* LASN_picture_logo.jpg

 

Locks and Security News: your weekly locks and security industry newsletter
29th July 2026 Issue no. 812

Your industry news - first

 

We strongly recommend viewing Locks and Security News full size in your web browser. Click our masthead above to visit our website version.

 

Search
English French Spanish Italian German Dutch Russian Mandarin


The security stack reckoning: more tools are creating more risks

A growing number of organisations are suffering from security tool sprawl according to KPMG's 2026 Cybersecurity & Technology Risk Survey, that found  only 14% of organisations have reached an advanced, predictive level of vulnerability management. 

Infrastructure complexity and fragmented security systems remain the biggest obstacles.

Mark Appleton, Group Lead Vendor Ecosystem Development at ALSO Group, explains why organisations need to move away from buying more tools and instead focus on security consolidation and platformisation.

Tool sprawl often starts with good intentions - IT leaders plugging operational gaps with a myriad of products. However over time, this leads to dozens of tools which might not even work well together. A KPMG 2026 Cybersecurity & Technology Risk Survey found that even as security budgets keep climbing, most organisations remain stuck in a reactive posture, buying more tools without gaining real clarity. 

“Businesses might add a tool to meet a compliance need and a second in response to a breach but gradually tool sprawl creeps in and snowballs into a costly, multi-vendor ecosystem,” said Mark Appleton, Group Lead Vendor Ecosystem Development at ALSO Group. “The impact is felt the most by IT and security teams who begin firefighting against various dashboards, reconciling overlapping alerts, and navigating inconsistent reporting processes.”

Disparate tools across systems and networks can create a slow manual grind for employees while burying real threats under layers of noise. Overwhelmed by excessive notifications, urgency with security teams decreases and real threats begin to blend into the noise.

“It's telling that KPMG's survey found only 14% of organisations have reached an advanced, predictive state of vulnerability management, with IT infrastructure complexity and fragmented security systems cited as the two biggest barriers against this.

“Each security tool also has their own alerts which demand attention but these signals arrive faster than they can investigate them with a lack of context, making it harder to separate meaningful vulnerabilities from background noise. Layer on fatigue from triaging these alerts, and businesses are responding slower and spending less time on impactful operations.”

For organisations, especially those that require specialist security tools, Appleton points to a consolidated approach as the first step.

“Instead of asking which tools they want, security leaders should be identifying the outcomes they are trying to achieve. For many businesses, this starts with building a security strategy that prioritises consolidation over accumulation.

“Security consolidation is often positioned as a financial conversation but it can improve signal correlation, reduce alert noise and simplify governance. This reduces vendor load and maintenance overhead so you only pay for what you need.” 

Reducing the number of tools is only the first step. Owning fewer products doesn't guarantee that data flows freely between teams or that alerts are correlated automatically. This is where platformisation becomes relevant.

“Platformisation is a logical next step toward reducing complexity while strengthening overall security posture,” said Appleton. “To put it simply, consolidation reduces the number of separate applications an organisation has to manage. Platformisation goes a step further by bringing security capabilities onto a shared architecture, where network and data communicate and create a unified operational picture.”

This builds an expectation on resellers to provide an integrated security solution that works across cloud, on-premise, identity systems, data stores and more. This is where a strong distributor can help to simplify security procurement. 

“Different customers require different solutions to meet their business priorities. Distributors can provide access to emerging cybersecurity vendors and technologies, and curate portfolios that complement each other. They also validate interoperability between products so partners can confidently design multi-tool strategies. This reduces complexity and risk for both resellers and customers.”

Appleton concluded, “The cybersecurity conversation has focused on adding the newest tools but this only creates fragmented visibility. The security stack that succeeds the best is the one that is smartly built by consolidating overlapping technologies and embracing platform-based approaches. It's time to move from managing tools to managing risk.”

About ALSO – The Technology Provider 

ALSO Holding AG (ALSN.SW) (Emmen/Switzerland) is the biggest technology provider in Europe, currently active in 31 European countries and in many countries worldwide via PaaS partners. The ALSO ecosystem comprises a total potential of more than 135,000 resellers, to whom we offer hardware, software and IT services from more than 800 vendors in over 1,570 product categories. In the spirit of the circular economy, the company provides all services from provision to remanufacturing from a single source.

The business activities comprise the areas of Supply, Solutions and Service. Supply stands for the transactional provisioning of hardware and software. Solutions support customers in the development of customised IT solutions. Subscription-based cloud offerings as well as digital platforms for IoT, cybersecurity, virtualisation and AI are at the heart of the Service division. The main shareholder is the Droege Group, Düsseldorf, Germany. Further information can be found at https://also.com.

29th July 2026




© Locks and Security News 2026.
Subscribe | Unsubscribe | Hall of Fame | Cookies | Sitemap