What questions should we ask any endpoint security vendor?
Short answer: Ask where decisions are made, what happens without connectivity, what the tool depends on to function, and whether it prevents or merely reports. The answers separate architecture from marketing quickly.
Questions worth asking
- Where is the protective decision made — on the endpoint or in your cloud? A network round trip in the critical path cannot beat a millisecond-scale attack.
- What happens when the machine is offline or air-gapped? If protection degrades, it wasn't local.
- Does your agent depend on Windows system libraries to function? If yes, an attacker who compromises those libraries in memory can blind or silence it.
- Do you require signatures or threat intelligence feeds? If yes, protection trails the attacker by definition.
- Does a response require a human? If yes, response time is bounded by human biology.
- Do you store our encryption keys or upload sensitive data for analysis? Centralized storage creates a target and a compelled-disclosure risk.
- What is your false positive rate, and what does a response actually do? Full-system lockdown as the only containment option is expensive in a hospital or a plant.
Why these questions matter
Most endpoint tools look similar in a datasheet. These questions surface the architectural decisions that determine whether a tool can act in time — or can only explain, afterward, what happened.