[{"data":1,"prerenderedAt":2080},["ShallowReactive",2],{"navigation_docs":3,"-company-problem-statement":369,"-company-problem-statement-surround":2077},[4,8,72,102,220,266,280,301,365],{"title":5,"path":6,"stem":7},"Introduction","\u002Fintroduction","0.introduction",{"title":9,"icon":10,"path":11,"stem":12,"children":13,"page":67},"Company","i-lucide-building-2","\u002Fcompany","1.company",[14,18,22,26,30,34,38,42,46,50,54,68],{"title":15,"path":16,"stem":17},"About","\u002Fcompany\u002Fabout","1.company\u002F0.about",{"title":19,"path":20,"stem":21},"Values","\u002Fcompany\u002Fvalues","1.company\u002F1.values",{"title":23,"path":24,"stem":25},"Communication","\u002Fcompany\u002Fcommunication","1.company\u002Fcommunication",{"title":27,"path":28,"stem":29},"Competition","\u002Fcompany\u002Fcompetition","1.company\u002Fcompetition",{"title":31,"path":32,"stem":33},"Hybrid Working","\u002Fcompany\u002Fhybrid-working","1.company\u002Fhybrid-working",{"title":35,"path":36,"stem":37},"Manchester Office","\u002Fcompany\u002Foffice","1.company\u002Foffice",{"title":39,"path":40,"stem":41},"Operations","\u002Fcompany\u002Foperations","1.company\u002Foperations",{"title":43,"path":44,"stem":45},"Policies","\u002Fcompany\u002Fpolicies","1.company\u002Fpolicies",{"title":47,"path":48,"stem":49},"Problem Statement","\u002Fcompany\u002Fproblem-statement","1.company\u002Fproblem-statement",{"title":51,"path":52,"stem":53},"Product Strategy","\u002Fcompany\u002Fproduct-strategy","1.company\u002Fproduct-strategy",{"title":55,"path":56,"stem":57,"children":58,"page":67},"Products","\u002Fcompany\u002Fproducts","1.company\u002Fproducts",[59,63],{"title":60,"path":61,"stem":62},"Capability Exchange","\u002Fcompany\u002Fproducts\u002Fcapability-exchange","1.company\u002Fproducts\u002Fcapability-exchange",{"title":64,"path":65,"stem":66},"ESProfiler Platform","\u002Fcompany\u002Fproducts\u002Fesprofiler","1.company\u002Fproducts\u002Fesprofiler",false,{"title":69,"path":70,"stem":71},"Security","\u002Fcompany\u002Fsecurity","1.company\u002Fsecurity",{"title":73,"icon":74,"path":75,"stem":76,"children":77,"page":67},"People Ops","i-lucide-users","\u002Fpeople-ops","2.people-ops",[78,82,86,90,94,98],{"title":79,"path":80,"stem":81},"Compensation","\u002Fpeople-ops\u002Fcompensation","2.people-ops\u002Fcompensation",{"title":83,"path":84,"stem":85},"Education","\u002Fpeople-ops\u002Feducation","2.people-ops\u002Feducation",{"title":87,"path":88,"stem":89},"Expenses","\u002Fpeople-ops\u002Fexpenses","2.people-ops\u002Fexpenses",{"title":91,"path":92,"stem":93},"Holiday & Leave","\u002Fpeople-ops\u002Fleave","2.people-ops\u002Fleave",{"title":95,"path":96,"stem":97},"Onboarding","\u002Fpeople-ops\u002Fonboarding","2.people-ops\u002Fonboarding",{"title":99,"path":100,"stem":101},"Recruitment","\u002Fpeople-ops\u002Frecruitment","2.people-ops\u002Frecruitment",{"title":103,"icon":104,"path":105,"stem":106,"children":107,"page":67},"Engineering","i-lucide-rocket","\u002Fengineering","3.engineering",[108,151,155,175,196,200,208,212,216],{"title":109,"path":110,"stem":111,"children":112,"page":67},"Contributing","\u002Fengineering\u002Fcontributing","3.engineering\u002Fcontributing",[113,117,121,125,129,142],{"title":114,"path":115,"stem":116},"Development Setup","\u002Fengineering\u002Fcontributing\u002Fdevelopment-setup","3.engineering\u002Fcontributing\u002F1.development-setup",{"title":118,"path":119,"stem":120},"Engineering Operations","\u002Fengineering\u002Fcontributing\u002Fengineering-operations","3.engineering\u002Fcontributing\u002F2.engineering-operations",{"title":122,"path":123,"stem":124},"Documentation","\u002Fengineering\u002Fcontributing\u002Fdocumentation","3.engineering\u002Fcontributing\u002F3.documentation",{"title":126,"path":127,"stem":128},"Agentic Coding","\u002Fengineering\u002Fcontributing\u002Fagentic-coding","3.engineering\u002Fcontributing\u002Fagentic-coding",{"title":130,"path":131,"stem":132,"children":133,"page":67},"Back End","\u002Fengineering\u002Fcontributing\u002Fback-end","3.engineering\u002Fcontributing\u002Fback-end",[134,138],{"title":135,"path":136,"stem":137},"API Guidelines","\u002Fengineering\u002Fcontributing\u002Fback-end\u002Fapi-guidelines","3.engineering\u002Fcontributing\u002Fback-end\u002Fapi-guidelines",{"title":139,"path":140,"stem":141},"LLM Prompts & Langfuse Integration","\u002Fengineering\u002Fcontributing\u002Fback-end\u002Fllm-prompts","3.engineering\u002Fcontributing\u002Fback-end\u002Fllm-prompts",{"title":143,"path":144,"stem":145,"children":146,"page":67},"Front End","\u002Fengineering\u002Fcontributing\u002Ffront-end","3.engineering\u002Fcontributing\u002Ffront-end",[147],{"title":148,"path":149,"stem":150},"Testing","\u002Fengineering\u002Fcontributing\u002Ffront-end\u002Ftesting","3.engineering\u002Fcontributing\u002Ffront-end\u002Ftesting",{"title":152,"path":153,"stem":154},"Production Database","\u002Fengineering\u002Fdatabase-connection","3.engineering\u002Fdatabase-connection",{"title":156,"path":157,"stem":158,"children":159},"Deployment","\u002Fengineering\u002Fdeployment","3.engineering\u002Fdeployment",[160,163,167,171],{"title":60,"path":161,"stem":162},"\u002Fengineering\u002Fdeployment\u002Fcapability-exchange","3.engineering\u002Fdeployment\u002Fcapability-exchange",{"title":164,"path":165,"stem":166},"Langfuse Deployment","\u002Fengineering\u002Fdeployment\u002Fecs-langfuse-deployment","3.engineering\u002Fdeployment\u002Fecs-langfuse-deployment",{"title":168,"path":169,"stem":170},"ESP Platform Configuration","\u002Fengineering\u002Fdeployment\u002Fesp-platform-configuration","3.engineering\u002Fdeployment\u002Fesp-platform-configuration",{"title":172,"path":173,"stem":174},"Platform","\u002Fengineering\u002Fdeployment\u002Fplatform","3.engineering\u002Fdeployment\u002Fplatform",{"title":176,"path":177,"stem":178,"children":179,"page":67},"Github","\u002Fengineering\u002Fgithub","3.engineering\u002Fgithub",[180,184,188,192],{"title":181,"path":182,"stem":183},"Packages","\u002Fengineering\u002Fgithub\u002Fpackages","3.engineering\u002Fgithub\u002Fpackages",{"title":185,"path":186,"stem":187},"Personal Access Token","\u002Fengineering\u002Fgithub\u002Fpersonal-access-token","3.engineering\u002Fgithub\u002Fpersonal-access-token",{"title":189,"path":190,"stem":191},"Troubleshooting","\u002Fengineering\u002Fgithub\u002Ftroubleshooting","3.engineering\u002Fgithub\u002Ftroubleshooting",{"title":193,"path":194,"stem":195},"Workflows","\u002Fengineering\u002Fgithub\u002Fworkflows","3.engineering\u002Fgithub\u002Fworkflows",{"title":197,"path":198,"stem":199},"Platform Ops","\u002Fengineering\u002Fplatform-ops","3.engineering\u002Fplatform-ops",{"title":172,"path":201,"stem":202,"children":203,"page":67},"\u002Fengineering\u002Fplatform","3.engineering\u002Fplatform",[204],{"title":205,"path":206,"stem":207},"useAPI","\u002Fengineering\u002Fplatform\u002Fuse-api","3.engineering\u002Fplatform\u002Fuse-api",{"title":209,"path":210,"stem":211},"Project Management","\u002Fengineering\u002Fproject-management","3.engineering\u002Fproject-management",{"title":213,"path":214,"stem":215},"Releases","\u002Fengineering\u002Frelease","3.engineering\u002Frelease",{"title":217,"path":218,"stem":219},"Tools","\u002Fengineering\u002Ftools","3.engineering\u002Ftools",{"title":221,"icon":222,"path":223,"stem":224,"children":225,"page":67},"Design","i-lucide-palette","\u002Fdesign","4.design",[226,247,251,255,259,262],{"title":227,"path":228,"stem":229,"children":230,"page":67},"Personas","\u002Fdesign\u002Fpersonas","4.design\u002F0.personas",[231,235,239,243],{"title":232,"path":233,"stem":234},"CISO - Simon","\u002Fdesign\u002Fpersonas\u002F01-ciso-simon","4.design\u002F0.personas\u002F01-ciso-simon",{"title":236,"path":237,"stem":238},"Head of Cyber - Harry","\u002Fdesign\u002Fpersonas\u002F02-head-of-cyber-harry","4.design\u002F0.personas\u002F02-head-of-cyber-harry",{"title":240,"path":241,"stem":242},"Security Architect - Sasha","\u002Fdesign\u002Fpersonas\u002F03-security-architect-sasha","4.design\u002F0.personas\u002F03-security-architect-sasha",{"title":244,"path":245,"stem":246},"Procurement Officer - Paige","\u002Fdesign\u002Fpersonas\u002F04-procurement-officer-paige","4.design\u002F0.personas\u002F04-procurement-officer-paige",{"title":248,"path":249,"stem":250},"Design Thinking","\u002Fdesign\u002Fdesign-thinking","4.design\u002F1.design-thinking",{"title":252,"path":253,"stem":254},"Design & Development","\u002Fdesign\u002Fdesign-and-development","4.design\u002F3.design-and-development",{"title":256,"path":257,"stem":258},"Branding","\u002Fdesign\u002Fbranding","4.design\u002F4.branding",{"title":217,"path":260,"stem":261},"\u002Fdesign\u002Ftools","4.design\u002F5.tools",{"title":263,"path":264,"stem":265},"Customer Success","\u002Fdesign\u002Fworking-with-customers","4.design\u002F6.working-with-customers",{"title":267,"icon":268,"path":269,"stem":270,"children":271,"page":67},"Sales","i-lucide-dollar-sign","\u002Fsales","4.sales",[272,276],{"title":273,"path":274,"stem":275},"Customer Onboarding","\u002Fsales\u002Fonboarding","4.sales\u002Fonboarding",{"title":277,"path":278,"stem":279},"Sales Tools","\u002Fsales\u002Ftools","4.sales\u002Ftools",{"title":281,"icon":282,"path":283,"stem":284,"children":285,"page":67},"Marketing","i-lucide-book-image","\u002Fmarketing","5.marketing",[286,290,294,297],{"title":287,"path":288,"stem":289},"Content","\u002Fmarketing\u002Fcontent","5.marketing\u002Fcontent",{"title":291,"path":292,"stem":293},"Messaging","\u002Fmarketing\u002Fmessaging","5.marketing\u002Fmessaging",{"title":217,"path":295,"stem":296},"\u002Fmarketing\u002Ftools","5.marketing\u002Ftools",{"title":298,"path":299,"stem":300},"Website","\u002Fmarketing\u002Fwebsite","5.marketing\u002Fwebsite",{"title":302,"icon":303,"path":304,"stem":305,"children":306,"page":67},"AI & Data Ops","i-lucide-database","\u002Fdata-ops","6.data-ops",[307,315,319,344,361],{"title":60,"path":308,"stem":309,"children":310,"page":67},"\u002Fdata-ops\u002Fcapability-exchange","6.data-ops\u002FCapability Exchange",[311],{"title":312,"path":313,"stem":314},"Leaderboard Calculation","\u002Fdata-ops\u002Fcapability-exchange\u002Fleaderboard-calculation","6.data-ops\u002FCapability Exchange\u002Fleaderboard-calculation",{"title":316,"path":317,"stem":318},"Account Portal (CAS)","\u002Fdata-ops\u002Faccount-portal","6.data-ops\u002Faccount-portal",{"title":320,"path":321,"stem":322,"children":323,"page":67},"Data Management","\u002Fdata-ops\u002Fdata-management","6.data-ops\u002Fdata-management",[324,328,332,336,340],{"title":325,"path":326,"stem":327},"Adding Products","\u002Fdata-ops\u002Fdata-management\u002Fadding-products","6.data-ops\u002Fdata-management\u002Fadding-products",{"title":329,"path":330,"stem":331},"Adding Vendors","\u002Fdata-ops\u002Fdata-management\u002Fadding-vendors","6.data-ops\u002Fdata-management\u002Fadding-vendors",{"title":333,"path":334,"stem":335},"Framework Mapping","\u002Fdata-ops\u002Fdata-management\u002Fframework-mapping","6.data-ops\u002Fdata-management\u002Fframework-mapping",{"title":337,"path":338,"stem":339},"Refreshing Vendors","\u002Fdata-ops\u002Fdata-management\u002Frefreshing-vendors","6.data-ops\u002Fdata-management\u002Frefreshing-vendors",{"title":341,"path":342,"stem":343},"Reviewing Draft Vendors","\u002Fdata-ops\u002Fdata-management\u002Freviewing-draft-vendors","6.data-ops\u002Fdata-management\u002Freviewing-draft-vendors",{"title":345,"path":346,"stem":347,"children":348,"page":67},"LLM Ops","\u002Fdata-ops\u002Fllm-ops","6.data-ops\u002Fllm-ops",[349,353,357],{"title":350,"path":351,"stem":352},"Agents","\u002Fdata-ops\u002Fllm-ops\u002Fagents","6.data-ops\u002Fllm-ops\u002F1.agents",{"title":354,"path":355,"stem":356},"ESPi Architecture & Query Flow","\u002Fdata-ops\u002Fllm-ops\u002Fespi-architecture","6.data-ops\u002Fllm-ops\u002F2.espi-architecture",{"title":358,"path":359,"stem":360},"Evaluating Agents","\u002Fdata-ops\u002Fllm-ops\u002Fevaluations","6.data-ops\u002Fllm-ops\u002F3.evaluations",{"title":362,"path":363,"stem":364},"Message Queues","\u002Fdata-ops\u002Fmessage-queues","6.data-ops\u002Fmessage-queues",{"title":366,"path":367,"stem":368},"Glossary","\u002Fglossary","glossary",{"id":370,"title":47,"body":371,"description":2070,"extension":2071,"links":2072,"meta":2073,"navigation":2074,"path":48,"seo":2075,"stem":49,"__hash__":2076},"docs\u002F1.company\u002Fproblem-statement.md",{"type":372,"value":373,"toc":2044},"minimark",[374,421,424,463,470,500,505,508,512,515,545,567,582,585,589,596,599,788,793,827,831,842,845,958,964,968,975,980,991,1066,1079,1083,1094,1161,1169,1173,1180,1190,1315,1329,1385,1394,1398,1407,1410,1414,1447,1472,1476,1512,1516,1535,1538,1610,1616,1644,1652,1656,1712,1716,1720,1771,1774,1809,1812,1859,1862,1904,1907,1927,1930,1938,1941,2009,2012],[375,376,377,378,382,383,386,396,403,410,417,418],"p",{},"Large organisations spend ",[379,380,381],"strong",{},"millions of dollars a year on cyber"," — in the biggest estates, tens or hundreds of millions — and run ",[379,384,385],{},"dozens to 100+ security tools",[387,388,389],"sup",{},[390,391,395],"a",{"href":392,"rel":393},"https:\u002F\u002Fwww.gartner.com\u002Fen\u002Fnewsroom\u002Fpress-releases\u002F2025-03-03-gartner-identifiesthe-top-cybersecurity-trends-for-2025",[394],"nofollow","[1]",[387,397,398],{},[390,399,402],{"href":400,"rel":401},"https:\u002F\u002Fnhimg.org\u002Fcommunity\u002Fcybersecurity-beyond-identity\u002Fsecurity-tool-sprawl-and-context-loss-what-practitioners-need-to-fix\u002F",[394],"[2]",[387,404,405],{},[390,406,409],{"href":407,"rel":408},"https:\u002F\u002Fwww.paloaltonetworks.com\u002Fcompany\u002Fpress\u002F2025\u002Fibm-and-palo-alto-networks-find-platformization-is-key-to-reduce-cybersecurity-complexity",[394],"[3]",[387,411,412],{},[390,413,416],{"href":414,"rel":415},"https:\u002F\u002Fwww.ibm.com\u002Fdownloads\u002Fdocuments\u002Fus-en\u002F115dcc7f0fb637c2",[394],"[4]",". The largest customers we sell into sit at 100+ tools. The money is real. The portfolio is real. ",[379,419,420],{},"The picture of it is not.",[375,422,423],{},"Security leaders at 10,000+ employee, $1bn+ enterprises typically cannot answer, on demand and with evidence:",[425,426,427,434,440,446,457],"ul",{},[428,429,430,433],"li",{},[379,431,432],{},"what they actually have"," (licensed vs deployed vs in use)",[428,435,436,439],{},[379,437,438],{},"where tools overlap"," (two products, same capability, both still paid for)",[428,441,442,445],{},[379,443,444],{},"where the gaps are"," (bought coverage that is missing, partial, or never rolled out)",[428,447,448,451,452,456],{},[379,449,450],{},"how things are configured"," (what the control is ",[453,454,455],"em",{},"doing",", not what the invoice says it does)",[428,458,459,462],{},[379,460,461],{},"how well they are protected"," (mapped to NIST \u002F ISO \u002F ATT&CK, not a vendor heatmap)",[375,464,465,466,469],{},"That picture does not live in a spreadsheet or in tribal knowledge. It is assembled, late, under pressure — for a board, a consultancy review, an audit, or a 90-day notice period — and it is already stale when it lands. ",[379,467,468],{},"That is the problem ESProfiler exists to solve."," Another control product is more sprawl. ESProfiler is the living description of the estate. The competitor is a stale spreadsheet plus a consultancy invoice.",[375,471,472,473,477,478,477,482,486,487,491,492,495,496,499],{},"This page details the evidence base for that framing. It should be used to support the framing in design, marketing, and sales. The user personas — ",[390,474,476],{"href":475},"..\u002Fdesign\u002Fpersonas\u002F01-ciso-simon","Simon the CISO",", ",[390,479,481],{"href":480},"..\u002Fdesign\u002Fpersonas\u002F02-head-of-cyber-harry","Harry the Head of Cyber",[390,483,485],{"href":484},"..\u002Fdesign\u002Fpersonas\u002F03-security-architect-sasha","Sasha the Security Architect",", and ",[390,488,490],{"href":489},"..\u002Fdesign\u002Fpersonas\u002F04-procurement-officer-paige","Paige the Procurement Officer"," — ground who feels the pressure; this page describes ",[379,493,494],{},"why the pressure is real"," and ",[379,497,498],{},"why the purchase is a necessity",", not a nice-to-have.",[501,502,504],"h2",{"id":503},"the-necessity-in-one-sentence","The necessity in one sentence",[375,506,507],{},"You cannot govern, cut, or defend millions of dollars of cyber spend against a stack you cannot describe.",[501,509,511],{"id":510},"_1-consultancy-pressure","1. Consultancy Pressure",[375,513,514],{},"A PwC review of a security org is built to demand a picture most CISOs cannot produce from a spreadsheet.",[375,516,517,518,525,532,533,536,537,544],{},"PwC Portfolio Rationalisation (with Microsoft) sells a packaged assessment: current tool inventory, overlapping capabilities, unused functions, total cost of ownership (TCO), licence-renewal decisions, and a future-state stack",[387,519,520],{},[390,521,524],{"href":522,"rel":523},"https:\u002F\u002Fwww.pwc.nl\u002Fen\u002Ftopics\u002Fdigital\u002Fcybersecurity\u002Fportfolio-rationalisation.html",[394],"[5]",[387,526,527],{},[390,528,531],{"href":529,"rel":530},"https:\u002F\u002Fappsource.microsoft.com\u002Fen-us\u002Fmarketplace\u002Fconsulting-services\u002Fpricewaterhousecoopers1596463445891.pwc_portfolio_rationalisation",[394],"[7]",". Their copy is explicit that ",[379,534,535],{},"too many point solutions create a redundant landscape that can hinder cyber risk management",". The Canadian alliance page says the same: overlapping capabilities and unused technology functions, completed in weeks rather than a multi-year rationalisation programme",[387,538,539],{},[390,540,543],{"href":541,"rel":542},"https:\u002F\u002Fwww.pwc.com\u002Fca\u002Fen\u002Fservices\u002Falliances\u002Fmicrosoft\u002Fcybersecurity\u002Fportfolio-rationalization.html",[394],"[6]",".",[375,546,547,548,555,556,559,560,544],{},"KPMG Cyber cost optimization sells the same motion: underutilized or overlapping security tools, security-tool rationalization, cost vs reward",[387,549,550],{},[390,551,554],{"href":552,"rel":553},"https:\u002F\u002Fkpmg.com\u002Fus\u002Fen\u002Fcapabilities-services\u002Fadvisory-services\u002Fcyber-security-services\u002Fcyber-transformation\u002Fcyber-cost-optimization.html",[394],"[8]",". Their ",[453,557,558],{},"Security through a downturn"," briefing describes enterprises paying significant licensing fees for underutilized or duplicative tools that were never aligned back to strategy or architecture",[387,561,562],{},[390,563,566],{"href":564,"rel":565},"https:\u002F\u002Fassets.kpmg.com\u002Fcontent\u002Fdam\u002Fkpmgsites\u002Fuk\u002Fpdf\u002F2021\u002F02\u002Fsecurity-through-a-downturn.pdf",[394],"[9]",[375,568,569,578,579,581],{},[379,570,571,572,574,575,577],{},"Implication for ",[390,573,476],{"href":475}," \u002F ",[390,576,481],{"href":480},":"," when consultancy walks in, the ask is inventory + overlap + unused function + TCO. If that picture does not already exist, ",[390,580,476],{"href":475}," is exposed in the room — and the firm will pay PwC or KPMG to assemble a point-in-time version of what ESProfiler is meant to hold continuously.",[375,583,584],{},"We have seen success in enegagements hre a consultancy firm has provided a picture of the estate, and then we get pulled in to fix the problems around the visibility of the estate.",[501,586,588],{"id":587},"_2-tool-sprawl","2. Tool Sprawl",[375,590,591,592,595],{},"Counts vary by methodology (tools vs solutions vs vendors). The ",[379,593,594],{},"direction"," does not: large enterprises run dozens of overlapping products, complexity is a first-order operational and cost problem, and consolidation \u002F inventory is now a management and regulatory motion.",[375,597,598],{},"The pattern we sell into — complex IT, M&A duplicate estates, identity and integration backlogs, audit mapping that has to stand up to SOX \u002F ISO \u002F NIST — is visible in industry research and regulation.",[600,601,602,618],"table",{},[603,604,605],"thead",{},[606,607,608,612,615],"tr",{},[609,610,611],"th",{},"Claim",[609,613,614],{},"Figure",[609,616,617],{},"Source",[619,620,621,649,668,687,716,736,757],"tbody",{},[606,622,623,627,637],{},[624,625,626],"td",{},"Average security solutions \u002F vendors",[624,628,629,632,633,636],{},[379,630,631],{},"83"," solutions from ",[379,634,635],{},"29"," vendors",[624,638,639,644],{},[387,640,641],{},[390,642,409],{"href":407,"rel":643},[394],[387,645,646],{},[390,647,416],{"href":414,"rel":648},[394],[606,650,651,654,660],{},[624,652,653],{},"Fragmentation blocks operations \u002F threat response",[624,655,656,659],{},[379,657,658],{},"52%"," of executives",[624,661,662,663],{},"Same study",[387,664,665],{},[390,666,409],{"href":407,"rel":667},[394],[606,669,670,673,680],{},[624,671,672],{},"Large-enterprise tool count",[624,674,675,676,679],{},"Average ",[379,677,678],{},"45"," cybersecurity tools (162 large enterprises, Aug–Oct 2024)",[624,681,682],{},[387,683,684],{},[390,685,395],{"href":392,"rel":686},[394],[606,688,689,692,702],{},[624,690,691],{},"Consolidation in motion",[624,693,694,697,698,701],{},[379,695,696],{},"62%"," pursuing vendor consolidation; ",[379,699,700],{},"36%"," plan to in 0–3 years",[624,703,704,705,708,709],{},"Gartner, ",[453,706,707],{},"From Overload to Optimization"," (June 2025; report paywalled)",[387,710,711],{},[390,712,715],{"href":713,"rel":714},"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fbusinessinsights\u002Fsecurity-platform-is-dead-long-live-security-platform",[394],"[10]",[606,717,718,721,727],{},[624,719,720],{},"Earlier consolidation wave",[624,722,723,726],{},[379,724,725],{},"75%"," pursuing security vendor consolidation in 2022 (up from 29% in 2020)",[624,728,729],{},[387,730,731],{},[390,732,735],{"href":733,"rel":734},"https:\u002F\u002Fwww.gartner.com\u002Fen\u002Fnewsroom\u002Fpress-releases\u002F2022-09-12-gartner-survey-shows-seventy-five-percent-of-organizations-are-pursuing-security-vendor-consolidation-in-2022",[394],"[11]",[606,737,738,741,748],{},[624,739,740],{},"Complexity raises breach cost",[624,742,743,744,747],{},"Security-system complexity remains a ",[379,745,746],{},"top cost amplifier"," (with supply-chain breach and shadow AI)",[624,749,750],{},[387,751,752],{},[390,753,756],{"href":754,"rel":755},"https:\u002F\u002Fwww.ibm.com\u002Freports\u002Fdata-breach",[394],"[12]",[606,758,759,762,772],{},[624,760,761],{},"Inventory is a control",[624,763,764,765,768,769],{},"NYDFS ",[379,766,767],{},"23 NYCRR 500.13(a)"," — complete, accurate, documented asset inventory (owner, location, classification, support expiration, RTO, update frequency). Compliance date ",[379,770,771],{},"1 Nov 2025",[624,773,774,781],{},[387,775,776],{},[390,777,780],{"href":778,"rel":779},"https:\u002F\u002Fwww.law.cornell.edu\u002Fregulations\u002Fnew-york\u002F23-NYCRR-500.13",[394],"[13]",[387,782,783],{},[390,784,787],{"href":785,"rel":786},"https:\u002F\u002Fwww.dfs.ny.gov\u002Fsystem\u002Ffiles\u002Fdocuments\u002F2023\u002F11\u002Fcybersecurity_implementation_timeline_covered_entities.pdf",[394],"[14]",[789,790,792],"h3",{"id":791},"how-to-use-the-numbers","How to use the numbers",[425,794,795,804,813],{},[428,796,797,798,803],{},"Prefer the IBM\u002FPalo Alto Networks (PA) example ",[387,799,800],{},[390,801,409],{"href":407,"rel":802},[394]," set when talking to the C-suite about complexity as an operational blocker.",[428,805,806,807,812],{},"Prefer Gartner's 45-tool large-enterprise figure ",[387,808,809],{},[390,810,395],{"href":392,"rel":811},[394]," when talking to architects who will argue \"we don't have 83 products.\"",[428,814,815,816,821,826],{},"Prefer NYDFS 500.13 ",[387,817,818],{},[390,819,780],{"href":778,"rel":820},[394],[387,822,823],{},[390,824,787],{"href":785,"rel":825},[394]," when the buyer is in financial services or already treating inventory as an audit artefact. Do not collapse all three into one fake \"average.\"",[501,828,830],{"id":829},"_3-identifying-gaps-in-the-security-stack","3. Identifying gaps in the security stack",[375,832,833,834,837,838,841],{},"Tool count is not the same as coverage. Large estates pay for dozens of products and still cannot show, with evidence, ",[379,835,836],{},"which capabilities they have twice, which they do not have at all, and which they only have on the invoice",". That is the gap problem: overlap ",[453,839,840],{},"and"," holes, in the same undescribed portfolio.",[375,843,844],{},"Public research is blunt on this:",[425,846,847,861,878,926],{},[428,848,849,852,853,855,856,544],{},[379,850,851],{},"Fragmentation is an operational failure, not a housekeeping issue."," IBM IBV + Palo Alto Networks found ",[379,854,658],{}," of executives say fragmentation of security solutions limits the ability to deal with cyber threats; complexity is the biggest impediment to security operations",[387,857,858],{},[390,859,409],{"href":407,"rel":860},[394],[428,862,863,866,867,872,873,544],{},[379,864,865],{},"Consultancy products assume the gap\u002Foverlap picture does not already exist."," PwC Portfolio Rationalisation is sold as inventory + overlapping capabilities + unused functions + TCO",[387,868,869],{},[390,870,524],{"href":522,"rel":871},[394],". KPMG describes significant licensing fees for underutilized or duplicative tools never aligned back to strategy or architecture",[387,874,875],{},[390,876,566],{"href":564,"rel":877},[394],[428,879,880,883,884,887,888,891,892,895,896,899,900,903,904,907,908,915,922,923,544],{},[379,881,882],{},"Bought telemetry is not the same as coverage."," CardinalOps' 2025 ",[453,885,886],{},"State of SIEM Detection Risk"," (hundreds of production SIEMs) found enterprise SIEMs have detections for only about ",[379,889,890],{},"21–22%"," of MITRE ATT&CK techniques — leaving roughly ",[379,893,894],{},"78–79%"," of techniques without a mapped detection — while ingesting enough data to ",[453,897,898],{},"potentially"," cover ",[379,901,902],{},"90%+",". On average ",[379,905,906],{},"13%"," of existing detection rules are non-functional (misconfigured sources, missing fields)",[387,909,910],{},[390,911,914],{"href":912,"rel":913},"https:\u002F\u002Fwww.prnewswire.com\u002Fnews-releases\u002Fenterprise-siems-miss-79-of-mitre-attck-techniques-used-by-adversaries-according-to-cardinalops-5th-annual-report-302473779.html",[394],"[15]",[387,916,917],{},[390,918,921],{"href":919,"rel":920},"https:\u002F\u002Fcardinalops.com\u002Fwp-content\u002Fuploads\u002F2025\u002F06\u002F25-CardinalOps-2025-State-of-SIEM-Report.pdf",[394],"[16]",". That is a SIEM-specific measurement, not a whole-stack ATT&CK score — use it as evidence that ",[379,924,925],{},"licensed capability ≠ working coverage",[428,927,928,931,932,939,940,942,943,950,951,544],{},[379,929,930],{},"Vendor heatmaps are not an estate description."," CISA states ATT&CK can be used to identify defensive gaps and assess security tool capabilities",[387,933,934],{},[390,935,938],{"href":936,"rel":937},"https:\u002F\u002Fwww.cisa.gov\u002Fsites\u002Fdefault\u002Ffiles\u002F2023-01\u002FBest%20Practices%20for%20MITRE%20ATTCK%20Mapping.pdf",[394],"[17]",". AttackIQ's argument is the one ",[390,941,481],{"href":480}," already uses: untested coverage is unknown, not green",[387,944,945],{},[390,946,949],{"href":947,"rel":948},"https:\u002F\u002Fwww.attackiq.com\u002F2026\u002F03\u002F10\u002Fwhat-does-mitre-attack-coverage-really-mean\u002F",[394],"[18]",". A USENIX Security 2024 study of commercial endpoint rulesets found products that detect the same behaviour often do not even claim the same ATT&CK techniques",[387,952,953],{},[390,954,957],{"href":955,"rel":956},"https:\u002F\u002Fwww.usenix.org\u002Fsystem\u002Ffiles\u002Fusenixsecurity24-virkud.pdf",[394],"[19]",[375,959,960,963],{},[379,961,962],{},"How to use this."," Overlap is the commercial half of the gap (two invoices, one capability). Holes are the risk half (a NIST outcome or ATT&CK technique with no working control). ESProfiler has to show both against a framework the buyer already reports to — not against a vendor's marketing matrix.",[789,965,967],{"id":966},"frameworks-they-invest-against","Frameworks they invest against",[375,969,970,971,974],{},"Boards do not fund \"more tools.\" They fund ",[379,972,973],{},"risk reduction and compliance.",". The three languages that show up in large-enterprise cyber investment are NIST (outcomes), MITRE ATT&CK (adversary coverage), and an internal \u002F ISO-shaped control catalogue. None of them can be answered from a contract spreadsheet.",[976,977,979],"h4",{"id":978},"nist-cybersecurity-framework-20","NIST Cybersecurity Framework 2.0",[375,981,982,983,986,987,990],{},"NIST CSF 2.0 is the default board and regulator language for \"are we protected?\" It does ",[379,984,985],{},"not"," prescribe products. It requires organisations to describe ",[379,988,989],{},"outcomes",", then invest against the difference between where they are and where they need to be.",[425,992,993,1029,1041,1052],{},[428,994,995,998,999,1002,1003,1006,1007,1014,1021,1022,1025,1026,1028],{},[379,996,997],{},"Current Profile vs Target Profile is the official gap analysis."," NIST's process is: scope the profile → gather information (including practices and ",[453,1000,1001],{},"tools",") → create Current and Target Profiles → ",[379,1004,1005],{},"analyse the gaps and create a prioritized action plan"," (risk register, POA&M) → implement and update",[387,1008,1009],{},[390,1010,1013],{"href":1011,"rel":1012},"https:\u002F\u002Fnvlpubs.nist.gov\u002Fnistpubs\u002FCSWP\u002FNIST.CSWP.29.pdf",[394],"[20]",[387,1015,1016],{},[390,1017,1020],{"href":1018,"rel":1019},"https:\u002F\u002Fnvlpubs.nist.gov\u002Fnistpubs\u002FSpecialPublications\u002FNIST.SP.1301.pdf",[394],"[21]",". The investment case for cyber ",[453,1023,1024],{},"is"," that action plan. If ",[390,1027,481],{"href":480}," cannot evidence the Current Profile from the estate, the Target Profile is fiction.",[428,1030,1031,1034,1035,1040],{},[379,1032,1033],{},"Inventory of software and supplier services is an Identify outcome."," ID.AM-02: inventories of software, services, and systems are maintained. ID.AM-04: inventories of services provided by suppliers are maintained. ID.AM-08: systems, hardware, software, services, and data are managed throughout their life cycles",[387,1036,1037],{},[390,1038,1013],{"href":1011,"rel":1039},[394],". A security-tool portfolio that lives only in procurement is a failed Identify function.",[428,1042,1043,1046,1047,544],{},[379,1044,1045],{},"Risk assessment has to use threats, not invoices."," ID.RA-03: internal and external threats are identified and recorded. ID.RA-05: threats, vulnerabilities, likelihoods, and impacts are used to understand risk. ID.RA-06: risk responses are chosen, prioritized, planned, tracked, and communicated. GV.OV expects leadership to review cybersecurity strategy against those outcomes",[387,1048,1049],{},[390,1050,1013],{"href":1011,"rel":1051},[394],[428,1053,1054,1057,1058,1065],{},[379,1055,1056],{},"Where 800-53 is the overlay."," Organisations that assess against NIST SP 800-53 still need CM-8 (system component inventory), CA-2 \u002F CA-7 (control assessment and continuous monitoring), and RA-3 (risk assessment)",[387,1059,1060],{},[390,1061,1064],{"href":1062,"rel":1063},"https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F53\u002Fr5\u002Fupd1\u002Ffinal",[394],"[22]",". Same demand: a living inventory mapped to controls, not an annual spreadsheet.",[375,1067,1068,1071,1072,1074,1075,1078],{},[379,1069,1070],{},"Implication:"," NIST is how ",[390,1073,476],{"href":475}," defends ",[453,1076,1077],{},"investment",". Without a Current Profile grounded in what is actually licensed, deployed, and configured, every new purchase is \"another tool,\" not a gap close.",[976,1080,1082],{"id":1081},"mitre-attck","MITRE ATT&CK",[375,1084,1085,1086,1089,1090,1093],{},"ATT&CK is ",[379,1087,1088],{},"not a statute"," and not a certification. Treat it as the shared language for ",[453,1091,1092],{},"defensive coverage",", which CISOs and CISA expect you to be able to show. To the board, this is communicated as \"we are protected against these attacker's techniques.\"",[425,1095,1096,1119,1136],{},[428,1097,1098,1101,1102,1107,1108,1111,1112,544],{},[379,1099,1100],{},"CISA's stated uses"," include identifying defensive gaps, assessing security tool capabilities, organising detections, and validating mitigation controls",[387,1103,1104],{},[390,1105,938],{"href":936,"rel":1106},[394],". Eric Goldstein (CISA) on the Decider release: ATT&CK helps organisations ",[379,1109,1110],{},"prioritize cybersecurity controls and mitigations"," that reduce intrusions",[387,1113,1114],{},[390,1115,1118],{"href":1116,"rel":1117},"https:\u002F\u002Fwww.mitre.org\u002Fnews-insights\u002Fnews-release\u002Fcisa-releases-new-tool-mapping-adversary-behavior-mitre-attack",[394],"[23]",[428,1120,1121,1124,1125,1130,1135],{},[379,1122,1123],{},"The coverage problem is measurable."," CardinalOps (above) shows production SIEMs covering roughly a fifth of techniques, with broken rules inside the fifth they think they have",[387,1126,1127],{},[390,1128,914],{"href":912,"rel":1129},[394],[387,1131,1132],{},[390,1133,921],{"href":919,"rel":1134},[394],". That is the \"we bought detection\" gap.",[428,1137,1138,1141,1142,1145,1146,1148,1149,1152,1153,1156,1157,1160],{},[379,1139,1140],{},"Do not confuse vendor ATT&CK maps with estate coverage."," Vendor evaluations and product heatmaps describe a ",[453,1143,1144],{},"product in a lab or a brochure",". The question ",[390,1147,481],{"href":480}," asks is whether ",[453,1150,1151],{},"this estate",", with ",[453,1154,1155],{},"these"," products ",[453,1158,1159],{},"as configured",", covers the techniques that matter — and what residual risk a renewal cut opens.",[375,1162,1163,1165,1166,1168],{},[379,1164,1070],{}," ATT&CK is how ",[390,1167,481],{"href":480}," answers \"if I take this out, what gap am I opening?\" If the map is a vendor PDF, the answer is not defensible.",[976,1170,1172],{"id":1171},"internal-and-iso-shaped-control-sets","Internal and ISO-shaped control sets",[375,1174,1175,1176,1179],{},"Most 10,000+ employee buyers do not run NIST or ATT&CK alone. They run a ",[379,1177,1178],{},"home-grown control library"," in GRC (often ISO 27001 Annex A, 800-53, PCI, SOX, or a sector overlay, plus local policy). Investment still has to trace to that library.",[375,1181,1182,1183,1186,1187,1189],{},"That library is frequently ",[379,1184,1185],{},"not written in-house",". Accenture, KPMG, PwC, Deloitte, and peers sell the design of the control set as a packaged engagement: take public standards, crosswalk them, tailor to sector and risk appetite, and leave the organisation with a unified catalogue that ",[390,1188,476],{"href":475}," then reports against. Public service descriptions are explicit:",[425,1191,1192,1209,1234,1275],{},[428,1193,1194,1197,1198,1201,1202,544],{},[379,1195,1196],{},"PwC"," lists ",[379,1199,1200],{},"cybersecurity framework development"," as a named service: define objectives and scope, run a risk assessment, then develop the cybersecurity strategy and framework — using NIST CSF, ISO\u002FIEC 27001, COBIT, ITIL, and local regulation as inputs",[387,1203,1204],{},[390,1205,1208],{"href":1206,"rel":1207},"https:\u002F\u002Fwww.pwc.com\u002Fsg\u002Fen\u002Fservices\u002Frisk\u002Fdigital-solutions\u002Fcybersecurity-frameworks-and-maturity.html",[394],"[24]",[428,1210,1211,1214,1215,1218,1219,1226,1227,544],{},[379,1212,1213],{},"Deloitte"," sells ",[379,1216,1217],{},"controls and policy harmonization",": \"develop a unified control framework tailored to your risk and sector,\" plus multi-regulation gap assessments that visually map overlapping controls across ISO, NIST CSF, NIS2, DORA, SOC 2, and others",[387,1220,1221],{},[390,1222,1225],{"href":1223,"rel":1224},"https:\u002F\u002Fwww.deloitte.com\u002Fcz-sk\u002Fen\u002Fservices\u002Fconsulting\u002Fanalysis\u002Fcybersecurity-and-digital-compliance-advisory.html",[394],"[25]",". Their NIST practice likewise consults on which standards apply and runs gap analyses against the control and security requirements that overlap",[387,1228,1229],{},[390,1230,1233],{"href":1231,"rel":1232},"https:\u002F\u002Fwww.deloitte.com\u002Fus\u002Fen\u002Fservices\u002Fconsulting\u002Farticles\u002Fnist-compliance.html",[394],"[26]",[428,1235,1236,1239,1240,1243,1244,1251,1252,1255,1256,1263,1264,1267,1268,544],{},[379,1237,1238],{},"KPMG"," sells an ",[379,1241,1242],{},"IT risk and control framework"," \"integrated with the leading standards and laws and regulations\" (COBIT, SWIFT, NIST, SOC 2, ISO 27001, and more) so the organisation can design, construct, and operate that framework",[387,1245,1246],{},[390,1247,1250],{"href":1248,"rel":1249},"https:\u002F\u002Fkpmg.com\u002Fnl\u002Fen\u002Fservices\u002Faudit-and-assurance\u002Fit-assurance\u002Fit-risk-in-control.html",[394],"[27]",". Their NIS2 briefing argues for building and monitoring a ",[379,1253,1254],{},"unified control framework"," so the buyer can \"test once and comply to many\"",[387,1257,1258],{},[390,1259,1262],{"href":1260,"rel":1261},"https:\u002F\u002Fassets.kpmg.com\u002Fcontent\u002Fdam\u002Fkpmg\u002Fkr\u002Fpdf\u002F2023\u002Fkpmg-eu-nis2-report.pdf",[394],"[28]",". Technology Risk Advisory copy is the same motion: assess IT governance, cybersecurity, and control frameworks, then ",[379,1265,1266],{},"design tailored solutions"," aligned to NIST, ISO, and COBIT",[387,1269,1270],{},[390,1271,1274],{"href":1272,"rel":1273},"https:\u002F\u002Fkpmg.com\u002Fkw\u002Fen\u002Fservices\u002Fadvisory\u002Frisk-consulting\u002Ftechnology-risk-advisory.html",[394],"[29]",[428,1276,1277,1280,1281,1284,1285,1288,1289,1296,1303,1304,1307,1308,544],{},[379,1278,1279],{},"Accenture"," sells cyber strategy plus a ",[379,1282,1283],{},"security target operating model",": a blueprint that includes a ",[379,1286,1287],{},"controls review",", maturity and threat assessments, RACI, processes and capabilities, suppliers, and a three-to-five-year target state for evidence-based investment",[387,1290,1291],{},[390,1292,1295],{"href":1293,"rel":1294},"https:\u002F\u002Fwww.applytosupply.digitalmarketplace.service.gov.uk\u002Fg-cloud\u002Fservices\u002F425797577040796",[394],"[30]",[387,1297,1298],{},[390,1299,1302],{"href":1300,"rel":1301},"https:\u002F\u002Fwww.accenture.com\u002Fus-en\u002Fservices\u002Fcybersecurity\u002Fcyber-strategy",[394],"[31]",". IDC's GRC MarketScape notes Accenture's offering spans ",[379,1305,1306],{},"strategy, operating model design, platform implementation",", and managed services",[387,1309,1310],{},[390,1311,1314],{"href":1312,"rel":1313},"https:\u002F\u002Fwww.accenture.com\u002Fcontent\u002Fdam\u002Faccenture\u002Ffinal\u002Faccenture-com\u002Fdocument-4\u002FIDC-MarketScape-WW-Cybersecurity-GRC-Consulting-Services-2025-Vendor-Assessment-2025-Dec.pdf",[394],"[32]",[375,1316,1317,1318,1321,1322,1324,1325,1328],{},"The pattern: ISO \u002F NIST \u002F CIS \u002F COBIT \u002F sector rules are the ",[453,1319,1320],{},"ingredients",". The artefact ",[390,1323,481],{"href":480}," inherits is a consultancy-authored crosswalk with local IDs, KRIs, and a Statement of Applicability. When the same firm (or another) returns for a rationalisation or audit, they test the estate against ",[379,1326,1327],{},"that"," catalogue — not against a vendor heatmap.",[425,1330,1331,1349,1368],{},[428,1332,1333,1336,1337,1340,1341,1348],{},[379,1334,1335],{},"ISO\u002FIEC 27001:2022"," requires a Statement of Applicability (clause 6.1.3): which Annex A controls apply, whether they are implemented, and why any are excluded. Annex A ",[379,1338,1339],{},"5.9"," requires an inventory of information and other associated assets, with owners, kept current — software and services included",[387,1342,1343],{},[390,1344,1347],{"href":1345,"rel":1346},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F27001.html",[394],"[33]",". A stale tool list cannot support the SoA or the risk treatment plan.",[428,1350,1351,1354,1355,1360,1361,544],{},[379,1352,1353],{},"Internal catalogues"," (",[390,1356,1359],{"href":1357,"rel":1358},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSherwood_Applied_Business_Security_Architecture",[394],"SABSA-style"," traceability, custom \"cyber control libraries,\" board KRIs — whether written by the architects or by Accenture \u002F KPMG \u002F PwC \u002F Deloitte) make the same demand in local language: a control that cannot be traced to a risk is not required; two tools that trace to the same control are overlap; a required control with no working tool is a gap",[387,1362,1363],{},[390,1364,1367],{"href":1365,"rel":1366},"https:\u002F\u002Fsabsa.org\u002Fthe-attributers-blog-traceable\u002F",[394],"[34]",[428,1369,1370,1373,1374,1379,1384],{},[379,1371,1372],{},"Sector overlays"," (NYDFS 500.13 inventory, SOX 404 control evidence, NIS2 \u002F DORA) sit on top",[387,1375,1376],{},[390,1377,780],{"href":778,"rel":1378},[394],[387,1380,1381],{},[390,1382,1262],{"href":1260,"rel":1383},[394],". They do not replace NIST\u002FATT&CK\u002FISO; they are why the unified catalogue exists.",[375,1386,1387,1389,1390,1393],{},[379,1388,1070],{}," ESProfiler has to map the estate to ",[379,1391,1392],{},"the buyer's framework",", not only to vanilla NIST or ATT&CK. That framework is often a paid consultancy deliverable. The product problem is the same mapping job with a different left-hand column — and the next consultancy visit will use that column.",[501,1395,1397],{"id":1396},"_4-why-they-have-to-buy-esprofiler","4. Why they have to buy ESProfiler",[375,1399,1400,1401,1404,1405,544],{},"Buying another detection, identity, or GRC point product ",[379,1402,1403],{},"adds a row to the spreadsheet",". It does not produce the spreadsheet. It does not tell you what overlaps. It does not tell you what is missing. And it does not arrive in time for the notice period owned by ",[390,1406,490],{"href":489},[375,1408,1409],{},"The purchase is a necessity because three failures happen together in the ICP:",[789,1411,1413],{"id":1412},"renewal-decisions-happen-too-late","Renewal decisions happen too late",[375,1415,1416,1417,1420,1421,1428,1429,1431,1432,1439,1440,544],{},"The commercial clock is 30–90 days of notice, often with auto-renew as the default — ",[379,1418,1419],{},"69%"," of software contracts carry an auto-renew clause with a 30–90 day cancellation window",[387,1422,1423],{},[390,1424,1427],{"href":1425,"rel":1426},"https:\u002F\u002Fwww.bettercloud.com\u002Fmonitor\u002Fhow-to-avoid-automatic-software-renewals-and-save-big\u002F",[394],"[35]","; Gartner data cited by Varisource indicates ~",[379,1430,725],{}," of SaaS vendors rely on auto-renewal as retention",[387,1433,1434],{},[390,1435,1438],{"href":1436,"rel":1437},"https:\u002F\u002Fwww.varisource.com\u002Fblog\u002Fsoftware-renewal-negotiation-guide-best-practices",[394],"[36]",". Vendors track that deadline; buyers often do not",[387,1441,1442],{},[390,1443,1446],{"href":1444,"rel":1445},"https:\u002F\u002F2-data.com\u002Fknowledge-hub\u002Fsoftware-contract-auto-renewal-traps-the-commercial-clauses-that-are-costing-enterprises-millions-every-year\u002F",[394],"[37]",[375,1448,1449,1450,1457,1458,1460,1461,1463,1464,1466,1467,1471],{},"Ownership is fragmented across procurement, finance, IT, and security",[387,1451,1452],{},[390,1453,1456],{"href":1454,"rel":1455},"https:\u002F\u002Fsysgenpro.com\u002Fautomation\u002Fsaas-procurement-process-automation-to-reduce-renewal-delays-and-approval-friction",[394],"[38]",". By the time ",[390,1459,481],{"href":480}," can answer \"keep \u002F cut \u002F renegotiate,\" leverage is gone and the stack grows by inertia. The specific ",[390,1462,490],{"href":489}," ↔ ",[390,1465,481],{"href":480}," 90-day scramble is a ",[390,1468,1470],{"href":1469},"..\u002Fdesign\u002Fpersonas\u002F04-procurement-officer-paige#what-is-evidenced-vs-synthesized","synthesis","; the clock, the clause, and the late answer are not.",[789,1473,1475],{"id":1474},"there-there-is-no-clear-picture-of-capability-overlap","There There is no clear picture of capability overlap",[375,1477,1478,1479,1482,1483,1488,1493,1494,1496,1497,1502,1503,1505,1506,1511],{},"Two products can satisfy the same NIST outcome or the same ATT&CK technique, both still paid for. PwC and KPMG sell the assessment ",[453,1480,1481],{},"because"," that picture is not in the estate",[387,1484,1485],{},[390,1486,524],{"href":522,"rel":1487},[394],[387,1489,1490],{},[390,1491,554],{"href":552,"rel":1492},[394],". Consolidation programmes (",[379,1495,696],{}," pursuing vendor consolidation in 2025",[387,1498,1499],{},[390,1500,715],{"href":713,"rel":1501},[394],"; ",[379,1504,725],{}," in 2022",[387,1507,1508],{},[390,1509,735],{"href":733,"rel":1510},[394],") cannot be executed safely if \"duplicate\" is an opinion rather than a mapped capability.",[789,1513,1515],{"id":1514},"there-are-gaps-in-portfolio-capability-not-just-extra-tools","There are gaps in portfolio capability, not just extra tools",[375,1517,1518,1519,1524,1529,1534],{},"CardinalOps, IBM\u002FPANW fragmentation, and NIST's Current vs Target process all describe the other side of sprawl: outcomes and techniques with no working control, or a control that exists only as a licence",[387,1520,1521],{},[390,1522,921],{"href":919,"rel":1523},[394],[387,1525,1526],{},[390,1527,409],{"href":407,"rel":1528},[394],[387,1530,1531],{},[390,1532,1020],{"href":1018,"rel":1533},[394],". Cutting spend without that map opens a hole. Adding spend without that map buys a second copy of something they already have — or a product that does not close the Target Profile gap they are funding.",[375,1536,1537],{},"ESProfiler is necessary when all of the following are true at once — which they are, for the ICP:",[1539,1540,1541,1547,1565,1571,1598],"ol",{},[428,1542,1543,1546],{},[379,1544,1545],{},"Someone external will ask."," Consultancy, internal audit, regulator, board, or CFO. The question is always some version of: what do we have, what does it cover, where does it overlap, where are the gaps, what can we cut.",[428,1548,1549,1552,1553,1555,1556,1558,1559,1561,1562,1564],{},[379,1550,1551],{},"The current system of record is not a system."," Contracts sit with ",[390,1554,490],{"href":489},". Ground truth sits with ",[390,1557,485],{"href":484},". The board narrative sits with ",[390,1560,481],{"href":480},". ",[390,1563,476],{"href":475}," is accountable for a number he cannot verify.",[428,1566,1567,1570],{},[379,1568,1569],{},"The renewal window is shorter than the analysis."," A Current-vs-Target or ATT&CK coverage exercise that takes weeks will miss a 30–90 day notice period. Point-in-time consulting expires the Monday after it lands; renewals do not wait for the next engagement.",[428,1572,1573,1576,1577,1582,1583,1588,1593,544],{},[379,1574,1575],{},"Regulation and frameworks are moving inventory from preference to control."," NYDFS 500.13 is the sharpest public example",[387,1578,1579],{},[390,1580,780],{"href":778,"rel":1581},[394],". NIST CSF Profiles, ISO 27001 SoA \u002F A.5.9, and ATT&CK-as-coverage-language are how the same demand shows up in investment and audit",[387,1584,1585],{},[390,1586,1020],{"href":1018,"rel":1587},[394],[387,1589,1590],{},[390,1591,1347],{"href":1345,"rel":1592},[394],[387,1594,1595],{},[390,1596,938],{"href":936,"rel":1597},[394],[428,1599,1600,1603,1604,1606,1607,544],{},[379,1601,1602],{},"Spend cannot be cut — or increased — safely without coverage evidence."," Consolidation without overlap\u002Fgap mapping is how ",[390,1605,476],{"href":475}," gets unpicked in the board. A new purchase that is not traced to a Target Profile gap ",[453,1608,1609],{},"is more sprawl",[375,1611,1612,1613,577],{},"What ESProfiler has to be, therefore, is the ",[379,1614,1615],{},"living description of the estate",[425,1617,1618,1621,1624,1630,1637],{},[428,1619,1620],{},"what is licensed vs deployed vs in use",[428,1622,1623],{},"what it actually does (vs what was bought)",[428,1625,1626,1627],{},"where capabilities ",[379,1628,1629],{},"overlap",[428,1631,1632,1633,1636],{},"where the ",[379,1634,1635],{},"gaps"," are against NIST \u002F ATT&CK \u002F the internal control set",[428,1638,1639,1640,1643],{},"which renewals can be killed or renegotiated ",[379,1641,1642],{},"in time",", without opening a gap",[375,1645,1646,1647,1651],{},"If a feature does not help produce that picture — or act on it inside a ",[390,1648,1650],{"href":1649},"..\u002Fdesign\u002Fdesign-thinking#the-decision-window--how-the-four-interact-over-time","decision window"," — it is not the problem we are solving.",[501,1653,1655],{"id":1654},"_5-how-this-lands-with-personas","5. How this lands with personas",[600,1657,1658,1668],{},[603,1659,1660],{},[606,1661,1662,1665],{},[609,1663,1664],{},"Persona",[609,1666,1667],{},"Why it is a necessity for them",[619,1669,1670,1679,1694,1703],{},[606,1671,1672,1676],{},[624,1673,1674],{},[390,1675,476],{"href":475},[624,1677,1678],{},"He is accountable for a number and a posture he did not build. Consultancy and the board will unpick a guess. He needs one page that survives the room.",[606,1680,1681,1685],{},[624,1682,1683],{},[390,1684,481],{"href":480},[624,1686,1687,1688,1690,1691,1693],{},"He has to walk into every renewal with a costed recommendation. Without an estate description he is always late to the clock owned by ",[390,1689,490],{"href":489}," and exposed when ",[390,1692,476],{"href":475}," is.",[606,1695,1696,1700],{},[624,1697,1698],{},[390,1699,485],{"href":484},[624,1701,1702],{},"She already knows fragments of ground truth. The necessity is making that knowledge evidenced, repeatable, and defensible — not spending three weeks per category reconstructing it from consoles.",[606,1704,1705,1709],{},[624,1706,1707],{},[390,1708,490],{"href":489},[624,1710,1711],{},"Notice periods do not slip because Security is still investigating. She needs an evidenced keep \u002F cut \u002F renegotiate answer while leverage still exists.",[501,1713,1715],{"id":1714},"sources","Sources",[789,1717,1719],{"id":1718},"security-stack-size","Security stack size",[425,1721,1722,1734,1747,1762],{},[428,1723,1724,1727,1728,1731,1732,679],{},[390,1725,395],{"href":392,"rel":1726},[394]," Gartner, ",[453,1729,1730],{},"Top Cybersecurity Trends for 2025"," — average ",[379,1733,678],{},[428,1735,1736,1739,1740,1731,1743,1746],{},[390,1737,402],{"href":400,"rel":1738},[394]," NHIMG \u002F Securiti, ",[453,1741,1742],{},"Security tool sprawl and context loss",[379,1744,1745],{},"61"," security tools",[428,1748,1749,1752,1753,1756,1757,632,1759,1761],{},[390,1750,409],{"href":407,"rel":1751},[394]," IBM IBV + Palo Alto Networks, ",[453,1754,1755],{},"Capturing the cybersecurity dividend"," (Jan 2025) — ",[379,1758,631],{},[379,1760,635],{}," vendors; 52% say fragmentation blocks threat response",[428,1763,1764,1767,1768,1770],{},[390,1765,416],{"href":414,"rel":1766},[394]," IBM IBV, ",[453,1769,1755],{}," (PDF download)",[789,1772,511],{"id":1773},"_1-consultancy-pressure-1",[425,1775,1776,1782,1788,1794,1800],{},[428,1777,1778,1781],{},[390,1779,524],{"href":522,"rel":1780},[394]," PwC Netherlands — Portfolio Rationalisation",[428,1783,1784,1787],{},[390,1785,543],{"href":541,"rel":1786},[394]," PwC Canada — Portfolio Rationalization (Microsoft alliance)",[428,1789,1790,1793],{},[390,1791,531],{"href":529,"rel":1792},[394]," Microsoft AppSource — PwC Portfolio Rationalisation",[428,1795,1796,1799],{},[390,1797,554],{"href":552,"rel":1798},[394]," KPMG — Cyber cost optimization",[428,1801,1802,1805,1806,1808],{},[390,1803,566],{"href":564,"rel":1804},[394]," KPMG — ",[453,1807,558],{}," (PDF)",[789,1810,588],{"id":1811},"_2-tool-sprawl-1",[425,1813,1814,1828,1837,1847,1853],{},[428,1815,1816,1819,1820,1822,1823,1825,1826,701],{},[390,1817,715],{"href":713,"rel":1818},[394]," Bitdefender citing Gartner, ",[453,1821,707],{}," (June 2025) — ",[379,1824,696],{}," consolidating; ",[379,1827,700],{},[428,1829,1830,1833,1834,1836],{},[390,1831,735],{"href":733,"rel":1832},[394]," Gartner newsroom (Sep 2022) — ",[379,1835,725],{}," pursuing security vendor consolidation",[428,1838,1839,1842,1843,1846],{},[390,1840,756],{"href":754,"rel":1841},[394]," IBM — ",[453,1844,1845],{},"Cost of a Data Breach Report 2025"," — complexity as a top cost amplifier",[428,1848,1849,1852],{},[390,1850,780],{"href":778,"rel":1851},[394]," 23 NYCRR 500.13 — asset management inventory as a control",[428,1854,1855,1858],{},[390,1856,787],{"href":785,"rel":1857},[394]," NYDFS — implementation timeline for covered entities (PDF)",[789,1860,830],{"id":1861},"_3-identifying-gaps-in-the-security-stack-1",[425,1863,1864,1870,1880,1889,1898],{},[428,1865,1866,1869],{},[390,1867,914],{"href":912,"rel":1868},[394]," CardinalOps via PR Newswire — enterprise SIEMs miss ~79% of ATT&CK techniques",[428,1871,1872,1875,1876,1879],{},[390,1873,921],{"href":919,"rel":1874},[394]," CardinalOps — ",[453,1877,1878],{},"5th Annual State of SIEM Detection Risk"," (2025, PDF) — ~21–22% coverage; ~13% broken rules",[428,1881,1882,1885,1886,1808],{},[390,1883,938],{"href":936,"rel":1884},[394]," CISA — ",[453,1887,1888],{},"Best Practices for Mapping to MITRE ATT&CK",[428,1890,1891,1894,1895],{},[390,1892,949],{"href":947,"rel":1893},[394]," AttackIQ — ",[453,1896,1897],{},"What Does MITRE ATT&CK Coverage Really Mean?",[428,1899,1900,1903],{},[390,1901,957],{"href":955,"rel":1902},[394]," USENIX Security 2024 — Virkud et al., endpoint products and ATT&CK labelling",[976,1905,979],{"id":1906},"nist-cybersecurity-framework-20-1",[425,1908,1909,1915,1921],{},[428,1910,1911,1914],{},[390,1912,1013],{"href":1011,"rel":1913},[394]," NIST CSWP 29 — CSF 2.0 (Current \u002F Target Profiles; ID.AM; ID.RA)",[428,1916,1917,1920],{},[390,1918,1020],{"href":1018,"rel":1919},[394]," NIST SP 1301 — Creating and Using Organizational Profiles",[428,1922,1923,1926],{},[390,1924,1064],{"href":1062,"rel":1925},[394]," NIST SP 800-53 Rev. 5 — CM-8, CA-2 \u002F CA-7, RA-3",[976,1928,1082],{"id":1929},"mitre-attck-1",[425,1931,1932],{},[428,1933,1934,1937],{},[390,1935,1118],{"href":1116,"rel":1936},[394]," MITRE \u002F CISA — Decider release",[976,1939,1172],{"id":1940},"internal-and-iso-shaped-control-sets-1",[425,1942,1943,1949,1955,1961,1967,1973,1979,1985,1991,1997,2003],{},[428,1944,1945,1948],{},[390,1946,1208],{"href":1206,"rel":1947},[394]," PwC Singapore — Cybersecurity framework development",[428,1950,1951,1954],{},[390,1952,1225],{"href":1223,"rel":1953},[394]," Deloitte — unified control framework tailored to risk and sector",[428,1956,1957,1960],{},[390,1958,1233],{"href":1231,"rel":1959},[394]," Deloitte — NIST adoption and compliance",[428,1962,1963,1966],{},[390,1964,1250],{"href":1248,"rel":1965},[394]," KPMG Netherlands — IT Risk in Control",[428,1968,1969,1972],{},[390,1970,1262],{"href":1260,"rel":1971},[394]," KPMG — NIS2 briefing (PDF) — unified control framework; test once, comply to many",[428,1974,1975,1978],{},[390,1976,1274],{"href":1272,"rel":1977},[394]," KPMG — Technology Risk Advisory",[428,1980,1981,1984],{},[390,1982,1295],{"href":1293,"rel":1983},[394]," Accenture UK — Security Target Operating Model (G-Cloud)",[428,1986,1987,1990],{},[390,1988,1302],{"href":1300,"rel":1989},[394]," Accenture — Cyber Strategy",[428,1992,1993,1996],{},[390,1994,1314],{"href":1312,"rel":1995},[394]," IDC MarketScape excerpt via Accenture (PDF) — GRC consulting 2025–2026",[428,1998,1999,2002],{},[390,2000,1347],{"href":1345,"rel":2001},[394]," ISO\u002FIEC 27001:2022 — SoA (6.1.3); Annex A 5.9",[428,2004,2005,2008],{},[390,2006,1367],{"href":1365,"rel":2007},[394]," SABSA — control traceability",[789,2010,1397],{"id":2011},"_4-why-they-have-to-buy-esprofiler-1",[425,2013,2014,2023,2032,2038],{},[428,2015,2016,2019,2020,2022],{},[390,2017,1427],{"href":1425,"rel":2018},[394]," BetterCloud — auto-renewals; ",[379,2021,1419],{},"; 30–90 day notice",[428,2024,2025,2028,2029,2031],{},[390,2026,1438],{"href":1436,"rel":2027},[394]," Varisource citing Gartner — ~",[379,2030,725],{}," of SaaS vendors rely on auto-renewal",[428,2033,2034,2037],{},[390,2035,1446],{"href":1444,"rel":2036},[394]," 2-Data — auto-renewal traps; vendor tracks the notice deadline",[428,2039,2040,2043],{},[390,2041,1456],{"href":1454,"rel":2042},[394]," Sysgenpro — renewal delays and fragmented ownership",{"title":2045,"searchDepth":2046,"depth":2046,"links":2047},"",2,[2048,2049,2050,2054,2057,2062,2063],{"id":503,"depth":2046,"text":504},{"id":510,"depth":2046,"text":511},{"id":587,"depth":2046,"text":588,"children":2051},[2052],{"id":791,"depth":2053,"text":792},3,{"id":829,"depth":2046,"text":830,"children":2055},[2056],{"id":966,"depth":2053,"text":967},{"id":1396,"depth":2046,"text":1397,"children":2058},[2059,2060,2061],{"id":1412,"depth":2053,"text":1413},{"id":1474,"depth":2053,"text":1475},{"id":1514,"depth":2053,"text":1515},{"id":1654,"depth":2046,"text":1655},{"id":1714,"depth":2046,"text":1715,"children":2064},[2065,2066,2067,2068,2069],{"id":1718,"depth":2053,"text":1719},{"id":1773,"depth":2053,"text":511},{"id":1811,"depth":2053,"text":588},{"id":1861,"depth":2053,"text":830},{"id":2011,"depth":2053,"text":1397},"Large enterprises spend millions on cyber and run huge tool portfolios — and still cannot see what they have, where it overlaps, where it has gaps, how it is configured, or how well they are protected.","md",null,{},true,{"title":47,"description":2070},"Vlhb0vpJ1PEj_wubn01onW_F90pi-8BIt408fyWEWgM",[2078,2079],{"title":43,"path":44,"stem":45,"description":2045,"children":-1},{"title":51,"path":52,"stem":53,"description":2045,"children":-1},1790076745456]