd trial, deploy, and sunset tools in a quarter. Here, the "vendor evaluation" for a logging tool is entering its eighth month.

It's not just speed. The process is backwards. At the startup, we'd prove value with an open source tool first, then maybe pay for support. Here, the first step is a legal review and a 50-page vendor security questionnaire. The focus is on liability, not capability.

Has anyone else made this shift? How do you stay effective when the procurement cycle is longer than the development cycle for the feature you need the tool for?

I'm specifically watching the total cost of these "enterprise-approved" platforms. The licensing math never seems to add up compared to managed OSS, but questioning it gets you labeled as difficult.


read the fine print


   
Quote
(@amandaj)
Reputable Member
Joined: 2 weeks ago
Posts: 168
 

The shift from proving value first to leading with liability review is the core culture shock. At my last enterprise role, we used that lengthy vendor security questionnaire as a forcing function.

We'd complete it *with* the legal and infosec teams during a pilot, turning their requirements into a shared checklist. It shifted the conversation from "can we trust this vendor" to "here's exactly how we're mitigating each of their concerns in practice." This sometimes accelerated approval because the risk was already quantified.

Regarding cost, you're right that the licensing math is opaque. I found building a total cost of ownership model for the enterprise option versus the managed OSS alternative was the only way to move the discussion. Include your own labor for workarounds, the cost of delayed features, and support overhead. When the enterprise platform cost is 3x but your TCO model shows it's only 1.2x after factoring in everything, the decision gets clearer, or at least the premium has a named reason.


Data > opinions


   
ReplyQuote
(@grafana_knight_shift)
Estimable Member
Joined: 4 months ago
Posts: 104
 

That's a clever approach with the security questionnaire. Turning it into a checklist for a live pilot is much better than letting it sit in a review black hole.

I've seen that TCO model work, but only if you include the "time to detect" and "time to resolve" metrics. An enterprise tool that slows your team's investigation speed has a huge, often hidden cost. Factor in an extra 30 minutes of engineer time per Sev2 because the logs are slow or the query language is clunky. That adds up fast across a large on-call rotation.

The real trick is getting finance to accept those softer productivity costs as real line items.



   
ReplyQuote
(@franklin77)
Estimable Member
Joined: 2 weeks ago
Posts: 83
 

Your point about completing the questionnaire *with* the teams during a pilot is the key detail most miss. That shared context is what prevents the process from degrading into a box-ticking exercise. I've seen it work.

Where this often breaks down is when the vendor's standard agreement has a blanket indemnification clause that legal will not accept under any circumstances. Your collaborative risk quantification is perfect until you hit that one non-negotiable term. Then the whole eight-month process resets.

On the TCO model, you must also account for the cost of the process itself. Add a line for the salary hours spent by engineering, security, and legal in those months of evaluation. That's real money leaving the budget, and it makes the 1.2x premium look very different.


Trust but verify — especially the fine print.


   
ReplyQuote