The Security Stack Cost Audit

Your security budget is larger than it needs to be.

Security stack waste is often invisible to the CFO: redundant capabilities, tools nobody uses, and licensing tiers that never matched what the organisation actually needs. One structured day of independent audit provides the evidence required to consolidate spend without compromising protection.

Identified Waste

$30K–$100K

Average identified per mid-market stack

Engagement Model

$12,500

Fixed fee, all inclusive, one day

The $20,000 guarantee

If we do not identify at least $20,000 in overlapping or redundant tool spend, the audit is completely free.

Structural Inefficiency

Security spend follows predictable patterns of waste. Once identified, it becomes impossible to ignore.

  1. 01

    Duplicate Capability

    Two or more tools performing the same function, endpoint detection and EDR overlap, or SIEM and log management duplication. Both are licensed; neither team knows the other exists.

  2. 02

    Shelfware

    Fully licensed, never deployed. Common after M&A activity, team turnover, or a vendor upsell that preceded the organisation's capability to implement it. The invoice processes monthly; the tool collects dust.

  3. 03

    Zombie Tools

    Deployed once, abandoned after. The original champion left the organisation, but the renewal auto-processed. Ask the team; they will name two immediately.

  4. 04

    Overprovisioned Tiers

    Enterprise licences for a mid-market business, or premium tiers for features never enabled. Seat counts often have not been reconciled since the contract was signed.

  5. 05

    Inflated Premium Pricing

    Market-leading brand names procured at premium prices where a second-tier product delivers equivalent protection at a fraction of the cost. The vendor is happy to keep the status quo.

  6. 06

    Misaligned Licence Models

    Per-device licensing in a per-user environment, or vice versa. In hybrid environments, this mismatch represents 20 to 40 per cent excess cost on a single product.

"Your MSP is not acting in bad faith. They are acting in their own interest, which is structurally different from yours. They earn margin on the tools they choose. You need an advisor whose fee is paid entirely by you."

The Audit Process

What one structured day produces

  1. 01

    Asset Register Review

    Every licensed tool identified, categorised and mapped against actual usage data and your current risk profile.

  2. 02

    Stakeholder Interviews

    Short structured interviews with the users. This is where zombie tools surface: IT knows, nobody has asked.

  3. 03

    Overlap Analysis

    Capability mapping across the full stack. Where two tools do the same job, one is identified for elimination.

  4. 04

    Executive Presentation

    Findings consolidated into two deliverables and presented directly to the CFO. Plain language, actionable from day one.

Two documents. Immediate commercial value.

Deliverable 01

The Kill List

A prioritised list of tools recommended for elimination or consolidation, with estimated annual savings per line item and a recommended sequence for removal.

Deliverable 02

The Vendor Negotiation Brief

For every tool recommended for retention: current market pricing, leverage points, and a recommended negotiation position.

What An Audit Uncovers

Three patterns appear in almost every mid-market stack review.

The Phantom Tool

A DLP, SIEM or email platform generating alerts for months with no recipient acting on the output. The licence renews. You are paying for the appearance of protection.

The MSP Overlap

Two endpoint protection platforms running simultaneously: one from the previous IT team, one added by the incoming MSP. Combined waste: $20K–$40K per annum.

The Frozen Contract

An enterprise-tier contract signed three years ago for a headcount that no longer exists. Auto-renewal processed without review. The vendor was not going to raise it.

Instant Access — Ten Questions

The Cost Consolidation Scorecard

Ten yes-or-no questions about your security stack. Each "No" is a direct cost recovery opportunity, and "Unsure" counts as No: in cost as in security, not knowing is the finding.

Stack Efficiency

Q1–06

Six categories of waste: most mid-market organisations carry at least three.

No duplicate capability

You can list every active security tool and confirm no two perform the same primary function. Overlap is the most common, and easiest, waste to eliminate.

All tools fully deployed

Every licensed tool is fully deployed: none partially implemented or still awaiting rollout. Partial deployments cost the same as complete ones.

No zombie subscriptions

You have cross-referenced your IT general ledger against active log sources in the last 90 days to find billing for inactive tools. Ask your team: they'll name two immediately.

Licensing reflects reality

Seat counts and enterprise agreements reflect current active users and hybrid-workforce realities, not peak historical headcount. Overprovisioning typically runs 20 to 30 per cent above actuals.

Mapped to specific controls

Every active tool is explicitly mapped to a required security control or threat scenario. Nothing exists merely just in case or because it is a current buzzword.

No premium feature bloat

You aren't paying for premium licensing tiers (Microsoft E5, for example) for capability that remains unconfigured. Right-sizing tiers saves instantly.

Governance & Accountability

Q07–08

Tools with no named owner cost the same as tools that are actively managed.

Every tool has a named owner

Each tool has a named individual accountable for maintenance, patching and reviewing its outputs. No owner means no one noticing the cost.

Alerts are acted on

Every tool generating alerts has someone actively reviewing and acting on that output. DLP and SIEM consoles with unread alerts are the most expensive shelfware.

Advisor Independence

Q09–10

The advisor managing your stack has a financial interest in its size. Does yours?

Your advisor earns no vendor margin

Your MSP or IT advisor doesn't earn margin, referral fees or vendor incentives on the tools they manage. If they do, their recommendation and your cost optimisation conflict.

Your stack has had an independent review

The most telling question. Reviewed by an advisor with no financial relationship with any current vendor, whose only interest is your cost efficiency.

Your Score

0/10

Answer all ten questions to see your result.

0 of 10 answered

Book a Briefing

Find out what your stack is actually costing you.

A 15-minute conversation with Dean Kastelic. No obligation: if the audit is not the right fit, Dean will tell you directly.

Dean Kastelic

The Advisor

Dean Kastelic

Founder, Vyfority — Former Enterprise CISO

Dean works with mid-market CFOs and boards to reclaim wasted security spend. Having led cyber governance at KPMG and served as CISO for large enterprises, he understands both the technical requirement and the commercial reality of a security stack. His advice is independent, fixed fee, and focused entirely on client value.

The Guarantee

I will identify at least $20,000 in annual savings from your current security stack, or the initial assessment is free.

Find out what your stack is actually costing you.

Fixed fee, agreed before we start, led personally by a former enterprise CISO.