WEEK 34 · INVENTORY

Run the "shut it off" thought experiment on one tool.

Your stack has never gotten smaller, and the reason has very little to do with whether the tools work.

Your security stack has never once gotten smaller. Ask anybody who's run the same program for five years and they'll confirm it without hesitating, and not one of them can name the tool they'd remove.

Stacks grow by accretion. Somebody reads about a breach at a peer company and a purchase follows, then an auditor writes a finding and another purchase follows, and somewhere in the middle a vendor folds a new module into a renewal that nobody ever evaluated on its own.

Each of those decisions made sense on the day it happened, and none of them included a step where somebody removed whatever the new thing replaced.

So you end up with overlapping coverage nobody has mapped, four products that all claim endpoint detection, and a budget line that renews on autopilot because cancelling requires an argument and renewing requires a signature.

The question that cuts through this is embarrassingly simple. If we turned this off tomorrow, what would actually break, and who would notice by Friday?

Ask the team rather than the vendor, and write the answer down instead of nodding at it.

Pay attention to how the answer arrives. A tool that earns its keep produces a fast, specific response naming a workflow and a person. A tool that doesn't produces a pause, then a sentence about coverage, then a reference to the compliance requirement it was bought to satisfy. The pause is the data, and it'll tell you more than the renewal quote.

Most people treat a renewal as a question about value. What's actually happening is that value here can't be tested at all. The tool was bought to prevent things, prevention that works produces nothing you can point at, and every control in the stack ends up claiming the same quiet year at the same time.

That's the work this question does. It trades an unanswerable claim about the past for a checkable one about next Tuesday, and a checkable claim can turn out to be wrong, which is exactly what makes it worth having.

There's a version of this that pays off even when you keep everything. You end up with a written map of which tool covers which outcome, and that map is the thing you were missing the last time somebody asked what would happen if a given control failed.

So, here's the MondayMove

Pick one security tool you've owned for more than three years, ask your team what would actually break if you turned it off tomorrow, and write down what they say.

Save the answer, because you'll want to run this across the whole stack, one renewal at a time.

Friday Follow-Up

The pause was the answer.

Asking what breaks takes a minute. Nobody warns you about the quiet that follows, and the quiet is the part worth reading.

MondayMove gives you one concrete action every Monday. FridayFollowUp closes the loop.

Each Friday, a short dispatch on what practitioners actually found when they ran the week's move: where they got stuck, what surprised them, and what to do next. Not sanitized case studies. Field notes. Practitioner to practitioner.

Monday's move was to pick one tool you've owned for more than three years, ask your team what would break if you turned it off tomorrow, and write down what came back.

My first guess is you didn't pick the tool you meant to pick. Most people walk in aiming at the one they already suspect, then choose something safer at the last second, because asking the real question about the real tool means the answer might oblige you to do something in October.

The answers came in two speeds. Somebody named a workflow and a person inside four seconds, and somebody else took a breath and said the word coverage. The second one is worth more, because the person saying it isn't dodging you. They've operated that console for two years and cannot describe what it produces, and that gap belongs to the program rather than to them.

Then you tried to write it down, which is where I expect the whole thing snagged. A vague answer sounds perfectly reasonable out loud and looks obviously empty in a sentence. "It gives us visibility" survives a meeting. It does not survive a text field with your name at the top.

One more, and this is the one that stings. Somebody in that room heard the question as a threat to their headcount or their budget. Not because you framed it badly. Because every previous time a security org asked what happens if we turn this off, a cut followed within two quarters, and people remember the pattern longer than they remember your intentions.

So take the vaguest answer you got and go one layer down. Find the person who opens that console on a normal Tuesday, ask them the same question, and write the gap between the two answers next to the first one. That gap is the finding, and it's usually bigger than anything the renewal quote would have told you.

Then leave the tool alone until you've done this twice more. One data point is an opinion about a vendor. Three is the beginning of a map.

Keep going. See what a week can do.

No correct answers here. This is practitioner-to-practitioner. The more honest the responses, the more useful this gets for everyone reading on Monday morning.

See you then.

Discussion