Strategic audit and TCO optimization of IT security

Mapping and consolidation of $480M of cybersecurity spend across 25 subsidiaries. Comprehensive TCO modeling and identification of rationalization levers.

01 Challenges and context

Context and strategic stakes

An international financial group with over 25 subsidiaries faced complete opacity regarding its cybersecurity investments. The dispersion of expenses (Cloud, hardware, software, managed services, consultants, penalties) made it impossible to construct a reliable Total Cost of Ownership (TCO), limiting management's ability to measure the effectiveness of its investments in the face of heterogeneous geopolitical and regulatory contexts.

02 Work carried out

Approach and methodology

The first step involved breaking down financial information silos by conducting a centralized and exhaustive inventory of all IT security-related expenses. We collected and harmonized raw data concerning human resources (internal FTEs, external consultants), software licenses (EDR, SIEM, IAM, firewalls), Cloud and On-Premise infrastructure costs, as well as audits, certifications, penetration tests, and operational resilience costs (incident response) across all 25 subsidiaries.

03 Outcomes achieved

Results and indicators

480 M$

IT security spending analyzed

25

Group subsidiaries

  • Consolidated analysis of a massive financial scope of 480 million dollars in IT security spending.

  • Creation of a 360-degree, centralized vision for the group's 25 subsidiaries.

  • Presentation of strategic recommendations validated by the executive committee to rationalize costs without compromising risk coverage.