The Group Photo Nobody Wants to Take


George Just
Head of Channel Sales
3 min read · Sep 2, 2026
Your vendors have never stood together for one. That's not an accident.
When was the last time all of your tech stack vendors were in the same room, asking you what you need, and how they're protecting your business together?
Take a second with that before you answer, and don't round up. I ask this in almost every conversation now, and I get the same answer every time, once people really think about it for a minute.
Zero. Not “it's been a while.” Zero.
Picture what that room would look like if it ever happened: every vendor in your stack, lined up together for one photo, all claiming credit for protecting the same account. That photo has never been taken, and it's not because nobody could find a date that worked. It's because nobody ever designed for it to exist, and none of them particularly want to be the one who suggests it.
Think about how the stack got built. Nobody sat down ten years ago and architected a coordinated security program from scratch. Endpoint is whatever the team that started putting this together back then put in, and nobody's gone back to question it since. MDR came in later, after an actual bake-off, three vendors, a scorecard, months of back and forth before anyone signed. SOC-as-a-service got layered on top once alert volume outgrew what the internal team could handle on its own. Each purchase made sense on its own, made by smart people solving the problem directly in front of them at the time. Nobody was ever asking how all of those systems would operate together under one managed IT model, because that job doesn't show up on an org chart. It shows up after the incident, when everyone's trying to figure out who owns what.
Here's the part that should bother you more than it probably does: the average mid-market company is running at least 20 security point solutions. That number comes from two independent surveys, one out of the UK mid-market, one out of US companies in the 500 to 999 employee range, both landing in the same range on their own. At least 20 vendors, each with their own contract, their own renewal date, their own support line, their own idea of what they're responsible for.
And every one of those relationships introduces another dependency that has to be understood, governed, and held accountable.
It gets worse at scale, not better. Enterprise organizations, according to the same body of research, are running well over 40 tools, and nearly half of security teams say they're pulling in more than 20 different tools just to investigate a single incident. Mid-market hasn't escaped this, it's just earlier in the same trajectory, before the budget exists to hire someone whose full-time job is untangling it.
Now ask yourself how many of those 20 vendors have ever spoken to each other. Not through you, relaying information back and forth like a hostage negotiator. Actually talked. Compared notes. Agreed on where one vendor's coverage ends and the next one's begins.
If your answer is still zero, you're not alone. Nearly half of mid-market security leaders, 44% in one recent survey, describe their own stack as disconnected, stitched together after the fact rather than built as a system. That's not a technology problem. That's a design problem, and it was designed this way one purchase at a time, with nobody ever responsible for how the pieces fit.
To be fair, the industry knows this. Three-quarters of organizations are now actively pursuing vendor consolidation, up from less than a third just a few years ago, and the top reason they give isn't cost. It's that a smaller, more coordinated stack performs better than a sprawling one. Even the vendors selling into this mess are starting to admit the mess is the problem. That should tell you something. When 75% of the market is trying to walk back a strategy, it wasn't a strategy. It was an accumulation.
I wrote last month about what happens when a fragmented security stack gets tested by a real incident: every vendor goes into self-preservation mode and you end up refereeing a blame tournament instead of getting an actual answer. This is the same story, told earlier. The photo that never gets taken before the incident is exactly why the blame tournament happens after it. You can't expect coordination under pressure from vendors who've never once had to coordinate, or stand next to each other and admit it.
I sat in on a conversation recently where a partner did something simple and, in twenty years of doing this, genuinely rare. He got three of a client's vendors on one call. Not to sell anything. Just to ask each of them, in front of the others, “what are you covering, and what happens if you're wrong?” It was, by his account, one of the most uncomfortable calls he's ever run. Not because anyone got caught doing something wrong, but because nobody had ever had to answer that question with the other vendors listening. Two of them, it turned out, both assumed the other was covering the same piece of the network. The third had no idea either of them existed. None of that showed up in a single dashboard, a single report, or a single renewal conversation, until someone finally forced them into the same frame.
That discomfort is the whole point. A stack where nobody's ever had to stand in that frame and answer for their piece of it isn't a security program.
It's 20 separate bets that nothing goes wrong on any one of their watches. None of those bets are on you.
The alternative isn't simply fewer tools. It's a structure where responsibility is defined and someone is accountable for how the entire environment operates.
So ask yourself the question again, now that you know the honest answer. When was the last time you tried to get all of your vendors in the same room, let alone the same photo? And if the answer is never, what exactly are you paying 20 of them to protect?
George Just leads Channel Sales at RedZone Technologies, where Passpoint Security and RedZone's managed services operate as a unified platform for mid-market cyber resilience. Before moving into channel leadership, he spent years working directly in cybersecurity and networking, which is part of why he thinks about vendor accountability like an operator, not just a salesperson. This is the second in a series he's writing on the intersection of channel dynamics, cybersecurity reality, and what it actually takes to build a security program that holds.
