I get that impression too. I do some cybersecurity type stuff as a hobby and was hoping to make a business out of it somehow but it doesn't seem to be a easy market to crack.
I get that impression too. I do some cybersecurity type stuff as a hobby and was hoping to make a business out of it somehow but it doesn't seem to be a easy market to crack.
There are 2600 companies in the space and they almost all do one small thing (and lots of them don't do it terribly well).
It turns out what every company wants is more of a comprehensive turnkey solution than exists, or at least a highly modular framework that can accept modules from other vendors. Companies generally don't understand that security is an attribute of everything, it isn't an end product. Hence executives would rather pay for a blinky box than remember to incorporate security planning into every other expense. Also most companies aren't willing to pay much to a cybersecurity vendor because cybersecurity is largely seen as a cost center and not a profit center (because that's accurate most of the time).
I got into bug bounties for a little while, but the work is tough. Selecting a program which pays out enough and doesn't have all of the low-hanging fruit picked is difficult. It's the kind of work where very well organized bounty hunters will take the lion's share of the winnings, which doesn't lend itself well to developers who can make a healthy salary elsewhere.
Source: I work for a cybersecurity startup.