Security tool inventory and overlap register
The register a rationalization program actually runs on: cost, renewal date, notice period, named owner, claimed functions, and a decision per row.
Wiz found 58% of organizations running more than 25 security tools. This is the file the four-week rationalization playbook runs on. The columns are ordered the way the program uses them: inventory first, then the fields that decide whether a row is actionable this cycle, then the decision. Notice period is included because a tool with a 90-day notice window renewing in 70 days is not a candidate this quarter, and finding that out in week four wastes the program.
Preview
The first 4 of 4 rows, rendered from the same data the download is built from.
| Tool | Category | Annual cost (USD) | Renewal date | Notice period (days) | Named owner | Functions claimed | Decision | Action date | Reason |
|---|---|---|---|---|---|---|---|---|---|
| blank | blank | blank | blank | blank | blank | blank | blank | blank | blank |
| Example: Cloud security platform | CNAPP | 180000 | 2027-03-31 | 90 | Priya (SecOps) | asset inventory; vuln detection; config assessment; runtime detection; posture reporting | Keep | blank | Platform absorbed CSPM function in the 2026.2 release |
| Example: Standalone CSPM | CSPM | 48000 | 2027-01-15 | 60 | Unassigned | asset inventory; config assessment; posture reporting | Retire | 2027-01-15 | Fully covered by the platform above; murder board 2026-11-04 |
| Example: Legacy vulnerability scanner | Vulnerability scanner | 90000 | 2027-06-30 | 90 | Dan (IT) | asset inventory; vuln detection; posture reporting | Keep with review | 2027-04-01 | Sole source for authenticated scanning of 40 on-premise Windows hosts |
Formulas: Add a column computing the last date you can give notice: renewal date minus notice period. Sort by it. That column, not the savings column, is what sequences the program.
How to use it
- Populate from four sources, not one: finance for anything with a purchase order, the identity provider for anything with single sign-on, cloud accounts for anything with a deployed agent or role, and the security team's own memory for the rest.
- Leave Decision blank until phase three. A register filled in while inventorying becomes a wishlist.
- Rows with no named owner are your first finding. If more than one in ten is unowned, report that number before reporting any savings.
- Keep the rows you decided to keep. An overlap consciously accepted and written down is architecture; the same overlap unexamined is sprawl.
Changelog
- v1.0 (August 29, 2026):
- First release. Ten columns, three worked example rows.
Common questions
- What belongs in a security tool inventory?
- Annual cost including professional services, renewal date, notice period, a named internal owner, and the security functions the tool claims. Notice period is the field most often skipped and the one that decides whether a tool can be acted on this cycle at all.
- Where do you find the security tools nobody remembers buying?
- Cloud accounts, usually as a role or deployed agent created during an incident years earlier. Finance misses anything bought on a card or bundled, and the identity provider misses anything authenticating locally, which is disproportionately the oldest tooling. Use all four sources.
- How much spend does rationalization typically recover?
- Between five and fifteen percent of the tool budget in year one, weighted heavily toward platform absorption, where a platform you already pay for has grown a capability you buy separately. Consolidations rarely pay back inside twelve months once parallel running and detection rewrite are counted.
Filed under Buying & Evaluation.