I read another Forrester report this week. It was about the NAC market - a topic I care about deeply and work with daily. The analyst made several declarative statements about where the market is heading, which vendors are positioned to win, and what enterprises should be prioritizing in their evaluations. Some of these statements aligned with my experience. Some did not. All of them will influence purchasing decisions at hundreds of organizations.

And I thought to myself: I so want that job.

The Analyst Influence Machine

Consider for a moment how enterprise security purchasing actually works in most large organizations. A CISO identifies a need. A team evaluates options. They produce a shortlist. And at some point in that process - often very early - someone pulls up the Forrester Wave or the Gartner Magic Quadrant for the relevant product category and uses it to validate, refine, or completely reshape the shortlist.

The analyst firms understand this dynamic perfectly, which is why they charge what they charge. A Forrester subscription runs in the tens of thousands of dollars per year. Individual reports cost hundreds. Analyst inquiry time - the ability to call a Forrester analyst and ask questions about your specific situation - is the premium tier. And vendors pay even more for the privilege of being evaluated, briefing analysts, and participating in the waves and quadrants that shape their market positioning.

The result is a ecosystem where a relatively small number of analysts exert enormous influence over a multi-billion dollar market. When Forrester moves a vendor from "Strong Performer" to "Leader" in a Wave report, that vendor's sales team sends the report to every prospect in their pipeline within the hour. When a vendor gets downgraded, their competitive intelligence team goes into crisis mode.

What Analysts Get Right

Credit where it is due: the best analyst reports provide genuine value. They synthesize information from vendor briefings, customer reference calls, product demos, and market data into a structured evaluation that would take an individual practitioner months to assemble independently. When I am evaluating a product category I do not work with daily, analyst reports give me a useful starting framework.

The methodology behind the Forrester Wave is also reasonably transparent. They publish the criteria, the weightings, and the scores. You can disagree with the weightings - and I often do - but at least you can see how they arrived at their conclusions and adjust accordingly.

What They Get Wrong

The limitations are significant. Analyst evaluations are necessarily broad. They evaluate products against a generalized set of criteria that may not reflect the specific requirements of your environment. A product that scores well in a Wave because it has strong endpoint posture assessment might be a poor fit for an organization whose primary concern is guest access management.

There is also a structural bias toward large vendors. Analyst firms have limited time and attention. They tend to focus on the vendors with the largest market share and the most active analyst relations programs. Smaller vendors with genuinely innovative products can be overlooked or underevaluated simply because they lack the resources to engage with the analyst process effectively.

And then there is the question of recency. A Wave report represents a snapshot of the market at a particular moment. Products change. Companies get acquired. New competitors emerge. But the report lives on, influencing purchasing decisions for months or even years after the evaluation was conducted.

The Fantasy

So here is my fantasy version of being a Forrester analyst. I would spend my days talking to practitioners - not just CISOs giving reference calls, but the engineers and architects who actually deploy and operate these products. I would weight operational complexity and real-world performance more heavily than feature checklists. I would publish more frequent, shorter evaluations rather than comprehensive waves that take months to produce and are partially stale by the time they publish.

I would also be more willing to say "this category is overhyped and you probably do not need it yet" - something that the current analyst business model, which depends in part on vendor participation fees, makes structurally difficult to do.

Of course, the reality of analyst life involves considerably more vendor briefings, travel, and deadline pressure than my fantasy accounts for. And the political dynamics of maintaining relationships with vendors while simultaneously evaluating them objectively must be exhausting.

Still. The idea of being the person whose opinion shapes how the industry allocates billions of dollars in security spending has a certain appeal. Especially on weeks when I am buried in configuration guides and change control tickets.

Maybe next career.

SA
SecForAll Editorial
Security Analysis & Commentary
SecForAll covers enterprise security trends, policy, and technology for security professionals and decision-makers. Our analysis draws on industry research, vendor briefings, and hands-on evaluation of security products and standards.