Tag: procurement

  • Huawei Named a Gartner Storage Leader: What It Signals

    Huawei Named a Gartner Storage Leader: What It Signals

    Gartner has published its Magic Quadrant for Enterprise Storage Platforms, 2026, and Huawei says it has been placed in the Leaders quadrant — the only vendor outside North America to land there, according to the company’s announcement issued from Shenzhen, China, on 28 August 2026.

    The announcement centers on Huawei OceanStor Data Storage, which the company describes as a high-efficiency, unified AI data platform offering capacity density, energy efficiency and forward-looking data resilience. Huawei says its data storage business operates in more than 150 countries and regions, serving finance, telecommunications, manufacturing, healthcare, government and utilities customers across Latin America, Europe, the Middle East, Africa and Asia-Pacific.

    Executive Summary

    A Magic Quadrant is Gartner’s two-axis vendor map: the horizontal axis rates “completeness of vision” (strategy, roadmap, understanding of where the market is going) and the vertical rates “ability to execute” (products, support, viability, delivery). Vendors scoring high on both land in the Leaders quadrant. It is a widely used procurement shortcut, not a benchmark result — no throughput or latency numbers underpin the placement.

    That is precisely why this particular placement is interesting. Enterprise storage spent two decades being bought on capacity, availability and cost per terabyte. The attributes Huawei chose to foreground — a unified platform that serves AI workloads, capacity density and energy efficiency — are the criteria that matter when storage sits behind expensive accelerators in a power-constrained facility. The pitch is a tell about where the category’s center of gravity has moved.

    The second signal is structural. If the Leaders quadrant contains exactly one vendor headquartered outside North America, then for a large share of Western enterprise buyers the practical shortlist and the published shortlist are not the same document. Huawei faces procurement restrictions and security reviews in the United States and several allied markets, and the regional footprint the company itself lists does not include North America. The report describes a global market; most buyers shop in a regional subset of it.

    Storage Is Being Re-Specified Around AI Pipelines

    The economics of an AI cluster are brutally simple: the accelerators are the expensive part, and every second they spend waiting on data is money burned. That inverts the traditional storage conversation. A training run reads enormous volumes of small files at random; a checkpoint writes a very large object very fast; inference and retrieval workloads want low, predictable latency against vector and object stores. Historically those were three different systems from three different budgets.

    Huawei’s framing — “unified AI data platform” — is the industry’s current answer to that fragmentation: one platform presenting file, object and block access over shared media, so data does not have to be copied between silos at each pipeline stage. Every serious storage vendor is making some version of this argument, which is itself the point. When the leading players converge on the same message, the category has re-specified. Buyers who wrote their last storage RFP around capacity tiers and snapshot policy will find that document does not ask the questions that now decide the outcome.

    The other two attributes named — capacity density and energy efficiency — are facility economics wearing a product label. Density means terabytes per rack unit, which matters when a data hall is out of floor space; efficiency means watts per terabyte, which matters when the site is out of power long before it is out of space. In markets where grid connections are the binding constraint on new capacity, storage that consumes fewer watts is not a sustainability line item, it is the difference between deploying and waiting.

    Reading the “Only Non-North American Leader” Claim Carefully

    The claim is checkable and, taken at face value, striking: it implies the rest of the Leaders quadrant is North American. Enterprise storage has long had significant Japanese and European engineering, so a quadrant that concentrates that way is worth noticing. But two caveats belong in any fair reading. First, “non-North American” is a headquarters test, and several storage businesses run global R&D under a US-domiciled entity owned elsewhere — the label may sort vendors differently than an engineering-origin test would. Second, Magic Quadrant inclusion criteria (minimum revenue, product scope, geographic coverage) shape the field before any vendor is scored; who is absent is often a function of the inclusion rules, not of the evaluation.

    It is also worth being precise about what a Leader placement is and is not. It is an analyst judgment, informed by vendor briefings, customer references and Gartner’s own inquiry volume, about strategy and delivery capability. It is not a bake-off. Gartner publishes Strengths and Cautions for every vendor it names, and the Cautions are frequently the most useful page in the document for a buyer. The announcement does not summarize Huawei’s Cautions — which is normal for vendor press releases across the industry, and equally a reason to read the source report rather than the release.

    None of that makes the placement hollow. Landing in Leaders requires demonstrating both a coherent product direction and evidence of delivering at scale, and doing so as the sole vendor from outside the incumbent geography is a genuine competitive result. The honest reading is that the announcement substantiates the placement and the product positioning, and substantiates nothing about comparative performance, price or suitability for any specific workload — because it does not claim to.

    One Report, Two Buying Realities

    The most consequential fact in this story is not in the quadrant at all; it is in the regional list Huawei provides. The company cites customers across Latin America, Europe, the Middle East, Africa and Asia-Pacific. North America is not named. That reflects a well-documented reality: Huawei is subject to procurement restrictions and heightened security review in the United States and in a number of allied jurisdictions, which in practice removes it from many Western enterprise and public-sector shortlists regardless of how it scores.

    The effect is a market that is bifurcated rather than global. A bank in Riyadh, a telecom operator in São Paulo and a manufacturer in Kuala Lumpur can evaluate the full Leaders quadrant. A US federal agency, a defense contractor or an operator carrying regulated critical-infrastructure obligations in several allied markets cannot. Both are reading the same report; only one of them can act on all of it. Buyers in the restricted set should treat the quadrant as market intelligence — a read on where the technology frontier is — rather than as a shortlist.

    Who wins and loses from that split is not one-directional. Western incumbents benefit from reduced competitive pressure in protected markets, which historically translates into slower price erosion for customers. Huawei benefits from a large addressable market in regions where no such restrictions apply, and from being the credible non-US option for buyers who want supply-chain diversity for their own sovereignty reasons. The buyers who pay for the arrangement are the ones facing a shortened shortlist, and the buyers who benefit are the ones with a longer one. That is a description of the market structure, not an argument about the policies that created it — those rest on national-security judgments that sit well outside a storage procurement decision.

    What a Buyer Should Actually Do With This

    Analyst placements are best used to set the shortlist, never to close it. The practical translation of an AI-era storage evaluation is a proof of concept that mirrors the real pipeline: sustained small-file read throughput at training-scale concurrency, checkpoint write bandwidth at the size the models actually produce, metadata operations per second, and — critically — measured rack-level watts and rack units at the target capacity, since those are the numbers the facility team will hold you to.

    Two questions belong alongside the technical ones. First, total cost across the refresh cycle, including the effective cost of data reduction, support renewals and any capacity licensing — density claims and efficiency claims both compress or expand dramatically depending on how dedupe and compression ratios are counted. Second, supply and support continuity across the asset’s full life: not only whether a vendor can be bought today, but whether it can be supported, expanded and patched in every jurisdiction the organization operates in for the next five to seven years. For any vendor exposed to export-control or procurement-policy shifts in either direction, that risk assessment is part of the engineering decision, not a separate legal footnote.

    For investors, the signal is narrower than it looks. A Leaders placement is directional evidence about competitive standing, not a revenue disclosure. The announcement contains no market-share figure, no storage-segment revenue, no growth rate and no customer count — only a footprint claim of more than 150 countries and regions. Anyone modeling the enterprise storage market should treat the placement as one input among several and go to disclosed financials for the rest.

    Background

    Enterprise storage platforms are the systems that hold an organization’s primary data — the databases, virtual machine images, file shares and object stores that applications read and write continuously. The market has consolidated over the past decade around a handful of large vendors selling all-flash arrays and software-defined systems, with buying decisions historically driven by capacity, availability, data services and cost per terabyte. Gartner has tracked the category through successive Magic Quadrants, renaming and rescoping the research as the technology shifted from disk arrays to flash and from single-protocol appliances to unified platforms.

    Huawei entered enterprise storage as an extension of its telecommunications equipment business and built the OceanStor line into a global product family, strongest in Asia-Pacific, the Middle East, Africa, Latin America and parts of Europe. Its position in Western markets is shaped by a separate history: since the late 2010s the company has faced US export controls, procurement bans and security reviews in several allied jurisdictions, primarily concerning network equipment, with knock-on effects across its enterprise portfolio. The result is a vendor that competes at the top of the global market on the analyst scorecards while being effectively unavailable to a significant segment of Western buyers.

    Source: Huawei, Gartner®’ın 2026 Kurumsal Depolama Platformları Magic Quadrant™ raporunda lider olarak gösterildi — Huawei’s PR Newswire announcement, issued from Shenzhen on 28 August 2026 and distributed in multiple languages, stating its placement in the Leaders quadrant of Gartner’s 2026 enterprise storage Magic Quadrant.

  • MDR Buyer’s Remorse: What CISOs Must Fix Before Signing

    MDR Buyer’s Remorse: What CISOs Must Fix Before Signing

    Info-Tech Research Group, a global IT research and advisory firm, published a blueprint titled Streamline Security Detection & Response Outsourcing on August 27, 2026, from Arlington, Virginia. The firm argues that rising threat volume, expanding attack surfaces and thin security operations capacity are pushing more organizations toward managed detection and response (MDR) — an outsourced service where a third party watches an organization’s systems around the clock and reacts to suspected attacks — but that inconsistent vendor terminology makes providers hard to compare.

    The blueprint sets out a four-phase procurement methodology: Prepare, Set Outcomes, Procure, and Implement & Govern. Senior research analyst Seva Ioussoufovitch is quoted urging leaders not to “rush into a contract you’ll regret.” The full blueprint is available to Info-Tech clients and to media through the firm’s Media Insiders program.

    Executive Summary

    The announcement is advisory content rather than a product launch, but the problem it names is real and expensive. MDR has become a default answer for organizations that cannot staff a 24/7 security operations centre. Info-Tech’s position is that the market’s naming conventions — MDR, MSSP, SOCaaS, XDR-as-a-service and a long tail of branded packages — obscure genuine capability differences, so buyers end up comparing marketing categories instead of deliverables.

    Why it matters: detection and response is one of the few security functions where the buyer hands over not just tooling but decision-making during an incident. A contract that specifies how many alerts a provider triages, without specifying what the provider is authorized to do about them, who owns the resulting telemetry, and how the relationship unwinds, buys visibility the customer cannot act on. Info-Tech’s framing — capabilities and outcomes over acronyms — points in the right direction.

    The release also makes a secondary argument worth noting: MDR procurement is a natural moment to rationalize overlapping security tools, because modern providers often bring capabilities a buyer already licenses. That reframes an MDR deal from an added line item into a potential consolidation event, which changes the business case considerably.

    The Acronym Problem Is Really a Comparability Problem

    Info-Tech’s central observation — that providers use overlapping terms and branded descriptions for similar capabilities — sounds like a semantics complaint. It is actually a market-structure issue. When two offerings cannot be placed on the same axis, price competition weakens, because a buyer cannot credibly say a rival will do the same work for less. Differentiated naming is not necessarily deceptive; vendors genuinely build different things. But the practical effect is that the burden of constructing a comparison framework falls entirely on the buyer.

    That burden lands on exactly the teams least able to carry it. The release identifies limited security team bandwidth as one of its four named obstacles, alongside inconsistent terminology, growing vendor portfolios, and rushed decisions. The circularity is stark: organizations turn to MDR because they lack security operations capacity, then need meaningful security operations capacity to evaluate MDR properly. Structured requirements templates — the kind Info-Tech is selling — exist precisely to lower that evaluation cost. Whether a generic template is specific enough for a given environment is a fair question, and one the release does not address.

    Alert Volume Is the Wrong Unit of Account

    Info-Tech’s phase two calls for measurable KPIs and service level requirements, without prescribing which ones. That restraint is defensible in a general methodology, but it leaves the hardest question open. The metrics MDR contracts most commonly carry — alerts triaged, mean time to detect, mean time to acknowledge — measure the provider’s throughput, not the customer’s risk reduction. A provider can hit every one of them while an intrusion progresses, because acknowledging an alert is not containing an incident.

    The commercially decisive terms sit elsewhere: whether the provider may isolate a host, disable an account or block traffic without waiting for customer approval; how fast that authority applies at 3 a.m. on a holiday; and what happens when the provider acts and is wrong. Response authority is what separates managed detection from managed detection and response, and it is the clause most often softened during negotiation because it carries liability for both sides. Buyers who treat it as boilerplate discover the gap during their first serious incident. Info-Tech’s release does not name these specific terms; the emphasis on defining how responsibilities are divided between organization and provider in phase one is nonetheless the right place to force the conversation.

    Consolidation Cuts Both Ways

    The blueprint’s argument that MDR procurement can surface duplicate tooling is the most immediately monetizable idea in the release. If a provider’s platform already covers endpoint detection, log aggregation and threat intelligence, a buyer paying separately for all three has a genuine savings case — and a stronger negotiating position, because the deal is now worth more to the vendor. For infrastructure operators running their own colocation, network and cloud estates, this is often where the real economics of an MDR deal live.

    The counterweight is concentration. Folding detection tooling into a provider’s stack means the provider owns the pipeline that generates the evidence of its own performance. That raises questions the release does not take up: whether the customer retains a copy of raw telemetry in its own storage, in what format, for how long, and at what egress cost on the way out. A buyer who consolidates onto provider-owned tooling and later wants to switch may find that the practical cost of leaving is not the migration project but the loss of detection history — the baseline that makes anomaly detection work. Consolidation savings are real; they should be scored net of that exit risk, not gross.

    Governance Is the Phase Nobody Staffs

    Phase four asks organizations to actively govern provider performance rather than treat service reviews as passive status updates. This is the least glamorous part of the framework and probably the most predictive of whether a deal succeeds. An MDR relationship degrades quietly: detection rules go stale as the environment changes, integrations silently break after a cloud migration, escalation contacts leave the company. None of that shows up in a monthly alert-count report.

    The problem is that governance requires a named internal owner with time and authority — the same scarce resource whose absence justified outsourcing. Organizations that buy MDR as a headcount substitute and assign oversight as a fraction of someone’s week tend to get the relationship they resourced. The honest version of the business case treats MDR as a capacity multiplier that still requires a retained internal function, not as a full replacement. Info-Tech’s four phases imply that conclusion without stating it, and buyers would be well served to make it explicit in their own board-level justification.

    Background

    Managed detection and response emerged over the past decade as a response to a structural shortage: continuous threat monitoring requires staffing across three shifts, specialist tooling and constant tuning, which is out of reach for most organizations outside the largest enterprises. The category grew out of earlier managed security service provider (MSSP) models, which largely forwarded alerts to the customer, by adding investigation and, in principle, active response. Adjacent labels — SOC-as-a-service, extended detection and response, co-managed SIEM — overlap heavily in practice, which is the comparability problem Info-Tech’s blueprint addresses.

    Info-Tech Research Group is an IT research and advisory firm headquartered with a US presence in Arlington, Virginia, publishing prescriptive methodologies it calls blueprints alongside advisory services. Its business model is subscription research, so its published announcements function both as analysis and as marketing for the underlying deliverable. This particular release was distributed via PR Newswire’s CNW service on August 27, 2026, and follows other recent Info-Tech procurement guidance, including work on agentic AI contracting.

    Source: CISOs Risk MDR Buyer’s Remorse Without Clear Procurement Requirements, Says Info-Tech Research Group — Info-Tech Research Group’s August 27, 2026 announcement of its four-phase blueprint for procuring managed detection and response services.

  • The Unverifiable-Claims Problem Isn’t Advertising’s Alone. It’s Infrastructure’s.

    The Unverifiable-Claims Problem Isn’t Advertising’s Alone. It’s Infrastructure’s.

    Pesach Lattin, who writes the advertising newsletter ADOTAT, recently made an argument that deserves a wider audience than the ad industry it was aimed at. Borrowing from the philosopher Harry Frankfurt’s essay On Bullshit, he draws a distinction that matters: a liar knows the truth and conceals it, while a bullshitter simply doesn’t care whether what he says is true. Lattin’s claim is that the advertising business is mostly doing the second thing about AI — making confident, unverifiable assertions with an apparent indifference to whether they hold up. He says he reviewed six months of conference talks and found four claims that were actually checkable.

    I run an infrastructure company, not an ad agency. And reading it, I recognized the pattern immediately — because the same epistemics now govern how artificial intelligence gets sold one layer down, in the data centers, networks, and compute that everything else is built on.

    The tell is verifiability, not sincerity

    The useful part of Frankfurt’s framing is that it takes the argument away from intent. You do not have to decide whether a vendor is honest. You only have to ask a colder question: is this claim the kind of thing I could check? Most of the loudest statements in AI infrastructure marketing are not.

    “AI-optimized” is not a specification. “Cloud-scale” is not a number. “Enterprise-grade reliability” is not an SLA. A GPU cloud that advertises a headline price per hour has told you almost nothing until you know the utilization you can actually achieve, the queue times at your scale, the egress charges, and whether the accelerators you were sold are the ones you get. A data center that markets a power-usage-effectiveness figure has told you something real only if it says whether that number is a design target or a measured annual average, at what load, in what climate. The gap between those two readings is where a year of operating budget hides.

    The one uncontested number

    Lattin points out that in his world, exactly one figure goes uncontested: the collapse in referral traffic as AI answer engines absorb the clicks that used to reach publishers — reductions he puts in the range of 20 to 90 percent. It is uncontested precisely because it is measurable. Everyone can see their own analytics.

    Infrastructure has its own version of the uncontested number, and it is the electricity bill. You can argue about a model’s benchmark scores; you cannot argue with a utility invoice or a substation’s interconnection queue. This is why the most honest conversations in our industry right now are the ones about power and cooling. Megawatts do not bullshit. A grid operator’s capacity map is the least performative document in the AI economy, and it is quietly setting the ceiling on all of the confident projections layered above it.

    A working buyer’s test

    None of this is a case for cynicism. The technology is real, and the demand is real. The point is narrower and more practical: when someone sells you AI infrastructure, sort every claim into two piles before you sort it into true or false.

    • Testable now: Can it be written into a contract with a number and a penalty? Latency percentiles, delivered throughput, measured PUE over a defined period, uptime with real credits, a fixed price with the egress spelled out. Ask for the measurement method, not the headline.
    • Testable later: Can you run a bounded pilot that produces your own data — a parallel workload, a real month of your traffic — rather than the vendor’s reference benchmark? Insist on it before the multi-year commitment, not after.
    • Not testable: Adjectives, roadmaps, and transformation narratives. These are not lies. They are simply not evidence, and they should carry the weight of things that are not evidence.

    The vendors worth working with will not flinch at this. In my experience, the willingness to be measured is the single most reliable signal of whether a claim was meant to be true or merely meant to be said. The ones who lead with the utility bill, the SLA, and the pilot are telling you something. So are the ones who change the subject to the future.

    Lattin’s essay is about advertising, and it is worth reading on its own terms. But its real subject is a habit of mind that has spread well past his industry. The infrastructure layer is the last place that habit can safely live, because down here the claims eventually meet a power meter, a thermal limit, and a bill. Ask for the number. If there isn’t one, you have your answer.

    Source and inspiration: Pesach Lattin, “Nobody Is Lying to You About AI. Almost Nobody Is Telling You the Truth Either,” ADOTAT.