About
Subscribe
  • Home
  • /
  • TechForum
  • /
  • NEC XON Cyber drives Palo Alto-driven platform approach to tackle enterprise security 'tool sprawl'

NEC XON Cyber drives Palo Alto-driven platform approach to tackle enterprise security 'tool sprawl'

Johannesburg, 15 Apr 2026
Michael de Neuilly Rice, Principal Security Architect at NEC XON. (Image: Supplied)
Michael de Neuilly Rice, Principal Security Architect at NEC XON. (Image: Supplied)

South African ICT solutions provider NEC XON is advocating a shift away from fragmented cyber security toolsets towards unified platforms, arguing that “tool sprawl” is undermining the effectiveness of enterprise security operations.

Speaking about recent client engagements, Michael de Neuilly Rice, principal security architect at NEC XON, said organisations are increasingly struggling to manage sprawling collections of disconnected security tools.

Tool sprawl stretches already stretched cyber security teams

“Across both new and existing environments, we consistently find a proliferation of point products,” De Neuilly Rice said. “Each tool is licensed separately, configured independently and maintained in isolation. That places a heavy burden on already stretched security teams.”

De Neuilly Rice said modern security architecture must still address a wide range of domains – including endpoint, network, e-mail, applications, data, identity, cloud and attack surface – but warned that simply adding more tools is not the answer.

“It only takes a single vulnerability for a threat actor to gain access, but adding more tools doesn’t necessarily reduce that risk. In many cases, it increases complexity and introduces new points of failure,” he said.

Platform approach eliminates lack of integration

A key issue, according to De Neuilly Rice, is the lack of integration between tools, which limits visibility and slows response times.

“Security teams often can’t see the full progression of an attack across systems,” he said. “Analysts are forced to jump between multiple dashboards, correlate alerts manually and respond in silos. That delay can be critical during an incident.”

He added that traditional approaches – where logs are funnelled into a SIEM (security information and event management) and automated through separate SOAR (security orchestration, automation and response) platforms – often compound the integration challenge rather than solve it.

Multiple security capabilities on one unified platform

NEC XON is instead promoting a platform-based model built around Palo Alto Networks’ Cortex suite, particularly Cortex XSIAM, which consolidates multiple security functions into a single environment.

“The shift is towards platformisation,” De Neuilly Rice said. “With Cortex XSIAM, you can ingest data from across the environment, apply correlation and analytics, and automate response – all within one platform. It effectively replaces the need for separate SIEM, SOAR and endpoint tools.”

The platform also integrates capabilities such as endpoint detection and response via Cortex XDR, alongside add-ons covering cloud security, attack surface management, data loss prevention and identity threat detection.

“One of the biggest advantages is the unified data lake,” De Neuilly Rice said. “All telemetry sits in one place, which enables centralised threat hunting and gives analysts a complete, end-to-end view of an attack.”

He said advances in AI and machine learning are further enhancing this approach.

“Machine learning helps correlate events that would otherwise appear unrelated, while agentic AI can assist with investigation, threat hunting and automation. That allows analysts to focus on higher-value work rather than managing tools,” he said.

Emergence of the modern SOC

De Neuilly Rice argued that this model represents a broader shift in how security operations centres (SOCs) are designed and run.

“The modern SOC is no longer about stitching together dozens of products,” he said. “It’s about operating a unified platform where you can see the full attack narrative, respond quickly and continuously improve your security posture.”

According to NEC XON, organisations that adopt this approach can reduce operational complexity, improve response times and achieve faster returns on their security investments.

“Ultimately, this is about enabling security teams to do what they’re meant to do – detect, respond to and prevent threats – without being held back by their own technology stack,” De Neuilly Rice said.

Share

NEC XON

NEC XON is a leading African integrator of ICT solutions and part of NEC, a Japanese global company. The holding company has operated in Africa since 1963 and delivers communications, energy, safety, security, and digital solutions. It co-creates social value through innovation to help overcome serious societal challenges. The organisation operates in 54 African countries and has a footprint in 16 of them. Regional headquarters are located in South, East, and West Africa. NEC XON is a level 1-certified broad-based black economic empowerment (B-BBEE) business. Discover more at www.nec.africa.

Editorial contacts

Michelle Oelschig
Scarlet Letter
(083) 636 1766
michelle@scarletletter.co.za