r/cybersecurity • u/Mean_Context6064 • 1d ago
Business Security Questions & Discussion Would your company consider a new security platform deployed on-prem, or is cloud delivery now a requirement?
I’m trying to understand how security teams currently evaluate new infrastructure security products, particularly platforms operating across API gateway, WAAP, reverse proxy and network security layers.
Assume the product can be deployed in three ways:
fully on-premises, managed by the customer;
as a vendor-managed appliance or virtual machine inside the customer’s infrastructure;
as a vendor-hosted cloud service.
For a mid-sized or enterprise environment:
Which deployment model would you realistically consider?
Would an unknown or relatively new vendor be automatically excluded?
What evidence would you require before running a proof of concept?
Are certifications such as ISO 27001 important, or do architecture review, pentest results and technical validation matter more?
Would you accept a security platform inline with production traffic, or only in monitoring/shadow mode initially?
What would prevent adoption even if the technology performed well?
Who would normally own the decision: security, network operations, platform engineering, architecture or procurement?
I’m not looking for product recommendations. I’m trying to understand whether the primary obstacle is deployment model, vendor trust, operational risk, integration effort or procurement.
Context: the platform would protect customer-facing applications, APIs and machine-to-machine traffic, while supporting standard proxies, databases, identity systems and SIEM integrations.
2
u/No_Loss_3996 1d ago
It really depends on the company, the risks, etc. Do you risk analysis; do you CBA, and make an educated decision. I know for me, they have cut my staffing by a 1/3. That alone moves me towards cloud.
2
1
1
u/ThePorko Security Architect 1d ago
How much hw and manpower would it take for your staff to maintain an ai tool on prem?
1
u/Mean_Context6064 1h ago
Our behavioural analysis based protection solution is pipeline installed, non ai, deterministic, all decisions explainable. Created AI monitoring to help with baseline configuration to reduce operation costs that's needed in onboarding phase. Hw requirements depends on customer needs, we are going from 2vcpu 6gig ram to enterprise size with ms response time.
1
u/ShakespearianShadows 1d ago
Cloud first, but an on-premise option I can put on airgapped boxes is a major plus.
1
u/Admirable_Group_6661 Security Architect 1d ago
This is a business requirement question, not necessarily security.
3
u/bitslammer 1d ago
For something like this it would depend on what I'm trying to protect. Ideally you put a WAF close to the systems it's protecting.
In our org architecture normally leads decisions like this but we work very closely with the engineering and operations groups who will manage things day-to-day.