Nobody got fired for buying Cisco. Or did they?

AnubisNetworks By AnubisNetworks • August 10, 2026

As Cisco grew into the dominant email security vendor, A saying became loud into this space: "Nobody ever got fired for buying Cisco." The idea was that choosing the market leader was the safest decision because it was easy to justify if things went wrong. In today's email cybersecurity, however, that mindset can be dangerous.

For years, enterprise IT buyers have lived by a simple belief: "Nobody ever got fired for buying IBM." As Cisco grew into a dominant networking and email security vendor in the early 2000s, the saying evolved into "Nobody ever got fired for buying Cisco." The bigger name justified the bigger price. And if things went wrong, they would likely go wrong for plenty of other well-known organizations too.

In email cybersecurity, however, that mindset, the insecurity behind choosing security, can be dangerous -  a recognizable name does not automatically mean better protection, better support, or stronger defenses against modern threats.

And how well-known your security vendor is may actually work against you: The phishing cybercriminals usually focus on exploiting the solutions with the largest footprint - just look at Microsoft Exchange as the prize for breaching the system that holds a large percentage of the world's corporate mailboxes makes it the number 1 target for attackers.

Critics of the old adage have long argued that popularity and performance are not always the same thing. For today's security leaders, the real question is not:

"Will I get criticized for choosing this vendor?"

It is:

"Can I defend this decision after a successful phishing attack?"

When a breach occurs, boards and executives care about outcomes, not logos. They want to know whether the solution was properly evaluated, thoroughly tested, correctly configured, and genuinely capable of protecting the business. If a different solution could demonstrably have provided better protection, the reputation of the chosen vendor becomes largely irrelevant.

In modern email security, the best choice is not necessarily the safest-looking one. Organizations should focus on detection accuracy, response automation, user protection, operational efficiency, and integration with their broader security ecosystem.

And if, after careful evaluation, the best solution happens to be a market leader, that's fine. If it isn't, that's fine too. What matters is having the analysis, testing, and decision-making process to support the choice.

After all, nobody should be fired for choosing a vendor. They should only be questioned for choosing one without knowing why.

 

Visit Mailspike.io  And learn how to protect your email infrastructure

Recent Posts

Subscribe to Email Updates
Get instant notifications of new posts

Posts by Topic