In this article
The DTX Cyber Leaders' Summit Panel
At the DTX Cyber Leaders' Summit in Manchester on November 20, 2024, I had the opportunity to participate in a panel discussion titled "Build or Buy: Deciding the best path for your cybersecurity solutions." The panel was moderated by Jamie Whitecombe-Jones, Cytix's CISO advisor, and featured Deepa Ramadoss, Head of Security Risk Management at PXC, and Michael Heritage, Global Vice President of Cyber Security for the Financial Times.
The discussion centered on one of the most important strategic decisions facing security leaders today: when to develop cybersecurity solutions internally versus purchasing existing products from specialized vendors. The insights shared during this panel reflect the real-world challenges and opportunities that organizations face when building their security technology stack.
The Case for Building Custom Solutions
Tailored to Specific Needs
Building a security solution internally offers the ultimate in customization. Organizations can create tools that are precisely tailored to their specific:
Business requirements: Perfectly aligned with unique operational needs
Technical architecture: Seamlessly integrated with existing systems
Security policies: Exactly matching organizational security frameworks
Compliance requirements: Addressing specific regulatory obligations
Complete Control and Flexibility
When you build internally, you maintain complete control over the solution's features, roadmap, and evolution. This control allows for rapid adjustments, custom integrations, and the ability to respond immediately to changing business requirements without depending on external vendors.
The Hidden Costs of Building
Beyond Initial Development
During the panel, I highlighted that while building a solution internally allows for customization, it often becomes expensive, time-consuming, and complex. The true cost of building extends far beyond initial development:
Ongoing maintenance: Continuous updates, bug fixes, and security patches
Feature development: Building new capabilities as requirements evolve
Infrastructure costs: Hosting, monitoring, and scaling the solution
Talent acquisition: Hiring and retaining specialized developers
Opportunity cost: Resources diverted from core business activities
The Risk of Over-Engineering
Organizations often end up with overly costly solutions when a pre-built product could have addressed the problem more efficiently. The desire for perfect customization can lead to feature creep, extended development timelines, and solutions that are more complex than necessary for the actual business need.
The Advantages of Buying
Faster Time to Value
Purchasing existing cybersecurity solutions offers several compelling advantages:
Immediate deployment: Solutions that can be implemented quickly
Proven effectiveness: Tools that have been tested and refined by other organizations
Continuous innovation: Access to ongoing feature development and improvements
Professional support: Vendor-provided training, documentation, and technical support
Predictable costs: Clear pricing models and budget planning
Focus on Core Business
By purchasing rather than building, organizations can focus their internal resources on core business activities and strategic initiatives rather than maintaining cybersecurity tools. This focus often leads to better business outcomes and more efficient resource utilization.
The Middle Ground: Design Partnerships
Collaborative Development
The panel also explored the concept of design partnerships, where large companies collaborate with external firms to create products specific to their use cases. This approach can offer benefits of both building and buying:
Customization without full development costs: Tailored solutions without internal development overhead
Shared risk: Development costs and risks shared between partners
External expertise: Access to specialized knowledge and experience
Faster development: Leveraging existing platforms and frameworks
Considerations for Design Partnerships
While design partnerships can be beneficial, they require careful consideration to ensure the external company is capable and willing to develop the desired solution. The viability depends on the product's relevance to a broader market and the startup's ability to adapt to changing requirements.
Decision Framework: When to Build vs. Buy
Build When:
Unique requirements: Highly specific needs that off-the-shelf products cannot meet
Competitive advantage: The solution itself provides strategic business value
Existing capabilities: Strong internal development teams and infrastructure
Long-term commitment: Willingness to invest in ongoing maintenance and development
Integration complexity: Existing systems make external solutions difficult to implement
Buy When:
Standard requirements: Common security needs that existing products address well
Resource constraints: Limited development resources or budget
Time sensitivity: Need for rapid deployment and immediate value
Risk aversion: Preference for proven solutions over experimental development
Focus priorities: Desire to concentrate on core business activities
The Startup Perspective
Many Startups Rely on Design Partnerships
Many startups rely on the design partnership model, working closely with early customers to develop solutions. However, this approach has important considerations:
Market viability: Solutions must be relevant to a broader market beyond the initial customer
Adaptability: Ability to evolve beyond the specific requirements of the design partner
Resource balance: Managing development for one customer while building for many
Long-term vision: Maintaining product direction while accommodating partner feedback
Practical Recommendations
Start with a Clear Assessment
Before making a build vs. buy decision, organizations should conduct a thorough assessment:
Requirements analysis: Clearly define what you need vs. what you want
Market research: Thoroughly investigate available solutions
Total cost of ownership: Calculate the full cost of building and maintaining vs. purchasing
Risk assessment: Evaluate the risks of each approach
Timeline considerations: Consider how quickly you need the solution
Consider Hybrid Approaches
Many successful organizations use hybrid approaches, purchasing solutions for standard needs while building custom integrations or specialized functionality. This strategy can provide the best of both worlds while managing costs and complexity effectively.
Conclusion: Most Organizations Should Buy
The panel's consensus was that for most organizations, purchasing a cybersecurity solution is often more practical than building one from scratch due to resource constraints. The complexity, cost, and ongoing commitment required for building typically outweigh the benefits of customization.
However, for highly specific needs that off-the-shelf products cannot meet, developing a custom solution or engaging in a design partnership may be worthwhile. The key is to make this decision based on clear analysis of requirements, resources, and strategic priorities rather than assumptions about what might be better.
Ultimately, the build vs. buy decision should align with your organization's core competencies, strategic objectives, and resource constraints. The best choice is the one that enables you to achieve your security goals most effectively while supporting broader business success.








