Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Platformisation or platform theatre? Navigating cyber consolidation | Computer Weekly

By Computer Weekly by By Computer Weekly
March 25, 2026
Home Uncategorized
Share on FacebookShare on Twitter


The consolidation wave in enterprise security is real, and the business case is compelling. A January 2025 report from IBM and Palo Alto Networks found that organisations manage an average of 83 security solutions from 29 vendors. The complexity is staggering – and attackers exploit the gaps between those tools. The push to rationalise is not just about budget; it’s about coherence.

But the allure of a unified platform brings its own hazard. Not every vendor offering “end-to-end visibility” is delivering genuine integration. And even when they are, consolidation can silently introduce the very risk it promises to eliminate: a single point of catastrophic failure.

Spotting integration theatre

Integration theatre is the cyber security equivalent of a Potemkin village: application programming interfaces (APIs) stitched together with no shared data model, dashboards that aggregate alerts without correlating them, and licensing bundles that market themselves as platforms while operating as loosely coupled point solutions.

The diagnostic questions I ask vendors are deliberately outcome-focused, not feature-focused. Does threat detection in one module automatically trigger a policy change in another, without human intervention? Does a compromise of an identity trigger endpoint quarantine in under a minute? Can you demonstrate bi-directional data flow between your extended detection and response (XDR), security information and event management (SIEM) and cloud security posture management in a live environment – not a sales demo? Genuine platforms reduce mean time to detect (MTTD) and mean time to respond (MTTR). Theatre does not.

A further tell: ask how the vendor handles failure of a single module. If the answer is that the platform degrades gracefully, probe it. If the whole stack collapses, it was never truly integrated – it was just co-located.

The CrowdStrike warning shot

On 19 July 2024, a faulty configuration update to CrowdStrike’s Falcon sensor brought down approximately 8.5 million Windows devices globally – airlines, hospitals, broadcasters, 911 call centres. Fortune 500 losses were estimated at $5.4bn (£4.03bn). Delta Air Lines alone reported $500m in damages. This was not a cyber attack. It was a platform failure.

For organisations that had consolidated endpoint protection, identity threat detection and cloud security posture management into one vendor stack, the incident was not a localised disruption – it was organisational paralysis. The lesson, as one post-incident analysis framed it, is not to avoid consolidation. It is to understand what you are trading away: architectural redundancy and failure isolation in exchange for operational simplicity.

Governance and architectural safeguards

If you are consolidating, the governance framework must be commensurate with the concentration of risk. The Financial Conduct Authority’s (FCA’s) post-CrowdStrike guidance is instructive here: by March 2025, firms in scope of operational resilience rules were required to demonstrate they could sustain important business services in severe but plausible failure scenarios. That is the right standard of thinking for any CISO evaluating platformisation.

My approach rests on three pillars. First, layered redundancy: no single vendor should own more than two adjacent security domains without a contractual and technical fallback. Staged rollouts, canary deployments and automated rollback mechanisms are non-negotiable SLA requirements, not optional extras.

Second, zero-trust architecture: platformisation does not exempt you from zero trust principles. Compartmentalise blast radius. Even within a unified platform, segment data flows so a compromise or failure in one domain cannot propagate laterally.

Third, continuous third-party risk oversight: the WEF Global Cybersecurity Outlook 2025 explicitly flags supply chain vulnerabilities as a systemic amplifier. Your platform vendor is a critical third party. Contractual rights to audit, independent pentesting, escrow arrangements and documented exit strategies are governance essentials, not aspirations.

The board conversation

The WEF notes that boards are no longer asking whether they are secure – they are asking whether they are resilient. Platformisation can absolutely support resilience. But only if the CISO insists on genuine integration over marketing, builds governance structures proportionate to the concentration risk created, and retains the architectural independence to survive vendor failure.

Consolidation is a strategy. Platform theatre is a liability. Know the difference before you sign.

John Bruce is CISO at Quorum Cyber, an Edinburgh-based managed security services provider and Microsoft partner.



Source link

By Computer Weekly

By Computer Weekly

Next Post
AWS Data Center ‘Disrupted’ By Drones In Middle East; Client Workloads Being Migrated

AWS Data Center ‘Disrupted’ By Drones In Middle East; Client Workloads Being Migrated

Recommended.

The 0 oil playbook: How pro investors are investing around this energy shock

The $100 oil playbook: How pro investors are investing around this energy shock

March 9, 2026
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

November 30, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio