Problem Statement
Large organisations spend millions of dollars a year on cyber — in the biggest estates, tens or hundreds of millions — and run dozens to 100+ security tools[1][2][3][4]. The largest customers we sell into sit at 100+ tools. The money is real. The portfolio is real. The picture of it is not.
Security leaders at 10,000+ employee, $1bn+ enterprises typically cannot answer, on demand and with evidence:
- what they actually have (licensed vs deployed vs in use)
- where tools overlap (two products, same capability, both still paid for)
- where the gaps are (bought coverage that is missing, partial, or never rolled out)
- how things are configured (what the control is doing, not what the invoice says it does)
- how well they are protected (mapped to NIST / ISO / ATT&CK, not a vendor heatmap)
That picture does not live in a spreadsheet or in tribal knowledge. It is assembled, late, under pressure — for a board, a consultancy review, an audit, or a 90-day notice period — and it is already stale when it lands. That is the problem ESProfiler exists to solve. Another control product is more sprawl. ESProfiler is the living description of the estate. The competitor is a stale spreadsheet plus a consultancy invoice.
This page details the evidence base for that framing. It should be used to support the framing in design, marketing, and sales. The user personas — Simon the CISO, Harry the Head of Cyber, Sasha the Security Architect, and Paige the Procurement Officer — ground who feels the pressure; this page describes why the pressure is real and why the purchase is a necessity, not a nice-to-have.
The necessity in one sentence
You cannot govern, cut, or defend millions of dollars of cyber spend against a stack you cannot describe.
1. Consultancy Pressure
A PwC review of a security org is built to demand a picture most CISOs cannot produce from a spreadsheet.
PwC Portfolio Rationalisation (with Microsoft) sells a packaged assessment: current tool inventory, overlapping capabilities, unused functions, total cost of ownership (TCO), licence-renewal decisions, and a future-state stack[5][7]. Their copy is explicit that too many point solutions create a redundant landscape that can hinder cyber risk management. The Canadian alliance page says the same: overlapping capabilities and unused technology functions, completed in weeks rather than a multi-year rationalisation programme[6].
KPMG Cyber cost optimization sells the same motion: underutilized or overlapping security tools, security-tool rationalization, cost vs reward[8]. Their Security through a downturn briefing describes enterprises paying significant licensing fees for underutilized or duplicative tools that were never aligned back to strategy or architecture[9].
Implication for Simon the CISO / Harry the Head of Cyber: when consultancy walks in, the ask is inventory + overlap + unused function + TCO. If that picture does not already exist, Simon the CISO is exposed in the room — and the firm will pay PwC or KPMG to assemble a point-in-time version of what ESProfiler is meant to hold continuously.
We have seen success in enegagements hre a consultancy firm has provided a picture of the estate, and then we get pulled in to fix the problems around the visibility of the estate.
2. Tool Sprawl
Counts vary by methodology (tools vs solutions vs vendors). The direction does not: large enterprises run dozens of overlapping products, complexity is a first-order operational and cost problem, and consolidation / inventory is now a management and regulatory motion.
The pattern we sell into — complex IT, M&A duplicate estates, identity and integration backlogs, audit mapping that has to stand up to SOX / ISO / NIST — is visible in industry research and regulation.
| Claim | Figure | Source |
|---|---|---|
| Average security solutions / vendors | 83 solutions from 29 vendors | [3][4] |
| Fragmentation blocks operations / threat response | 52% of executives | Same study[3] |
| Large-enterprise tool count | Average 45 cybersecurity tools (162 large enterprises, Aug–Oct 2024) | [1] |
| Consolidation in motion | 62% pursuing vendor consolidation; 36% plan to in 0–3 years | Gartner, From Overload to Optimization (June 2025; report paywalled)[10] |
| Earlier consolidation wave | 75% pursuing security vendor consolidation in 2022 (up from 29% in 2020) | [11] |
| Complexity raises breach cost | Security-system complexity remains a top cost amplifier (with supply-chain breach and shadow AI) | [12] |
| Inventory is a control | NYDFS 23 NYCRR 500.13(a) — complete, accurate, documented asset inventory (owner, location, classification, support expiration, RTO, update frequency). Compliance date 1 Nov 2025 | [13][14] |
How to use the numbers
- Prefer the IBM/Palo Alto Networks (PA) example [3] set when talking to the C-suite about complexity as an operational blocker.
- Prefer Gartner's 45-tool large-enterprise figure [1] when talking to architects who will argue "we don't have 83 products."
- Prefer NYDFS 500.13 [13][14] when the buyer is in financial services or already treating inventory as an audit artefact. Do not collapse all three into one fake "average."
3. Identifying gaps in the security stack
Tool count is not the same as coverage. Large estates pay for dozens of products and still cannot show, with evidence, which capabilities they have twice, which they do not have at all, and which they only have on the invoice. That is the gap problem: overlap and holes, in the same undescribed portfolio.
Public research is blunt on this:
- Fragmentation is an operational failure, not a housekeeping issue. IBM IBV + Palo Alto Networks found 52% of executives say fragmentation of security solutions limits the ability to deal with cyber threats; complexity is the biggest impediment to security operations[3].
- Consultancy products assume the gap/overlap picture does not already exist. PwC Portfolio Rationalisation is sold as inventory + overlapping capabilities + unused functions + TCO[5]. KPMG describes significant licensing fees for underutilized or duplicative tools never aligned back to strategy or architecture[9].
- Bought telemetry is not the same as coverage. CardinalOps' 2025 State of SIEM Detection Risk (hundreds of production SIEMs) found enterprise SIEMs have detections for only about 21–22% of MITRE ATT&CK techniques — leaving roughly 78–79% of techniques without a mapped detection — while ingesting enough data to potentially cover 90%+. On average 13% of existing detection rules are non-functional (misconfigured sources, missing fields)[15][16]. That is a SIEM-specific measurement, not a whole-stack ATT&CK score — use it as evidence that licensed capability ≠ working coverage.
- Vendor heatmaps are not an estate description. CISA states ATT&CK can be used to identify defensive gaps and assess security tool capabilities[17]. AttackIQ's argument is the one Harry the Head of Cyber already uses: untested coverage is unknown, not green[18]. A USENIX Security 2024 study of commercial endpoint rulesets found products that detect the same behaviour often do not even claim the same ATT&CK techniques[19].
How to use this. Overlap is the commercial half of the gap (two invoices, one capability). Holes are the risk half (a NIST outcome or ATT&CK technique with no working control). ESProfiler has to show both against a framework the buyer already reports to — not against a vendor's marketing matrix.
Frameworks they invest against
Boards do not fund "more tools." They fund risk reduction and compliance.. The three languages that show up in large-enterprise cyber investment are NIST (outcomes), MITRE ATT&CK (adversary coverage), and an internal / ISO-shaped control catalogue. None of them can be answered from a contract spreadsheet.
NIST Cybersecurity Framework 2.0
NIST CSF 2.0 is the default board and regulator language for "are we protected?" It does not prescribe products. It requires organisations to describe outcomes, then invest against the difference between where they are and where they need to be.
- Current Profile vs Target Profile is the official gap analysis. NIST's process is: scope the profile → gather information (including practices and tools) → create Current and Target Profiles → analyse the gaps and create a prioritized action plan (risk register, POA&M) → implement and update[20][21]. The investment case for cyber is that action plan. If Harry the Head of Cyber cannot evidence the Current Profile from the estate, the Target Profile is fiction.
- Inventory of software and supplier services is an Identify outcome. ID.AM-02: inventories of software, services, and systems are maintained. ID.AM-04: inventories of services provided by suppliers are maintained. ID.AM-08: systems, hardware, software, services, and data are managed throughout their life cycles[20]. A security-tool portfolio that lives only in procurement is a failed Identify function.
- Risk assessment has to use threats, not invoices. ID.RA-03: internal and external threats are identified and recorded. ID.RA-05: threats, vulnerabilities, likelihoods, and impacts are used to understand risk. ID.RA-06: risk responses are chosen, prioritized, planned, tracked, and communicated. GV.OV expects leadership to review cybersecurity strategy against those outcomes[20].
- Where 800-53 is the overlay. Organisations that assess against NIST SP 800-53 still need CM-8 (system component inventory), CA-2 / CA-7 (control assessment and continuous monitoring), and RA-3 (risk assessment)[22]. Same demand: a living inventory mapped to controls, not an annual spreadsheet.
Implication: NIST is how Simon the CISO defends investment. Without a Current Profile grounded in what is actually licensed, deployed, and configured, every new purchase is "another tool," not a gap close.
MITRE ATT&CK
ATT&CK is not a statute and not a certification. Treat it as the shared language for defensive coverage, which CISOs and CISA expect you to be able to show. To the board, this is communicated as "we are protected against these attacker's techniques."
- CISA's stated uses include identifying defensive gaps, assessing security tool capabilities, organising detections, and validating mitigation controls[17]. Eric Goldstein (CISA) on the Decider release: ATT&CK helps organisations prioritize cybersecurity controls and mitigations that reduce intrusions[23].
- The coverage problem is measurable. CardinalOps (above) shows production SIEMs covering roughly a fifth of techniques, with broken rules inside the fifth they think they have[15][16]. That is the "we bought detection" gap.
- Do not confuse vendor ATT&CK maps with estate coverage. Vendor evaluations and product heatmaps describe a product in a lab or a brochure. The question Harry the Head of Cyber asks is whether this estate, with these products as configured, covers the techniques that matter — and what residual risk a renewal cut opens.
Implication: ATT&CK is how Harry the Head of Cyber answers "if I take this out, what gap am I opening?" If the map is a vendor PDF, the answer is not defensible.
Internal and ISO-shaped control sets
Most 10,000+ employee buyers do not run NIST or ATT&CK alone. They run a home-grown control library in GRC (often ISO 27001 Annex A, 800-53, PCI, SOX, or a sector overlay, plus local policy). Investment still has to trace to that library.
That library is frequently not written in-house. Accenture, KPMG, PwC, Deloitte, and peers sell the design of the control set as a packaged engagement: take public standards, crosswalk them, tailor to sector and risk appetite, and leave the organisation with a unified catalogue that Simon the CISO then reports against. Public service descriptions are explicit:
- PwC lists cybersecurity framework development as a named service: define objectives and scope, run a risk assessment, then develop the cybersecurity strategy and framework — using NIST CSF, ISO/IEC 27001, COBIT, ITIL, and local regulation as inputs[24].
- Deloitte sells controls and policy harmonization: "develop a unified control framework tailored to your risk and sector," plus multi-regulation gap assessments that visually map overlapping controls across ISO, NIST CSF, NIS2, DORA, SOC 2, and others[25]. Their NIST practice likewise consults on which standards apply and runs gap analyses against the control and security requirements that overlap[26].
- KPMG sells an IT risk and control framework "integrated with the leading standards and laws and regulations" (COBIT, SWIFT, NIST, SOC 2, ISO 27001, and more) so the organisation can design, construct, and operate that framework[27]. Their NIS2 briefing argues for building and monitoring a unified control framework so the buyer can "test once and comply to many"[28]. Technology Risk Advisory copy is the same motion: assess IT governance, cybersecurity, and control frameworks, then design tailored solutions aligned to NIST, ISO, and COBIT[29].
- Accenture sells cyber strategy plus a security target operating model: a blueprint that includes a controls review, maturity and threat assessments, RACI, processes and capabilities, suppliers, and a three-to-five-year target state for evidence-based investment[30][31]. IDC's GRC MarketScape notes Accenture's offering spans strategy, operating model design, platform implementation, and managed services[32].
The pattern: ISO / NIST / CIS / COBIT / sector rules are the ingredients. The artefact Harry the Head of Cyber inherits is a consultancy-authored crosswalk with local IDs, KRIs, and a Statement of Applicability. When the same firm (or another) returns for a rationalisation or audit, they test the estate against that catalogue — not against a vendor heatmap.
- ISO/IEC 27001:2022 requires a Statement of Applicability (clause 6.1.3): which Annex A controls apply, whether they are implemented, and why any are excluded. Annex A 5.9 requires an inventory of information and other associated assets, with owners, kept current — software and services included[33]. A stale tool list cannot support the SoA or the risk treatment plan.
- Internal catalogues (SABSA-style traceability, custom "cyber control libraries," board KRIs — whether written by the architects or by Accenture / KPMG / PwC / Deloitte) make the same demand in local language: a control that cannot be traced to a risk is not required; two tools that trace to the same control are overlap; a required control with no working tool is a gap[34].
- Sector overlays (NYDFS 500.13 inventory, SOX 404 control evidence, NIS2 / DORA) sit on top[13][28]. They do not replace NIST/ATT&CK/ISO; they are why the unified catalogue exists.
Implication: ESProfiler has to map the estate to the buyer's framework, not only to vanilla NIST or ATT&CK. That framework is often a paid consultancy deliverable. The product problem is the same mapping job with a different left-hand column — and the next consultancy visit will use that column.
4. Why they have to buy ESProfiler
Buying another detection, identity, or GRC point product adds a row to the spreadsheet. It does not produce the spreadsheet. It does not tell you what overlaps. It does not tell you what is missing. And it does not arrive in time for the notice period owned by Paige the Procurement Officer.
The purchase is a necessity because three failures happen together in the ICP:
Renewal decisions happen too late
The commercial clock is 30–90 days of notice, often with auto-renew as the default — 69% of software contracts carry an auto-renew clause with a 30–90 day cancellation window[35]; Gartner data cited by Varisource indicates ~75% of SaaS vendors rely on auto-renewal as retention[36]. Vendors track that deadline; buyers often do not[37].
Ownership is fragmented across procurement, finance, IT, and security[38]. By the time Harry the Head of Cyber can answer "keep / cut / renegotiate," leverage is gone and the stack grows by inertia. The specific Paige the Procurement Officer ↔ Harry the Head of Cyber 90-day scramble is a synthesis; the clock, the clause, and the late answer are not.
There There is no clear picture of capability overlap
Two products can satisfy the same NIST outcome or the same ATT&CK technique, both still paid for. PwC and KPMG sell the assessment because that picture is not in the estate[5][8]. Consolidation programmes (62% pursuing vendor consolidation in 2025[10]; 75% in 2022[11]) cannot be executed safely if "duplicate" is an opinion rather than a mapped capability.
There are gaps in portfolio capability, not just extra tools
CardinalOps, IBM/PANW fragmentation, and NIST's Current vs Target process all describe the other side of sprawl: outcomes and techniques with no working control, or a control that exists only as a licence[16][3][21]. Cutting spend without that map opens a hole. Adding spend without that map buys a second copy of something they already have — or a product that does not close the Target Profile gap they are funding.
ESProfiler is necessary when all of the following are true at once — which they are, for the ICP:
- Someone external will ask. Consultancy, internal audit, regulator, board, or CFO. The question is always some version of: what do we have, what does it cover, where does it overlap, where are the gaps, what can we cut.
- The current system of record is not a system. Contracts sit with Paige the Procurement Officer. Ground truth sits with Sasha the Security Architect. The board narrative sits with Harry the Head of Cyber. Simon the CISO is accountable for a number he cannot verify.
- The renewal window is shorter than the analysis. A Current-vs-Target or ATT&CK coverage exercise that takes weeks will miss a 30–90 day notice period. Point-in-time consulting expires the Monday after it lands; renewals do not wait for the next engagement.
- Regulation and frameworks are moving inventory from preference to control. NYDFS 500.13 is the sharpest public example[13]. NIST CSF Profiles, ISO 27001 SoA / A.5.9, and ATT&CK-as-coverage-language are how the same demand shows up in investment and audit[21][33][17].
- Spend cannot be cut — or increased — safely without coverage evidence. Consolidation without overlap/gap mapping is how Simon the CISO gets unpicked in the board. A new purchase that is not traced to a Target Profile gap is more sprawl.
What ESProfiler has to be, therefore, is the living description of the estate:
- what is licensed vs deployed vs in use
- what it actually does (vs what was bought)
- where capabilities overlap
- where the gaps are against NIST / ATT&CK / the internal control set
- which renewals can be killed or renegotiated in time, without opening a gap
If a feature does not help produce that picture — or act on it inside a decision window — it is not the problem we are solving.
5. How this lands with personas
| Persona | Why it is a necessity for them |
|---|---|
| Simon the CISO | He is accountable for a number and a posture he did not build. Consultancy and the board will unpick a guess. He needs one page that survives the room. |
| Harry the Head of Cyber | He has to walk into every renewal with a costed recommendation. Without an estate description he is always late to the clock owned by Paige the Procurement Officer and exposed when Simon the CISO is. |
| Sasha the Security Architect | She already knows fragments of ground truth. The necessity is making that knowledge evidenced, repeatable, and defensible — not spending three weeks per category reconstructing it from consoles. |
| Paige the Procurement Officer | Notice periods do not slip because Security is still investigating. She needs an evidenced keep / cut / renegotiate answer while leverage still exists. |
Sources
Security stack size
- [1] Gartner, Top Cybersecurity Trends for 2025 — average 45 cybersecurity tools (162 large enterprises, Aug–Oct 2024)
- [2] NHIMG / Securiti, Security tool sprawl and context loss — average 61 security tools
- [3] IBM IBV + Palo Alto Networks, Capturing the cybersecurity dividend (Jan 2025) — 83 solutions from 29 vendors; 52% say fragmentation blocks threat response
- [4] IBM IBV, Capturing the cybersecurity dividend (PDF download)
1. Consultancy Pressure
- [5] PwC Netherlands — Portfolio Rationalisation
- [6] PwC Canada — Portfolio Rationalization (Microsoft alliance)
- [7] Microsoft AppSource — PwC Portfolio Rationalisation
- [8] KPMG — Cyber cost optimization
- [9] KPMG — Security through a downturn (PDF)
2. Tool Sprawl
- [10] Bitdefender citing Gartner, From Overload to Optimization (June 2025) — 62% consolidating; 36% plan to in 0–3 years
- [11] Gartner newsroom (Sep 2022) — 75% pursuing security vendor consolidation
- [12] IBM — Cost of a Data Breach Report 2025 — complexity as a top cost amplifier
- [13] 23 NYCRR 500.13 — asset management inventory as a control
- [14] NYDFS — implementation timeline for covered entities (PDF)
3. Identifying gaps in the security stack
- [15] CardinalOps via PR Newswire — enterprise SIEMs miss ~79% of ATT&CK techniques
- [16] CardinalOps — 5th Annual State of SIEM Detection Risk (2025, PDF) — ~21–22% coverage; ~13% broken rules
- [17] CISA — Best Practices for Mapping to MITRE ATT&CK (PDF)
- [18] AttackIQ — What Does MITRE ATT&CK Coverage Really Mean?
- [19] USENIX Security 2024 — Virkud et al., endpoint products and ATT&CK labelling
NIST Cybersecurity Framework 2.0
- [20] NIST CSWP 29 — CSF 2.0 (Current / Target Profiles; ID.AM; ID.RA)
- [21] NIST SP 1301 — Creating and Using Organizational Profiles
- [22] NIST SP 800-53 Rev. 5 — CM-8, CA-2 / CA-7, RA-3
MITRE ATT&CK
- [23] MITRE / CISA — Decider release
Internal and ISO-shaped control sets
- [24] PwC Singapore — Cybersecurity framework development
- [25] Deloitte — unified control framework tailored to risk and sector
- [26] Deloitte — NIST adoption and compliance
- [27] KPMG Netherlands — IT Risk in Control
- [28] KPMG — NIS2 briefing (PDF) — unified control framework; test once, comply to many
- [29] KPMG — Technology Risk Advisory
- [30] Accenture UK — Security Target Operating Model (G-Cloud)
- [31] Accenture — Cyber Strategy
- [32] IDC MarketScape excerpt via Accenture (PDF) — GRC consulting 2025–2026
- [33] ISO/IEC 27001:2022 — SoA (6.1.3); Annex A 5.9
- [34] SABSA — control traceability

