The security line in the budget grows every year, but the feeling of being secure does not grow with it. The IT lead of a Swiss manufacturer recently counted fourteen security tools: three with overlapping functions, two nobody had logged into for months. The management team asks why costs keep rising while the number of incidents stays the same. And IT has no good answer to that question.
This is exactly where the work of consolidating security tools begins. Not with the question of what is still missing, but with the question of what is already there and actually works. For Swiss SMEs with 50 to 500 employees this is often the biggest lever available, and the one used least.
Many SMEs do not have a security problem, they have too many tools that overlap, cost money and remove the overview. Consolidating security tools means checking the existing landscape for effectiveness, cutting the duplicates, and only then closing the real gaps deliberately. The result in most mandates is more protection with fewer licences and lower cost.
Most companies do not have a security problem, they have a sizing problem. Too many tools, too little overview, too much cost for too little real protection. Consolidating therefore does not mean saving at any price, it means sizing things right: More protection. Fewer tools. Lower cost.
How do you know you have too many security tools?
The clearest sign: nobody in the company can say offhand which tool serves which purpose and who is responsible for it. Add to that dashboards nobody opens any more, alerts nobody triages, and licences that quietly renew every year. When a new tool arrives after every audit but none ever leaves, the landscape has run away from you.
The reason is rarely bad decisions. Tools accumulate because each individual purchase looked sensible on its own. One tool came with a project, one through a business unit, one as a reaction to an incident. Renewal then runs on autopilot, because nobody has the time to lay the whole inventory side by side once. Over the years this grows into a collection nobody has deliberately designed.
In practice it is usually the same patterns showing up in Swiss SMEs:
- Two or three tools promising the same function, for instance a classic antivirus next to a modern EDR solution that replaced it long ago.
- A tool introduced with considerable effort and then never properly configured. It runs, but reports nothing useful.
- Security features you already pay for through an existing licence such as Microsoft 365, which were never switched on, while an additional product does the same job in parallel.
- Reporting scraped together from five consoles, because no tool has an overview of the others.
No single one of these points is dramatic. Together they produce cost without value and, worse, blind spots between the tools that nobody sees any more.
Why more tools rarely mean more security
Nobody says no to a tool. An audit ends with a recommendation, a sales pitch with a demo, an incident with the wish never to go through that again. At the end of each of those situations sits a new product. The licence list grows, the risk stays.
The thinking error behind it: security does not come from the number of logos in the portfolio, it comes from coverage, clear ownership and the ability to react when it counts. A tool nobody maintains gives a false sense of protection. It sits in the inventory, it sits in the board presentation, and it does nothing. One well-run solution the team understands and watches protects better than three half-configured ones getting in each other's way.
The price is usually paid by a small IT team that is stretched anyway. Every extra tool eats attention that is then missing on the important signals. Meanwhile the outside picture is reassuring: the board sees a long list of protective measures and concludes the company is secure. That calculation rarely works out, because protection is measured by effect, not by the length of a list.
Every extra integration brings a quiet burden with it. Every tool wants to be connected and maintained. The more of them exist, the less time remains for what counts: understanding the alerts that point at a real problem. Alert fatigue is, in our experience, one of the biggest unsolved topics in the SME segment, and it grows with every tool.
What does tool consolidation actually deliver?
Consolidation mainly delivers more overview and fewer blind spots. The lower bill is a pleasant side effect, no more than that. When ten tools shrink to three, the team can see again what belongs together: alerts land in one place, and the freed-up licence budget flows into the gaps that matter.
The cost saving is the most visible effect, but not the most important one. More important is that risks no longer disappear between two tools because each assumes the other is handling it. A consolidated inventory is also far easier to explain to customers and auditors. If you have to demonstrate that your security works, a tidy, traceable landscape gets you much further than a long list of products.
In most mandates we run, licence cost falls while coverage rises. That sounds contradictory but is not: the protection was already there, it was just badly sized and expensively distributed.
When is consolidating security tools worth it?
It is worth it as soon as nobody can say with certainty which tool serves which purpose, or when two tools promise the same thing. At the latest before a certification or a customer audit a tidy inventory pays off, because at that point effectiveness is the question, not tool variety. A change in IT leadership or a cluster of expiring contracts is a good occasion too.
A frequent and underestimated trigger is the annual budget round. As soon as the management team asks why the security line grows without incidents going down, the moment for an honest review has arrived. After a merger or acquisition the same look pays off, because two grown tool inventories then sit side by side and much of it is duplicated.
For many Swiss companies a regulatory trigger comes on top. Operators of critical infrastructure have had to report cyber attacks to the Federal Office for Cybersecurity within 24 hours since 1 April 2025, as the BACS reporting obligation sets out. Anyone subject to the Information Security Act needs a working ISMS by the end of 2026. But an ISMS consists of lived processes and clear responsibilities. A large tool collection does not replace that. Which is exactly why tidying up is often the first sensible step towards being able to demonstrate anything.
The best moment remains the one where an independent stocktake shows honestly what stays and what can go. In our Cyber Assessment that is precisely the starting point: see before you act.
What consolidation looks like in practice
A supplier from eastern Switzerland with around 220 employees came to us with a typical picture. In use were a modern EDR solution, alongside it an old antivirus kept out of habit, two different vulnerability scanners, a SIEM that never went into operation, a separate tool for phishing simulations, and a Microsoft 365 E5 licence whose security features lay largely idle.
We started with what the company was already paying for. We switched on the security features in Microsoft 365, and they took over part of what had previously been bought expensively on the side. The old antivirus and one of the two scanners went out, as did the unused SIEM. What remained was a smaller but understood landscape with one central place for alerts.
The outcome: fewer licences, lower annual cost and still more coverage than before, because existing features were used for the first time. More important than the saving was that the management team could see in a single picture what is protected and who reacts in an emergency. The biggest effect came without a single product purchase, purely from the decision about what stays.
Six months later came the test from outside. A major customer sent a security questionnaire of the kind that is now standard in many tenders. Where the company would previously have scraped evidence together from five consoles, the answer was now at hand. A tidy inventory saves money and can be demonstrated on top. Whether a company can prove its security increasingly decides sales.
Decisions like these are easier with a voice that has neither a licence to sell nor its own team to protect. Who takes that role on a mandate and how it differs from classic consulting is described in our article on what a fractional CISO is. The through-line is the same everywhere: tidy up first, then invest.
Frequently asked questions
Do we lose protection when we switch tools off?
Only if you switch off something that covers a real function on its own. That is the first thing a consolidation checks. What gets switched off is what exists twice or what nobody operates anyway. The risk almost never sits in having one tool too few, it sits in the gaps between too many and in the tools nobody watches.
How long does tool consolidation take in an SME?
The clear picture of what stays and what can go usually stands after a few weeks of stocktaking. The actual implementation follows in stages, often along the expiring contracts, so nothing already paid for goes to waste. A large part of the benefit comes from the overview itself, long before the last tool is switched off.
What happens to running licence contracts?
Nothing gets ripped out mid-contract without a reason. The lever sits at renewal: what quietly renews without serving a purpose does not get renewed again. Cost then falls predictably across the usual contract cycles instead of in an expensive one-off push.