I recently spoke with Richard Stiennon, founder and CEO of IT Harvest. He was VP of Research at Gartner, which gave him a front-row seat to the limits of traditional analyst coverage. That experience led him to build something different: a database that covers 4000+ cybersecurity vendors instead of the 134 that Gartner covers.
We talked about why Gartner is struggling, what vendors consistently get wrong about their own products, the AI hype that is suffocating real innovation, and what gets buyers’ attention in 2026.
What is IT Harvest, and how is it different from traditional analyst coverage?
It’s built on lessons I learned at Gartner. When I was VP of Research there, we had no data. Everyone was just tracking their own area independently. Over the years, more and more cybersecurity companies have launched, and right now we’re at around 4,040 vendors. Gartner covers 134 of those. That’s roughly 3% of the industry.
We call what we do “long tail” analyst coverage, and the reason that matters is the signal is in the startup arena, not in what SAP or the huge established players are doing. The whole AI discussion proves the point. There are no established AI companies in cybersecurity yet. AI companies are only startups. Gartner’s coverage there is thin, and people are starting to realize they don’t need Gartner anymore. They just ask AI directly.
That said, I’ve tested AI against our database, and AI cannot answer the questions we can answer. Ask it how many cybersecurity vendors are headquartered in Canada and it’ll search forever. It doesn’t have a complete list. We do. That makes the difference.
When do you recommend vendors engage with analysts?
Not until they are at about $20 million in revenue. There’s no reason to pay Gartner’s fees before that. You are not going to make it into the Magic Quadrant, and the money isn’t worth it yet.
That said, once you are in that leader’s quadrant, you are made. You have to really screw it up not to be successful at that point. It’s pure validation. Gartner has 13,000+. Big companies. If you make it onto their radar, you suddenly have access to the Global 2000.
You’ve worked on some fascinating projects over the years – tell me about one of your favourites?
Early in my consultant days, I wrote white papers sponsored by vendors. One asked me to demonstrate that Windows Defender was not actually free.
I had to dig into Microsoft’s contract vehicles, get past the code names, calculate out the licensing costs, the servers, the updates, and the support. I could show that using what Microsoft calls free was more expensive than using Symantec.
A few months later, F-Secure asked for the same paper. I wrote it again for them. Trend Micro too. Then Microsoft changed their contracts, and I rewrote the entire analysis for all three vendors. That project made me a lot of money, and the real value was that digging forced me deep into Microsoft’s strategy and positioning. That research positioned me to understand and critique what Microsoft is doing in the market today. You get paid to research, and the research becomes your lasting knowledge.
What is the biggest gap between what vendors claim and what they do?
The frustration is almost universal. Go to any vendor website and ask yourself what they do. It’s painful because you’ll see jargon that has nothing to do with what they ship. Here’s my favorite example. NetFlow is a simple, free capability that every network device uses to report packets and traffic. That’s it. If you’re building a NetFlow monitoring solution, the first thing on your homepage should be “We monitor NetFlow.” Instead, you get “Integrated Network Defense Solution,” which tells you nothing.
The reason is obvious. Vendors hire marketing teams to look big, like IBM or Cisco. The website gets filled with jargon that’s supposed to sound trustworthy. A startup with two people can’t sound like a startup with two people, or nobody will trust them. But here’s what I discovered when I started ingesting product data for our platform.
I was reluctant as I thought it would be too much work, but we had a customer who needed it, so we did it. Something weird happened. We didn’t have to categorize the products ourselves. They self-categorized by keyword. If your product uses NetFlow, it has to say so somewhere in your product description. SEO depends on it. You can’t claim something, have a customer buy based on that claim, get disappointed, and ask for their money back. The product claims are accurate. The exaggeration is about the company itself, not what the product does.
What is the engineer-marketing disconnect?
It’s a communication breakdown. Product teams and engineering don’t tell marketing what they’re working on, or marketing doesn’t ask. I’ve been on both sides. When I was CMO at Fortinet, the CTO called me to a meeting to tell me they’d launched a product yesterday. Here’s the pricing, here’s what it does. Really frustrating. And Fortinet is still an engineering-led company today.
To bridge it, marketing must be embedded in engineering. Show up at product strategy meetings and make it a real, ongoing presence. The CEO has to prioritize it, but it’s doable. Marketing should be involved when the CTO decides what features to include in the next version. It goes both ways, too. Get engineers to Customer Advisory Board meetings for real conversations with customers. When engineering understands what customers care about, the entire organization gets better.
What red flags in vendor messaging make you sceptical?
If they claim AI, and especially now. We’re tracking 430 AI vendors right now. My book covered 378 when I finished the manuscript in March, so between March and now we added 60 new vendors. Now, all the legacy vendors are claiming AI too, and that requires investigation. If a company was founded before November 30th, 2022, and it claims AI, I need evidence of a pivot. You can’t just erase your history. I’ll check the Wayback Machine. Sometimes you find companies that haven’t changed anything. The website says the same thing it did three years ago, just with “AI” bolted on now. Sometimes you find companies like Darktrace with this mythical story about hiring Cambridge PhDs, but there are no Cambridge PhDs working there. The founder named his yacht Bayesian. That’s Bayesian statistical analysis of logs, not AI. It’s worth pushing back on.
What do CISOs and cybersecurity buyers hate in vendor outreach?
They hate cold outreach, and they really hate aggressive cold outreach.
A simple note saying we exist and here’s what we do is fine, but if you message them on LinkedIn, email them, and then call their cell phone, you’re blackballed forever. The right approach is educational outreach and content marketing. Consistent, valuable content that adds to the community. It’s a gamble, right? You’re throwing things out into the wind and hoping they land, but if you do it consistently and genuinely add value, then the good CISOs will come to you.
The vendors who are winning in cybersecurity are the ones doing original research. If you’re the one who found a new attack and can report on it first, everybody reads your stuff. Journalists quote you. It snowballs. A couple AI vendors did this right after Mythos and they published their own research, did their own testing using different models, and recreated the same vulnerabilities. That gets attention. Original research, genuine findings, original perspectives.
Where do you stay on top of what is happening?
I have to track AI because we’re building it into our platform, so I’ve created a bubble on X where I mostly see AI content. The AI community posts original research there, opening new vistas every time I read something.
On cybersecurity, I’ve noticed a major shift. We used to all read Dark Reading and CSO Online, but now I’m much more interested in independent voices. Most journalists are just reacting to press releases, so the real investigative work is coming from independents like Kim Zetter, Andy Greenberg, and Brian Krebs. They’re digging. Most cybersecurity professionals subscribe to Brian Krebs because he’s doing investigative work. People leak information to him because he’s the best outlet for it. That’s the reputation that matters.
Richard Stiennon is founder and CEO of IT Harvest, a data-driven industry analyst firm tracking cybersecurity vendors. He was previously VP of Research at Gartner and CMO of Fortinet. His recent book, Guardians of the Machine Age: Why AI Security Will Define the Future of Digital Defense, explores AI vendors and their claims. Catch him on Substack here.
About Bora
We’re Bora. We work with security companies to turn complex technical capabilities into clear, credible market narratives.
Get in touch for a free 30 minute consultation. If we’re not the right fit, we’ll help find someone who is.





