9 June 2026
Too many tools, too few suppliers
Consolidation does not reduce risk. It moves it, concentrates it, and turns sprawl you managed into a dependency you cannot unwind.
We spent ten years being told we had too many security tools.
We're about to learn the price of having too few suppliers.
Somewhere this year, a vendor you depend on was acquired - and the terms you negotiated changed hands with it. You weren't in the room. You'll meet the new arrangement at renewal.
The headline deals are staggering. Palo Alto Networks closed its roughly $25 billion acquisition of CyberArk this February; Google completed the largest security purchase in history, $32 billion for Wiz. The logic is hard to fault - the average enterprise was running more than sixty tools, and one platform is cleaner than a patchwork held together by hope and integrations.
But I've come to read consolidation differently. It doesn't reduce risk. It moves it, and concentrates it. The sprawl you used to manage becomes a dependency you can't unwind.
We have already seen the shape of that dependency. One vendor, one bad update, July 2024 - and airlines, hospitals and banks stopped for a day. The industry's takeaway was "test your releases." Also, this is what it costs when everyone leans on the same few shoulders. In 2026, we leaned harder.
The risk that matters here isn't technical, and it rarely gets red-lined.
When the company behind a tool you rely on is bought,
your data-processing agreement is rewritten,
your support tier shifts,
your data may cross a border it was never meant to,
And moreover, the leverage you held as a customer passes quietly to a supplier who now owns three of the controls you cannot turn off.
Should you ever want to leave, the door is heavier than it was.
This isn't a case against platforms. It's a case for treating every acquisition of a vendor you depend on as a risk event in its own right - re-reading the change-of-control and data-residency clauses, capping how much of your stack any single supplier can hold, and keeping an exit you have actually rehearsed.
So before the next deal closes, one question earns a place on the agenda: if your largest security vendor had a bad day tomorrow, how much of your defence goes dark with it?