By Sean Cleary, Partner and Cybersecurity Practice Lead
3 Takeaways
- The pendulum has settled. Security spent years buying everything, then swung toward building everything. AI has moved most teams to a hybrid.
- Buying alone underdelivers. In our 2026 Future of Tech Leadership research, 63% of organizations reporting no meaningful AI impact rely primarily on SaaS-first strategies, compared with 38% of respondents overall.
- Hire for judgment. Clients want CISOs who reason from first principles, decide case by case, and treat vendor selection as a core skill.
Cybersecurity Awareness Month tends to fill inboxes with vendor pitches. Fitting, because one of the most common requests I hear from clients right now is for a CISO who knows when to take those meetings and when to build instead. I’m hearing it more often as demand for security leadership climbs. Our security practice is on pace four times as many placements this year as last.
How the Pendulum Swung
For years, security ran on buy, buy, buy. Every new threat category brought a new tool, and plenty of teams ended up managing dozens of products with overlapping coverage and data stuck in separate consoles.
Then engineering-led security teams started building: detection as code, internal platforms, tooling tuned to their own environment. That worked for companies with deep engineering benches and created maintenance debt for everyone else.
AI has pulled the decision to the middle. A small team can now stand up custom detections, triage automation, or internal agents in weeks. Meanwhile, AI-native vendors are shipping faster than most internal teams can. The right call now changes capability by capability.
What the Research Says About Buying Alone
Our 2026 Future of Tech Leadership Report, based on nearly 1,000 technology leaders, measured this for AI broadly. Among organizations reporting no meaningful business impact from AI, 63% rely primarily on SaaS-first strategies, compared with 38% of respondents overall. The organizations getting results pair what they buy with internal technical talent that can integrate, govern, and extend it.
In my experience, security follows the same pattern. A purchased tool pays off when someone on the team configures it to your environment, connects it to your data, and governs how it behaves. The same research found 87% of Advanced organizations bring cybersecurity and governance in at the initial design phase, which puts the CISO in the room when build-or-buy decisions get made. More on that in What Is Shift-Left Security?
What First-Principles Thinking Looks Like
When clients ask for a CISO with first-principles thinking, here’s what they mean. The strongest leaders I place run each decision through a short set of questions:
- Does this capability differentiate us, or does every company need it?
- Who owns the data, and can we get it back out?
- What will a build cost to maintain over three years, people included?
- How does the vendor’s AI handle our data, and can we govern it?
- How fast will this category change, and what’s our exit plan?
Commodity controls with mature vendors usually point to buy. Capabilities tied to your product, your data, or your threat model often point to build. Plenty land in between: buy the platform, build the integrations and automation on top.
How to Test for It in a CISO Search
- Ask for a real build-or-buy decision they made, including one they would reverse.
- Ask which tools they consolidated and what they retired.
- Ask how they evaluate an AI-native vendor’s model and data handling.
- Listen for answers tied to company stage. A Series B CISO and a public company CISO should reach different conclusions on the same question.
Leaders with one fixed answer struggle when the business changes. The ones who meet the business where it is tend to last. For more on what strong candidates look for in return, see our CISO Career Guide.
Frequently Asked Questions
Should a company build or buy its security tools?
It depends on the capability. Commodity controls with mature vendors usually favor buying. Capabilities tied to proprietary products, data, or threat models often favor building. Many organizations now buy core platforms and build integrations and automation on top.
How has AI changed build vs. buy decisions in security?
AI has lowered the cost of building custom security tooling and produced a wave of fast-moving AI-native vendors. Most security teams now run a hybrid model and decide case by case.
What should you look for in a CISO for build vs. buy decisions?
Look for first-principles reasoning, vendor selection experience, a track record of tool consolidation, and the ability to evaluate how AI vendors handle data. Their answers should change with company stage.
Related: How to Hire a CISO
Related: Your Next Move as a CISO: Choosing the Right Seat, and What Comes After It
Sean Cleary leads the cybersecurity executive search practice at Riviera Partners. Connect on LinkedIn.