About
Many organisations invest in security from the top down. I believe you should start at the bottom.
The security industry has an incentive problem. Salespeople are rewarded for selling the most sophisticated and most expensive solutions: detection platforms, threat intelligence, managed response. Those sit at the top of the pyramid.
At the bottom, where everything else rests, are the unglamorous parts. Knowing what is on your network. Understanding which of it is actually exposed. Having a process that closes findings rather than collecting them. Without that foundation, every layer above is built on assumptions.
I spent 17 years in senior engineering roles at two of Switzerland’s largest managed security providers, and I saw the same pattern repeatedly. Heavy investment at the top of the pyramid while the base stayed incomplete. Not through carelessness. The basics are simply not where the money is.
Most organisations that own a vulnerability management platform are not getting a programme out of it. The tool produces findings and very little happens next, because nobody defined who fixes what by when, or what to do with the exceptions.
Everyone who could help with that has a reason to steer the answer. The vendor’s own services team is measured on their product working. A reseller earns margin on the licence. A managed service provider would rather run it for you indefinitely than teach you to run it yourself.
BrightPath sells none of it. No licences, no margins, no rebates, no vendor certifications that would create a preference. You can test that in one question: ask what we earn if you choose a different platform. The answer is nothing, and it is the same answer for every product on the market.
What is left is the work itself. Designing the process, defining measures that describe the programme rather than flatter it, and handing it over so your own engineers run it. That is a smaller business than a managed service. It is also the one worth doing.
Founder
Robert Randall
30 years in IT infrastructure, the last 17 focused on cybersecurity as engineer, consultant and architect at three of Switzerland’s established cybersecurity firms, with specialist work in log management and SIEM platforms.
Diplom Ingenieur FH in Computer Science, specialisation Network Security. Former lecturer in IT security at FFHS. German and English at native level, with professional French.
Company
BrightPath GmbH
Legal Name
BrightPath GmbH
UID
CHE-132.241.092
Location
Windisch, Aargau, Switzerland
Founded
March 2026
Specialisation
Vulnerability management advisory
Commercial model
Engagement fees only, no resale
Languages
Deutsch · English · Français
Industry (NOGA)
62.09 IT services
Let's talk about your environment
One to two hours with your technical people, technical and with no sales portion. If it turns out you can do this yourselves, that is a result too.
Arrange a conversation