# The Dangers of Picking the Wrong Vendor Page: https://stenobird.com/podcast/defense-in-depth-427616/the-dangers-of-picking-the-wrong-vendor Text version: https://stenobird.com/podcast/defense-in-depth-427616/the-dangers-of-picking-the-wrong-vendor.md Podcast: [Defense in Depth](https://stenobird.com/podcast/defense-in-depth-427616) Published: 2026-05-21T10:00:00+00:00 Episode link: https://defenseindepth.libsyn.com/the-dangers-of-picking-the-wrong-vendor Audio file: https://traffic.libsyn.com/secure/defenseindepth/Defense_in_Depth_05-21-26.mp3?dest-id=1020683 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/defense-in-depth-427616/episodes/the-dangers-of-picking-the-wrong-vendor Duration seconds: 1606 ## Resource All links and images can be found on CISO Series . Check out this post for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark , the producer of CISO Series , and Steve Zalewski . Joining us is our guest, Paul Guerra. In this episode: Read the contract How vendors win before the evaluation ends The fallout The real cost A huge thanks to our sponsor, Native Security Native makes secure-by-design inherent to how the cloud operates. It's the control plane for built-in cloud security, unifying and governing native controls, so security intent is defined once and applied consistently across providers. Learn more at native.security . ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/defense-in-depth-427616/episodes/the-dangers-of-picking-the-wrong-vendor/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/defense-in-depth-427616/the-dangers-of-picking-the-wrong-vendor.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.