Every tool on the invoice tells you who profited from the decision. Read the stack like a ledger.
Pull up the invoice from your IT provider and read the line items like a ledger. Every tool on it was a decision, and every decision had a beneficiary. Sometimes that was you. Often it was whoever sold the tool.
Nobody sets out to build a bad security stack. It accretes. A breach story makes the rounds and a product gets added. A vendor rep buys lunch and a product gets added. A renewal comes due and, because removing things feels risky, everything stays. The stack only grows, and each layer arrives with its own dashboard, its own agent on every computer, and its own line on the invoice.
Ask what any given layer is for and the answer is usually a category name: endpoint protection, email security, dark-web monitoring. Ask what it caught last quarter and the room gets quiet.
Most IT providers make margin on the products they resell. That is not a scandal; it is how the industry is structured. But it means the person recommending your security tools profits when the list gets longer, and the person paying for them cannot tell the difference between protection and padding. The information gap is the product.
A security stack should read like a set of answered questions. Most read like a sales history.
You can see the incentive problem in what is missing. The unglamorous controls that stop real incidents, a second step on every sign-in, backups that restore in a test, patching that actually lands, rarely show up as line items, because there is nothing to resell. The flashy acronyms show up instead.
Take the last invoice and ask four questions of every security line:
Anything with four shrugs is a candidate. In the environments we take over, the audit usually finds two or three tools doing overlapping work, one tool nobody has logged into since onboarding, and at least one gap, usually backups or sign-in security, that no product on the invoice covers.
There is a structural fix: pay for outcomes instead of products. A flat monthly model reverses the incentive, because every unnecessary tool comes out of the provider's margin instead of yours. The stack gets shorter and the posture gets stronger, because the provider profits from things not happening.
That is the reading we do in the first weeks of every engagement: every line gets a verdict. Keep, fix, kill, defer. A multi-state lender we work with came in with a vendor for every gap and audits failing anyway; the fix started with the list getting shorter, not longer.
Your invoice tells the story. If you want a second reader, the conversation takes 30 minutes, and you keep the ledger either way.

An embedded advisory partner in IT risk, cybersecurity, automation, and AI for leaders of high-stakes enterprises.