Introduction
Most business owners wouldn’t hesitate to ask a financial advisor how they’re compensated. It’s a normal question, because everyone understands that advice and commission sitting in the same place is worth knowing about. The advisor may be excellent and the recommendation may be the right one, but the question is still reasonable.
Almost nobody asks the same about cybersecurity.
Security products are usually purchased through a reseller, an integrator, or a managed provider who also serves as the advisor. That firm assesses the environment, identifies gaps, and recommends products. It then sells those products, and it earns a margin on what the client buys. The recommendation and the revenue come from the same organization, and in most cases the client has no visibility into how much of the price is for the product and how much is marked up.
This is the standard model. It isn’t hidden or unusual. But it is worth examining, particularly during budget season, when the year’s purchases get decided.
What the Model Quietly Encourages
The value-added reseller arrangement developed for sensible reasons. Vendors need channel partners, businesses need help navigating a crowded product landscape, and someone has to do the work of matching a company to the right tools. None of that is objectionable.
The difficulty is structural rather than ethical. When a firm’s revenue depends on product sales, several things become true regardless of anyone’s intentions. Recommending fewer products is financially worse than recommending more. Telling a client that an existing tool is sufficient generates no revenue at all, while replacing it does.
None of this means resellers give bad advice. Many are genuinely excellent, and plenty routinely tell clients not to buy things. The point is narrower: the client cannot easily distinguish good advice from well-delivered sales, because both look identical from the outside. .
That uncertainty has a real cost. It is one reason security stacks grow faster than security capability, and one reason businesses end up with overlapping tools nobody fully uses.
Three Questions Worth Asking
None of the following are confrontational, and any firm operating transparently should be able to answer them:
How are you paid on what I buy? Not whether the firm earns margin, since most do, but how much and on what. A clear answer is a good sign. A vague one is informative in itself.
Does your recommendation change depending on what I purchase? This is the heart of it. If the advisor’s compensation is identical whether you buy three products or none, the advice is easier to take at face value. If it isn’t, the advice may still be correct, but it may deserve more consideration.
Can I see what this product actually costs? In most arrangements the answer is no, as the markup & original price is bundled into a single figure. Bundled pricing is common and often reasonable, since resellers negotiate rates they aren’t always free to disclose. What matters is whether the conversation is an easy one to have.
A firm that welcomes these questions is demonstrating something meaningful. A firm that deflects them has answered anyway.
Why This Matters More Now
Two things have made the incentive question more consequential than it was a few years ago.
The first is the sheer size of the product landscape. There are now hundreds of credible security products across dozens of categories, many overlapping substantially. Choosing among them is genuinely difficult, which means businesses depend more heavily on advice at exactly the moment when the advice is hardest to verify.
The second is budget pressure. Security spending has grown steadily while most other technology budgets have been scrutinized, and that combination invites exactly the wrong kind of purchasing. Buying more becomes the visible signal that security is being taken seriously, whether or not the purchases connect to any coherent plan.
A Structure That Removes the Question
There is another way to arrange this, and it is worth understanding as a model rather than as a product pitch.
If a firm earns nothing on what the client buys, the incentive problem disappears entirely.
Advice becomes advice. The advisor has no reason to recommend more products, no reason to favor one vendor over another, and no reason to replace a tool that’s already working.
This is how we built our Secutor Insider Direct program. Members are paired with an expert Fractional CISO or CISO Advisor who carries no commission, and customers procure their security products at Secutor’s own cost. The entire business model runs on a fixed membership fee, which means the recommendation and the revenue are structurally separate. There is no version of the arrangement where advising a member to buy more improves Secutor’s outcome.
The practical effect shows up at onboarding. New members receive a NIST Cybersecurity Framework assessment alongside a full mapping of their existing security products, down to vendor, license count, price, and renewal date. That mapping lets us determine what a business already has before anyone discusses what it might need, which is the reverse of how most security procurement begins.
Final Perspective
The question is not whether your current provider is trustworthy. Most are. The question is whether you can tell, and whether the structure of the relationship makes that easy or difficult to determine.
Businesses examine incentives carefully in nearly every other area of spending. Security deserves the same scrutiny, particularly as the budgets grow and the product landscape becomes harder to navigate alone.
If you would like to understand what your security spending looks like without a margin attached to the advice, we’d be happy to walk you through it.
Connect with an Expert for a Free Consultation
Secutor is your team of world-class problem solvers with vast expertise and experience delivering complete solutions keeping your organization protected, audit-ready, and running smoothly. Use the form below to contact us for a free consultation.

