Buying cybersecurity

Why Generic Freelance Platforms Fall Short for Cybersecurity

Hiring independent cybersecurity expertise can be an entirely sensible decision, and for most smaller organisations it is the only realistic one. The difficulty is not the freelance model. It is that choosing security expertise from a profile, an hourly rate, a star rating and an availability indicator leaves out almost everything that determines whether the engagement will be useful.

General freelance marketplaces do a great deal well. They have made it straightforward to find and engage specialists for a very wide range of work. Cybersecurity simply presents an awkward buying problem: the provider may be given access to sensitive systems and information, and the buyer often lacks the technical background to judge the quality or the relevance of the work before committing to it. That combination is unusual, and generic marketplace mechanics are not designed around it.

The work may involve access you would not give an ordinary freelance supplier

Not every security engagement requires privileged access. Plenty of valuable work — advisory conversations, policy drafting, help with a customer questionnaire, a review of documented architecture — involves nothing more sensitive than a shared document. But depending on the engagement, a cybersecurity professional may need visibility into or access to:

  • Production systems and the environments customers actually depend on
  • Cloud accounts, configuration and administrative consoles
  • Source code and build pipelines
  • Security tooling, logs and monitoring data
  • Identity systems and privileged accounts
  • Architecture documentation and internal design decisions
  • Confidential customer information held within the systems being examined
  • Information about a live or recent incident

The point is not that this is dangerous. It is that the trust implications are materially different from commissioning a piece of design work or a set of marketing copy. When an engagement reaches into the systems a business runs on, questions such as who this person actually is, who is accountable for the work, and what happens to information gathered along the way stop being administrative details and become part of the buying decision itself.

A five-star rating can be true and still tell you very little

Ratings are not worthless. A long record of satisfied clients genuinely tells you something: that this person turns up, communicates, delivers on time and is straightforward to work with. Those qualities matter, and their absence is a reliable warning. The trouble is that in security work, client satisfaction and technical quality are only loosely coupled, and the gap between them is invisible from the outside.

A rating rarely tells you:

  • What technical work was actually performed
  • How complex the engagement was
  • Whether the reviewer was in a position to judge technical quality
  • Whether the provider's experience matches your environment
  • Whether the work held up months later
  • Whether the engagement resembled the problem you have now

There is an uncomfortable asymmetry underneath this. A buyer who could accurately assess the technical quality of a security engagement probably would not have needed to buy it. Most reviews of security work are therefore written by people rating the experience rather than the substance — which is a perfectly reasonable thing for them to do, and exactly why the rating needs context rather than dismissal. A five-star average across twelve logo projects and one security review is a different signal from a five-star average across forty comparable engagements, and the number itself does not distinguish between them.

"Cybersecurity expert" is far too broad a category

Cybersecurity is not a skill. It is a field containing a number of largely separate professions, and someone excellent in one may have limited working experience of another. A category label flattens that, and a buyer who does not yet know which discipline their problem belongs to has no way to see the difference.

Incident response

Working through a live or recent compromise: establishing what happened, coordinating the response and helping an organisation get back to a stable position. It is time-critical and organisationally demanding in a way most security work is not.

Penetration testing

A scoped, time-bounded assessment in which a tester attempts to find and demonstrate weaknesses in a defined target. Useful when you know what you want examined and why.

Application security

Concerned with how software is designed, built and deployed: authentication, data handling, dependencies, secrets and the decisions made in the code itself.

Cloud security

How cloud accounts, services and permissions are configured, and how that configuration has drifted since the day it was set up.

Identity and access

Accounts, authentication, permissions and the joiners-movers-leavers reality of who can reach what. Frequently where the practical exposure sits, and rarely the thing people ask for by name.

Security architecture

How the pieces fit together, and whether the overall design supports the security properties the organisation believes it has.

Security leadership

Governance, priorities, risk decisions and answering to customers and boards. A fractional or virtual CISO does this part-time for organisations that need judgement more often than they need operations.

Some practitioners work credibly across several of these. Many specialise deliberately, because depth is what makes them valuable. The problem for the buyer is that a single broad category tends to present all of them as interchangeable options in one list, sorted by whatever the platform sorts by.

Identity and capability are different questions

These get conflated constantly, and they should not be. Knowing that someone is genuinely the person they claim to be is a question about identity. Knowing that they can do the work well is a question about capability. Each needs its own evidence.

Identity verification matters more in security than in most fields, because of the access described above. It also proves nothing whatsoever about technical skill: a verified identity is a verified identity, no more. Equally, a strong CV, a well-known certification or a compelling portfolio says something about capability while establishing nothing about who is on the other end of the engagement. A buyer taking on meaningful access generally needs some signal on both, and should be wary of any single indicator presented as though it settles the matter.

Credentials help, but context matters

Certifications and professional credentials are useful evidence. Some require substantial practical assessment and are well regarded within a particular discipline; others demonstrate familiarity with a body of knowledge. Both can be relevant, and dismissing them as meaningless is its own form of posturing.

What they cannot do is settle the question by themselves. Excellent practitioners sometimes hold very few formal certifications, particularly those who came into the field through engineering or research rather than through a structured career path. Others hold strong credentials without having done work resembling the engagement in front of you. The useful question is not how many a provider has, but what a specific credential demonstrates in the context of this specific piece of work — and whether that is the thing you actually need demonstrated.

Price is easy to compare. Security work often is not.

Price is the one attribute of a security engagement that is unambiguous, instantly comparable and requires no domain knowledge to interpret. It is therefore the attribute buyers lean on hardest, which is a shame, because it is among the least informative.

Cheap does not mean bad, and expensive certainly does not mean good. The real issue is comparability. Two proposals that look broadly similar may differ in scope, depth, methodology, the seniority of who actually performs the work, relevant experience, what is delivered at the end, and what each has assumed about the environment. A quote that appears to be half the price of another is often describing a different piece of work, and the difference is usually visible only to someone who already understands the discipline. Placing two such offers side by side under a price column implies a comparison that has not really been made.

Sometimes the buyer does not yet know what they are buying

This is the part generic buying flows handle least well, because they begin from the assumption that the buyer knows what they want and needs help finding someone to do it. In cybersecurity the initial request is frequently a reasonable guess at a problem that has not yet been diagnosed.

A founder may ask for a penetration test when the more useful engagement would be application security advice on how the product is built — or the test may be exactly right, because a customer has asked for one specifically. A company may ask for "compliance help" when the immediate issue is a customer security review with a deadline attached, though it may also be the start of a genuine certification programme. Someone may search for a CISO when they need a short piece of specialist advice, or may genuinely need part-time security leadership. A company planning a vulnerability scan may find that what was actually requested of it was independent testing of a particular kind.

None of these resolves in a single predictable direction, and it would be dishonest to suggest otherwise. The pattern is simply that cybersecurity buying often starts with diagnosis rather than procurement. A marketplace that treats the buyer's opening request as a fixed specification will match them efficiently to the thing they asked for, which is only helpful if the request was right.

Scope is part of the buying decision

Security services with similar names can involve very different work, and the naming is not consistent across the industry. A few examples of pairs that are routinely conflated:

Vulnerability assessment and penetration testing

Both examine an environment for weaknesses, but they differ in method, depth, duration and what the output is for. Buying one while expecting the other is a recurring source of disappointment, and the words are used loosely across the industry.

Questionnaire support and security leadership

Helping a company answer a customer's security questions is a bounded piece of work. Owning a company's security direction is a continuing one. Both may be described as consulting.

Cloud review and incident response

One is a considered examination of configuration and design. The other is urgent, coordinated and shaped by circumstances outside anyone's control. They demand different temperaments as well as different skills.

Technical testing and strategic advice

A test tells you what was found in a defined target at a point in time. Advice tells you what to do about the position you are in. Companies sometimes buy the first when the question they were asked required the second.

A buyer does not need to master these distinctions. They do need to be able to see what is actually being proposed before comparing it against something else, which means the proposal has to be visible at the point of comparison rather than emerging after the engagement has begun.

Trust signals need context

If a rating and a rate are not enough, the reasonable question is what would help. There is no single signal, and anyone claiming one exists is selling something. A more useful set is cumulative:

  • Verified identity, particularly where sensitive access is involved
  • Experience that relates to the specific discipline and environment in question
  • Validated credentials where they exist, read for what they demonstrate rather than counted
  • Recommendations from people who were technically able to judge the work
  • Evidence of comparable specialist engagements
  • A clearly written scope agreed before work starts
  • Professional accountability: a named party responsible for the work and its quality

No item on that list proves competence, and it is worth being blunt about that. Together they give a buyer something to reason from, which is a more modest and more honest claim than the alternative. The value is in having several independent signals that can be weighed against the particular engagement, rather than one number standing in for all of them.

The marketplace itself shapes the buying decision

Platform design is not neutral. Whatever a marketplace displays prominently becomes what buyers compare; whatever it makes easy to filter on becomes the basis of selection. That is true of every marketplace, and it is a reasonable thing for a platform to optimise. The question is what it has been optimised for.

The structure influences which providers become visible, whether specialist disciplines stay distinct or collapse into a single category, how much trust information is surfaced and in what form, and whether the first conversation is about price or about the problem. A platform serving everything from logo design to administrative support has to generalise, and generalising means organising around the attributes that are common to all work rather than the ones specific to any of it. That is not a flaw. It is the necessary consequence of breadth.

Cybersecurity buying may simply benefit from an environment built around the context of security work: one where the disciplines stay separate, where identity and relevant experience are treated as first-order information, and where the buyer's problem is examined before a provider is compared on rate.

Does this mean you should never hire a cybersecurity freelancer?

No. Not remotely, and the opposite argument is the one worth making. Some of the strongest practitioners in this field work independently, by choice, precisely because it lets them stay deep in a discipline rather than being pulled into management. For most organisations, independent expertise is the only practical way to access senior specialist skill without creating a permanent role that would not have enough work to fill it.

The criticism in this article is aimed at the buying process, not at the people. Nothing about independent work makes security expertise less credible. What makes selection hard is the information available to the buyer at the moment they choose — and that is a property of the environment they are choosing in, not of the professionals within it.

What should you know before choosing someone?

Not a procurement process. Just enough to make the decision on something other than price and a number out of five. Before committing, you should be able to state:

  • Who you are engaging, and who is accountable for the work
  • What relevant experience they have in this particular discipline
  • What work is actually being proposed, in writing
  • Why that type of work fits the problem you have
  • What access will be required, and when
  • What evidence supports their claimed expertise

If several of those are unanswerable from what is in front of you, that is not necessarily a reason to walk away. It is a reason to have a conversation before agreeing a price. In security work the conversation usually costs less than the wrong engagement.

Find cybersecurity expertise with more context

Heelr is a marketplace for cybersecurity services. You can describe what you need, see providers by discipline rather than as one broad category, and agree scope and price before any work begins. The work itself is carried out by independent professionals and providers.

Common questions

Can I hire a cybersecurity expert through a freelance marketplace?

Yes. Independent cybersecurity professionals work through a wide range of channels, including general freelance marketplaces, referrals, consultancies and specialist platforms. The question is less whether it is possible and more whether the information available to you in that channel is enough to judge which provider suits the problem you actually have.

Is it safe to hire a penetration tester online?

It can be, and a great deal of testing work is arranged remotely. What matters is that you know who you are engaging, that the scope of the test is written down and agreed, that you understand what access is required and why, and that the provider's experience relates to the kind of environment being tested. Those are the same considerations that apply when engaging a tester through any other route.

What should I check before hiring a cybersecurity consultant?

At minimum: who they are, what relevant experience they have, what work is actually being proposed, why that type of work fits your problem, what access it will require, and what evidence supports their claimed expertise. If you cannot answer those from the information in front of you, the next step is a conversation rather than a purchase.

Do cybersecurity certifications prove someone is qualified?

No. Certifications can be useful evidence that someone has covered a defined body of knowledge or passed a practical assessment, and some are well regarded in specific disciplines. They do not on their own establish that a person has the particular experience your engagement needs, and plenty of capable practitioners hold few formal certifications. They are one input, read in context, rather than a verdict.

Is a freelance cybersecurity consultant suitable for a small company?

Often, yes. Smaller companies rarely have enough continuous security work to justify permanent hires, and independent specialists are a practical way to access expertise for a defined piece of work. The difficulty tends to be selection rather than suitability: knowing which discipline the problem calls for, and having enough context to compare providers sensibly.

Why does identity verification matter when hiring cybersecurity expertise?

Because some security engagements involve access to systems, data or credentials that a company would not extend to an ordinary supplier. Knowing that a provider is genuinely who they claim to be is a reasonable prerequisite for that kind of access. It is a separate question from technical capability, and neither answers the other.

What is the difference between a cybersecurity marketplace and a generic freelance marketplace?

Mainly what the platform is designed to surface. A general marketplace has to serve a very wide range of work, so it tends to organise around broad categories, profiles, rates and ratings. A marketplace built around one field can keep specialist disciplines distinct, ask for context relevant to that field, and structure the buying conversation around the problem rather than the price. Neither design guarantees a good outcome; they simply optimise for different things.