Oxford, England
ProjectsJuly 4, 2024

Cutting security tooling costs by 60% while widening coverage

Cutting security tooling costs by 60% while widening coverage
  • Organisation: a UK health-tech company handling regulated health data
  • My role: led the review, the vendor evaluation, the recommendation, and the rollout
  • Estate: endpoints across Windows, macOS, and Linux, plus cloud workloads
  • Result: around 60% lower annual security tooling spend, with wider coverage than before
The organisation was paying a significant annual fee for its security tooling. The question wasn't just "can we pay less?" It was whether we were paying for the right coverage for the estate we actually had. With endpoints on three operating systems and workloads running in the cloud, the tooling needed to protect all of it without the team juggling several consoles.
  1. Mapped what we actually had to protect: every operating system in the estate and the cloud environment, rather than starting from vendor feature lists.
  2. Set the requirements the replacement had to meet:
    • native protection for Windows, macOS, and Linux
    • cloud-native security for our workloads
    • detection and response the team could run day to day
    • a total annual cost that made sense for an organisation of our size
  3. Researched the market and liaised with several vendors, comparing each against those requirements rather than against each other's marketing.
  4. Recommended one platform that met all the requirements, and ran the migration.
Consolidating onto one platform brought everything into a single console at a much lower cost. But it didn't cover everything. Patch and vulnerability management needed dedicated tooling. Rather than accept that gap, I onboarded a specialist patch and vulnerability management platform to sit alongside endpoint protection. Remediation now runs continuously instead of as a periodic exercise.
  • Around 60% saved every year on security tooling
  • One platform covering every operating system in the estate, plus the cloud
  • Continuous patching and vulnerability remediation, closing the one gap consolidation left
  • A simpler day-to-day operation for the team, with fewer consoles to watch

Related projects

Penetration testing consultancy
Ongoing

Penetration testing consultancy

Independent penetration testing as a freelance consultant, backed by more than two years of managing and delivering an annual penetration testing programme in-house.
Xcevia: a security consultancy in the making
In development

Xcevia: a security consultancy in the making

A practitioner-led security consultancy for UK SMEs that I'm building on the side. It's not trading yet. The groundwork is being laid for Cyber Essentials Plus readiness, cloud security, and DevSecOps support.
Incident response and endpoint security in health tech

Incident response and endpoint security in health tech

Owning day-to-day alert handling across a multi-OS estate at a UK health-tech company, correlating cloud activity with endpoint telemetry, and leading the response to a live, high-severity security incident.
Embedding SAST into CI/CD pipelines

Embedding SAST into CI/CD pipelines

Adding static application security testing (SAST) to a health-tech company's delivery pipelines, so developers find code-level vulnerabilities before release rather than after.
Cyber Essentials Plus, ISO 27001 and security governance

Cyber Essentials Plus, ISO 27001 and security governance

Preparing the organisation for Cyber Essentials Plus certification, running the annual penetration testing programme, and keeping security policy, BCP/DR and awareness training aligned with ISO 27001 and GDPR.
EchoCare: a digital complaint management system for home care

EchoCare: a digital complaint management system for home care

An Innovate UK funded feasibility study and proof of concept with PBL Care Limited and Birmingham City University. The system replaces paper-based complaint handling with CQC-standard digital forms, NLP classification, and a live dashboard.