Left Arrow Icon
All articles

Security Leaders Trade Bloated Legacy Platforms For Tools Built For Today's Threats

The Security Digest - News Team
Published
October 8, 2026

Brad Gorka, CISO at Veritiv, on why security leaders are moving their budgets to platforms built for current threats as AI native challengers gain ground.

Credit: The Security Digest

Make The Security Digest one of your go-to sources on Google

Google Icon
Add The Security Digest on Google
Quote Icon
You have to walk away from these old legacy tools that served you well five, six, or seven years ago, but aren't really meant for today's threats.

Brad Gorka

CISO

Brad Gorka

CISO
Veritiv

The legacy security platforms that led the market five years ago now charge their customers twice, once for the original product and once for the AI features added later. Many security leaders are no longer willing to pay for both. Switching vendors has become cheap enough that newer companies built for current threats are taking accounts from the slower incumbents.

Brad Gorka is CISO at Veritiv, a leading, global full-service provider of specialty packaging solutions. In addition to packaging, Veritiv provides JanSan, hygiene, print, and publishing products and services. Gorka has spent more than two decades in IT and security and has worked at organizations ranging from a few hundred employees to more than 300,000. Before Veritiv, he spent seven years as CISO at CommScope, where he helped build the security function and team from the ground up. He has bought security tools across that entire range, and he has watched the vendors selling them fall behind what their customers need.

"You have to walk away from these old legacy tools that served you well five, six, or seven years ago, but aren't really meant for today's threats," Gorka says. Those tools worked well when they were installed. Attacks have gotten much faster since, and much of the activity security teams need to see has moved somewhere the older tools can't reach. He points to a network monitoring platform that a colleague recently raised with him, one that did an excellent job a decade ago. "Things have transitioned to more about identity telemetry than network telemetry, and you've got all this stuff out in clouds where you're not even able to monitor the network," he says.

Bolted on

Gorka isn't arguing for throwing out everything the older platforms were built to catch. "Those threats that those tools dealt with have not entirely gone away, so you can't abandon that. But you need to evolve into the newer tools that can detect and mitigate modern threats," he says. In his experience, younger companies get there first. They build for current attacks, then work backward to cover the older ones, a pattern he has seen play out in email security in particular.

Legacy vendors tend to move in the other direction, holding on to the monolithic platform they already have and adding AI on top of it. "It usually looks and feels poorly integrated, but then you get the quote for it and it's twice as much as one of these younger companies is asking for," Gorka says. "You've already put together this Frankenstein's monster that's clunky, and you want to charge me double for it."

What he'd rather see from the large vendors is a straight answer about where their investment is going. They have the research budget to find a promising startup, buy it, and stand behind it, and Gorka thinks they should say so plainly, then offer customers a licensing path off the old product. "We bought it. We stuck our logo on it. We're putting R&D dollars into it, and we think it's great," he says, describing the pitch he'd like to hear. Holding on to the old product line carries a bigger risk for the vendor. "Do you want to lose those SKUs and get them onto some new SKUs, or do you want to lose the entire account? Because that's what's happening right now."

Fixing at speed

The same AI that helps a security team is now in the hands of the people attacking it. "The bad guys have access to these tools too, and they've raised the bar on the quality and quantity of their attacks," Gorka says. On the team's side, AI works through more security data than people can review by hand, sorting it quickly and flagging what matters.

It's also taking on more of the analytical work. Gorka has followed AI in third-party risk management closely over the past few years and has watched the output improve. "A couple of years ago it was a little bit sloppy, and I had to fill in a lot of gaps. Now it's performing work that's the equivalent of a human with 150 years of experience, and there is no human with 150 years of experience," he says.

An attack that once took days can now run in a fraction of that time, and the window to catch and fix a flaw shrinks with it. Faster discovery doesn't make every finding urgent, though. "It doesn't matter if it found 150 low vulnerabilities that it can string together into a critical. If any point of that isn't achievable from your attack launch point, then it alters how important it is to really get it fixed," Gorka says.

For the flaws that do matter, Gorka wants his team to close them at machine speed, before the affected code reaches production. "Hopefully we can get to a point where we're remediating the code as fast as something like Mythos can identify the flaws. That's where we're going to have to get to," he says. A platform slower than that leaves his team exposed while the attack runs ahead of it.

Staying mobile

Gorka keeps contracts short, taking nothing longer than two years and some at one year, because the market resets every few months and a long commitment leaves no room to react. "I'm very strict about the duration of a contract. Know what your exit strategy is, try to set things up in such a way to drive down the cost and complexity of switching, and be willing to walk away," he adds.

He also pushes vendors to commit in writing that features promised at signing stay available and that any price increase carries a ceiling. Not all of them will, and knowing which is part of how he decides. One large vendor told him an AI feature was included in the platform, and he asked for that to go into the software agreement. The vendor refused, though Gorka's team did secure a cap on increases from one contract to the next. "They knew where I was going, and they weren't buying it. But I think we have to try and do as much of that as we can, otherwise the pricing can go wild," he says.

The leverage has shifted toward buyers. "With all the API capabilities we have now and everything cloud-based, the switching costs have gone substantially down on this stuff. So I think the market will govern itself to a certain degree," Gorka says. Smaller vendors also move faster on customer requests. One startup told him it could take an idea from a customer and have it in production days later. "Go tell that to a big company such as Microsoft or Cisco and they'll laugh at you," he says. "Every time you go ask them for something, they knock it out of the park and deliver in short order. You're going to stick with them."

Gorka now reevaluates the market roughly every three months and keeps his options current, since AI has lowered the barrier for new companies to reach the market. "It's like, 'Hey, you're not the only game in town. I've got people beating my door down for this stuff, and they've got better prices,'" he says. "You've got to be willing to walk and look at other options that are out there."

Faster on both sides

Gorka has watched this pattern repeat across his career. A new capability arrives and gives one side an advantage, then the other side catches up and the two even out. He expects AI to move the same way. "It's going to be the same battle we've been doing for the past 10 or 20 years," he says.

The cycle runs faster now, and cost decides how fast each side can move. Running these models costs money in compute, and Gorka expects attackers to keep chasing the biggest payoff for the fewest tokens. "The more their costs go up and the more their time and effort goes up, they consider those things too, just like a regular business does," he says.

Defenders are watching the same expense. He sees them matching the model to the task, running a cheaper, older one where it does the job and saving the newest for the work that needs it. "I'm starting to see organizations ask, 'Do you need the platinum-level AI to do this task?' And it's, 'No, we could use the AI from a year ago that costs very little now,'" Gorka says. Used that way, AI stays affordable even as teams lean on it more. "When it comes to adversaries, it's about economics and it's about cost. The speeds are going to dramatically shorten, and they're going to have to shorten on both sides," Gorka says.