Skip to content

Security tool inventory and overlap register

The register a rationalization program actually runs on: cost, renewal date, notice period, named owner, claimed functions, and a decision per row.

v1.0CSVCurrent as of August 29, 2026No signup, generated in your browser

Wiz found 58% of organizations running more than 25 security tools. This is the file the four-week rationalization playbook runs on. The columns are ordered the way the program uses them: inventory first, then the fields that decide whether a row is actionable this cycle, then the decision. Notice period is included because a tool with a 90-day notice window renewing in 70 days is not a candidate this quarter, and finding that out in week four wastes the program.

Preview

The first 4 of 4 rows, rendered from the same data the download is built from.

ToolCategoryAnnual cost (USD)Renewal dateNotice period (days)Named ownerFunctions claimedDecisionAction dateReason
blankblankblankblankblankblankblankblankblankblank
Example: Cloud security platformCNAPP1800002027-03-3190Priya (SecOps)asset inventory; vuln detection; config assessment; runtime detection; posture reportingKeepblankPlatform absorbed CSPM function in the 2026.2 release
Example: Standalone CSPMCSPM480002027-01-1560Unassignedasset inventory; config assessment; posture reportingRetire2027-01-15Fully covered by the platform above; murder board 2026-11-04
Example: Legacy vulnerability scannerVulnerability scanner900002027-06-3090Dan (IT)asset inventory; vuln detection; posture reportingKeep with review2027-04-01Sole source for authenticated scanning of 40 on-premise Windows hosts

Formulas: Add a column computing the last date you can give notice: renewal date minus notice period. Sort by it. That column, not the savings column, is what sequences the program.

How to use it

  1. Populate from four sources, not one: finance for anything with a purchase order, the identity provider for anything with single sign-on, cloud accounts for anything with a deployed agent or role, and the security team's own memory for the rest.
  2. Leave Decision blank until phase three. A register filled in while inventorying becomes a wishlist.
  3. Rows with no named owner are your first finding. If more than one in ten is unowned, report that number before reporting any savings.
  4. Keep the rows you decided to keep. An overlap consciously accepted and written down is architecture; the same overlap unexamined is sprawl.

The 30-day rationalization playbook

Changelog

v1.0 (August 29, 2026):
First release. Ten columns, three worked example rows.

Common questions

What belongs in a security tool inventory?
Annual cost including professional services, renewal date, notice period, a named internal owner, and the security functions the tool claims. Notice period is the field most often skipped and the one that decides whether a tool can be acted on this cycle at all.
Where do you find the security tools nobody remembers buying?
Cloud accounts, usually as a role or deployed agent created during an incident years earlier. Finance misses anything bought on a card or bundled, and the identity provider misses anything authenticating locally, which is disproportionately the oldest tooling. Use all four sources.
How much spend does rationalization typically recover?
Between five and fifteen percent of the tool budget in year one, weighted heavily toward platform absorption, where a platform you already pay for has grown a capability you buy separately. Consolidations rarely pay back inside twelve months once parallel running and detection rewrite are counted.

Filed under Buying & Evaluation.