By Mark Mitchell, CTO at CWSI
The latest Forrester Total Economic Impact™ study, commissioned by Microsoft, reinforces a trend I’ve seen across the industry for some time: organisations that simplify their security ecosystem are often better positioned to improve both resilience and return on investment.
The headline figures are compelling. The composite organisation in the study achieved a 124% return on investment, recovered its costs in less than six months, and reduced technology expenditure over a three-year period.
But the numbers aren’t the story.
What stood out was the approach. These organisations didn’t pursue consolidation for consolidation’s sake. They first gained a clear understanding of the security capabilities they already had, identified where products overlapped, and only retired existing technologies once equivalent capabilities had been successfully implemented and validated. That’s a fundamentally different mindset.
Too often, security conversations focus on what organisations need to buy next. In reality, many aren’t lacking security tools, they’re lacking the visibility, time and operational capacity to extract full value from the investments they’ve already made. Consolidation, when approached strategically, isn’t about reducing the number of vendors. It’s about creating a security architecture that’s easier to manage, more effective to operate, and better equipped to respond to an increasingly complex threat landscape.
Complexity is rarely a strategy
Few organisations set out to create a complex security environment. More often, complexity is the by-product of growth. A new threat demands a specialist solution. A business acquisition introduces another technology stack. Different teams make decisions to solve immediate challenges. Procurement cycles don’t align. Over time, a security estate evolves into a collection of capable tools that were never designed to work as a cohesive whole.
In isolation, each decision makes sense. Collectively, they can create an environment that’s harder to manage, more difficult to operate and increasingly challenging to optimise.
That’s why consolidation shouldn’t be viewed as a cost-cutting exercise. It’s an opportunity to step back and ask a more strategic question: Are we getting the full value from the security capabilities we’ve already invested in?
This is a conversation we have regularly with organisations. It’s not uncommon to find third-party tools delivering capabilities that already exist within their Microsoft licensing. In some cases, those specialist products remain the right choice because they provide differentiated functionality or meet specific operational requirements.
But just as often, overlapping tools remain in place simply because Microsoft’s native capabilities have never been fully implemented, configured or operationalised.
Capability doesn’t equal protection
One of the biggest misconceptions in cybersecurity is that owning a capability is the same as benefiting from it. It isn’t.
Whether it’s part of Microsoft Security or any other platform, a security control only delivers value when it’s properly configured, integrated into the wider environment and embedded into day-to-day operations. If teams don’t trust it, understand it or actively use it, its potential remains largely unrealised.
That’s why I think the term licence optimisation undersells what’s really at stake. This isn’t simply an exercise in reducing software costs or rationalising vendors. It’s about ensuring the security capabilities you’ve already invested in are delivering the outcomes they were intended to achieve.
The cost savings that often follow are valuable, but they’re rarely the primary objective. The greater benefit is a security environment that’s simpler to operate, easier to manage and more resilient because teams have confidence in the controls they’re relying on.
Achieving that doesn’t happen overnight. It requires careful planning, rigorous testing and the discipline to validate replacement capabilities before legacy tools are retired.
Better questions lead to better decisions
One of the most valuable aspects of the Forrester study isn’t the financial modelling, it’s the validation of a conversation many security leaders are already having: How do we build a security environment that’s both effective and sustainable?
The answer isn’t simply to consolidate for the sake of reducing vendors, nor is it to assume every specialist tool should be replaced by a native capability. The right strategy depends on understanding your own environment.
That starts with asking better questions:
- Which security capabilities are already available through your existing investments?
- Which are fully deployed and delivering value today?
- Where do third-party tools genuinely provide differentiated capability, and where do they simply duplicate functionality that’s already available?
- Most importantly, can replacement controls demonstrate the same level of protection before anything is retired?
Those aren’t procurement questions, they’re strategic ones.
Organisations that take the time to answer them are far more likely to build a security architecture that’s resilient, operationally efficient and aligned to their risk profile. They move beyond managing a collection of security products towards managing a coherent security capability.
Ultimately, effective cybersecurity isn’t measured by the number of tools in your environment. It’s measured by how well those capabilities work together, how confidently your teams can operate them, and how effectively they help the business manage risk.
That’s where the real opportunity lies: not in buying more technology, but in extracting greater value from the investments you’ve already made.
The sequence is as important as the strategy
Consolidation isn’t a procurement exercise. It’s a security transformation programme.
That distinction matters because the order in which decisions are made can have a direct impact on an organisation’s security posture. When cost reduction becomes the primary objective, it’s easy to focus on identifyingoverlapping products and retiring them as quickly as possible.
The organisations highlighted in the Forrester study took a more measured approach. They didn’t remove existing controls until they had confidence that replacement capabilities were fully implemented, integrated into day-to-day operations and capable of delivering the level of protection they required. It’s a simple principle, but one that’s often overlooked.
A capability doesn’t become operational simply because it’s included in a licence. It must be configured correctly, aligned with existing processes, deployed into your environment, understood by the teams responsible for managing it and validated in a live environment before it can be relied upon.
Approached this way, consolidation becomes less about replacing one technology with another and more about building confidence in your security architecture. The goal isn’t to do more with less. It’s to ensure every control has a clear purpose, every capability is delivering value, and every change strengthens – not compromises – your overall resilience.
Strong security foundations enable better AI outcomes
The conversation about security consolidation has become even more relevant as organisations accelerate their adoption of AI.
Whether it’s Microsoft Security Copilot, Microsoft 365 Copilot or other AI-powered services, their effectiveness depends on something far less visible than the technology itself: the strength of the security foundations beneath them.
AI amplifies what’s already in place. Strong identity controls, effective data governance and well-managed access policies enable organisations to adopt AI with greater confidence. Weak foundations, on the other hand, allow risk and complexity to scale just as quickly.
That’s why I don’t see the Forrester study as simply a case for consolidation. I see it as a reminder that every investment made in simplifying and strengthening your security architecture creates value beyond today’s operational challenges. It improves visibility, reduces complexity and establishes the foundations needed to adopt emerging technologies with confidence.
The organisations that will realise the greatest value from AI won’t necessarily be those that adopt it first. They’ll be the ones that have built the operational maturity and security resilience to use it effectively.
In that sense, consolidation isn’t the destination. It’s one of the steps that helps organisations prepare for what’s next.
Where to go from here
If your organisation is already invested in Microsoft Security, this is a good opportunity to take stock before introducing additional tools or renewing existing ones.
Start by understanding the capabilities you already have, where overlap exists and which controls are mature enough to play a greater role in your security strategy. The goal isn’t to consolidate for the sake of it, it’s to make informed decisions based on the needs of your organisation and the security outcomes you’re trying to achieve.
To help with that process, we’ve created the Switch On Before You Switch Off playbook. It provides a practical framework for assessing your current security capabilities, identifying opportunities to reduce unnecessary complexity and approaching consolidation with confidence.
