Your security stack has never once gotten smaller. Ask anybody who's run the same program for five years and they'll confirm it without hesitating, and not one of them can name the tool they'd remove.
Stacks grow by accretion. Somebody reads about a breach at a peer company and a purchase follows, then an auditor writes a finding and another purchase follows, and somewhere in the middle a vendor folds a new module into a renewal that nobody ever evaluated on its own.
Each of those decisions made sense on the day it happened, and none of them included a step where somebody removed whatever the new thing replaced.
So you end up with overlapping coverage nobody has mapped, four products that all claim endpoint detection, and a budget line that renews on autopilot because cancelling requires an argument and renewing requires a signature.
The question that cuts through this is embarrassingly simple. If we turned this off tomorrow, what would actually break, and who would notice by Friday?
Ask the team rather than the vendor, and write the answer down instead of nodding at it.
Pay attention to how the answer arrives. A tool that earns its keep produces a fast, specific response naming a workflow and a person. A tool that doesn't produces a pause, then a sentence about coverage, then a reference to the compliance requirement it was bought to satisfy. The pause is the data, and it'll tell you more than the renewal quote.
Most people treat a renewal as a question about value. What's actually happening is that value here can't be tested at all. The tool was bought to prevent things, prevention that works produces nothing you can point at, and every control in the stack ends up claiming the same quiet year at the same time.
That's the work this question does. It trades an unanswerable claim about the past for a checkable one about next Tuesday, and a checkable claim can turn out to be wrong, which is exactly what makes it worth having.
There's a version of this that pays off even when you keep everything. You end up with a written map of which tool covers which outcome, and that map is the thing you were missing the last time somebody asked what would happen if a given control failed.
So, here's the MondayMove
Pick one security tool you've owned for more than three years, ask your team what would actually break if you turned it off tomorrow, and write down what they say.
Save the answer, because you'll want to run this across the whole stack, one renewal at a time.
Discussion