Platformisation and the Ghost of Symantec: Why Cybersecurity Vendor Consolidation Should Worry Enterprise Buyers

There’s a word doing a lot of work in security vendor pitches right now: platformisation. One vendor for endpoint, identity, cloud, network, and SIEM. One console, one contract, one throat to choke. The pitch is simplification — and for security teams drowning in tool sprawl, it’s genuinely seductive.

I want to tell you a story about Symantec before you sign anything.

Not out of nostalgia. Out of pattern recognition. Because the cybersecurity vendor consolidation wave we’re living through — over $84 billion in disclosed security M&A in 2025 alone, the biggest year on record — is being sold to enterprise buyers as risk reduction, when it quietly concentrates one of the largest risks a security program can carry: your entire defensive capability tied to a single company’s ownership trajectory.

Symantec’s customers learned what that means. So, more recently, did VMware’s. As enterprise decision makers, we’d be foolish not to.


What happened to Symantec

For those who came into the industry recently, it’s hard to convey how big Symantec once was. Through the 2000s and early 2010s it was arguably the name in security — a genuine innovator across endpoint protection, email security, data loss prevention, and PKI, with one of the deepest threat research organisations on the planet. If you ran enterprise security, you almost certainly ran Symantec somewhere.

Then the arc bent. Growth stalled through the mid-2010s. The CEO departed abruptly in 2019 amid a revenue downgrade, with an activist hedge fund already holding board seats. Months later, Broadcom — a semiconductor company that had begun rolling up enterprise software with its CA Technologies and Brocade acquisitions — bought Symantec’s entire enterprise security business for US$10.7 billion in cash. The consumer side was spun off as NortonLifeLock. The Symantec that enterprise customers knew effectively ceased to exist.

What followed is now well documented, and it’s the part that matters for this article. Enterprise customers reported price increases of two to four times at renewal. Support quality declined. Product roadmaps went quiet, then products started receiving end-of-life notices — sometimes with less runway than a realistic migration requires. Talent left in waves, including much of the research capability that had made the products credible in the first place.

None of this was an accident or a botched integration. It was the business model working as designed.


The playbook, generalised

Broadcom’s approach to acquired software businesses is unusually explicit, but the underlying logic is common to a whole class of acquirers, and understanding it is the point of this section.

The economics: security software is a near-perfect margin-extraction asset. Recurring subscription revenue. Customers with genuinely painful switching costs — replacing a deployed security agent fleet, rebuilding detection tuning, retraining a SOC. Products embedded deeply enough in operations that a renewal, even an ugly one, is usually cheaper this year than a migration. An acquirer focused on extraction can raise prices, cut R&D and support costs, narrow focus to the largest and most profitable accounts, and harvest cash flow for years before enough customers complete their escapes to matter.

The buyers come in three flavours, with different risk profiles:

  • Strategic consolidators buying to extract (the Broadcom model) or to fill platform gaps (the current platformisation wave). The second is more benign for customers than the first — but an acquired product’s roadmap now serves the acquirer’s platform strategy, not necessarily your use case, and “encouraged” migration onto the acquirer’s stack is common.
  • Private equity, which owns a striking share of the security industry at any given moment. PE ownership isn’t automatically bad — some firms genuinely grow their assets — but the model runs on a hold-and-exit clock, which means cost discipline during the hold and another ownership change at the end of it, with all the same uncertainty replayed.
  • Hyperscalers and adjacent giants buying capability. Usually gentler on pricing, but the product’s independence, multi-cloud neutrality, and standalone roadmap all become open questions.

If the pattern felt theoretical after Symantec, VMware settled it. Not a security vendor, but the same acquirer and the same playbook at larger scale, running right now: perpetual licences eliminated entirely, a catalogue of over a hundred products collapsed into four mandatory bundles, minimum core requirements that force small deployments to pay for enterprise scale, and renewal increases that customers and analysts have documented at anywhere from a few multiples to over tenfold. Broadcom publicly stated its intent to roughly double VMware’s revenue within three years — from a customer base that isn’t growing at anything like that rate. The arithmetic only works one way: the customers pay it. Every Australian infrastructure team that lived through a recent VMware renewal understands, viscerally, what acquisition risk means. This article is simply asking you to apply that lesson to your security stack before the press release.


Platformisation raises the stakes

Here’s the uncomfortable interaction between the two trends.

The consolidation wave is real and accelerating. In 2025–26 alone: the largest standalone cybersecurity acquisition in history (a hyperscaler buying a cloud security leader for US$32 billion), a US$25 billion acquisition combining one of the biggest platform vendors with the long-standing leader in privileged access management, plus a steady drumbeat of billion-dollar deals across identity, AI security, MDR, and observability. Industry analysts are blunt about the driver: CISOs want fewer vendors, and acquirers are racing to become the platform those CISOs consolidate onto. “Platformization” isn’t a critic’s label — it’s the vendors’ own strategy language, on their own investor slides.

And to be fair: the platform pitch isn’t wrong about the problem. Tool sprawl is real. Integration tax is real. A well-integrated platform can genuinely be more secure than fifteen poorly-connected best-of-breed tools, and I’ve argued elsewhere on this site that ecosystem fit should weigh heavily in how you choose an EDR solution.

But notice what consolidation does to your exposure profile. When you ran fifteen vendors, any one of them getting acquired and squeezed was an annoyance — you migrated one tool. When you’ve consolidated endpoint, identity, cloud posture, and SIEM onto one platform vendor, that vendor’s ownership trajectory is your security program’s trajectory. An acquisition — or an activist investor, or a PE take-private, or simply a strategic pivot — doesn’t threaten a tool anymore. It threatens your detection and response capability, your identity plane, and your telemetry archive simultaneously, all bound under one master agreement whose renewal date is now the single most dangerous day on your calendar.

The platform vendors selling consolidation as risk reduction are not lying about the operational risks it reduces. They are simply not mentioning the concentration risk it creates — because that risk is, from their side of the table, the entire commercial point. Sticky, consolidated, hard-to-leave customers are precisely what makes a security company an attractive acquisition target. You are not just buying a platform. You are becoming part of what’s for sale.


A simple scoring system: vendor acquisition risk

You can’t control whether your vendor gets acquired. You can control how exposed you are when it happens. Here’s a deliberately simple framework — five factors, each scored 1 to 3, giving a total between 5 and 15. Score each strategic security vendor annually and before any major renewal or consolidation decision. It won’t predict acquisitions (nothing does), but it will tell you where your exposure is concentrated and how urgently to act.

#Factor1 point2 points3 points
1Ownership & governanceSecurity is the core business of a stable, independently governed companyDivision of a conglomerate; or public with visible activist/investor pressure; or founder recently departedPE-owned, in a sale process, or publicly reported as a target
2Financial trajectoryGrowing revenue, sustained R&D investment, hiringFlat growth, margin-focused messaging, quiet cost-cuttingDeclining revenue, layoffs, executive exodus, guidance downgrades
3Strategic attractivenessUnlikely target — too large, too integrated, or recently acquired and stabilisedPlausible target — solid position in a category adjacent to what platform builders are assemblingPrime target — category leader in a hot niche (identity, cloud, AI security), frequently named in deal speculation
4Your concentrationOne point solution; losing it is a project, not a crisisTwo or three adjacent functions on their stackPlatform hosting multiple critical functions — endpoint, identity, SIEM — under one agreement
5Your contractual exit postureStrong data export rights, ≤12-month terms, price protection on renewal, tested migration pathStandard terms; export possible but untested; some renewal protectionMulti-year lock-in, proprietary detection content and telemetry formats, no price caps, no rehearsed exit

Reading your score:

  • 5–7 — Low exposure. Monitor. Re-score annually and after any ownership news.
  • 8–11 — Medium exposure. Act at the next renewal: negotiate the protections below, document a credible (not necessarily rehearsed) exit path, and resist deepening concentration with this vendor until the contractual posture improves.
  • 12–15 — High exposure. Act now, not at renewal. Prioritise data portability and contractual protection immediately, build and test an exit plan for the most critical function on their stack, and treat any proposal to consolidate further onto this vendor as a board-level risk decision.

Two honest caveats. First, factors 1–3 are judgement calls based on public information — score them roughly and don’t agonise; the trend across years matters more than the number. Second, notice that factors 4 and 5 are entirely within your control, and they’re also the ones that determine whether an acquisition is a headline or a crisis for you. That’s not an accident. The framework’s real output isn’t a prediction about the vendor. It’s a measurement of your own preparedness.

One thing this site won’t do is publish scored verdicts on named, living vendors. Partly because a score assigned today is stale by the next earnings call — but mostly because the point of the framework is that your concentration and your contract change the answer. Two organisations running the same vendor can legitimately score it 7 and 13. Score your own.


What to actually do about a high score

A high score is not an instruction to rip out a platform. Consolidation done with open eyes can still be the right call. It’s an instruction to buy your insurance while it’s cheap — which is at signing and renewal, never after the acquisition announcement.

Contract levers, in rough priority order:

  • Data export rights, in usable formats. Your telemetry, cases, detection content, and configuration — with format and assistance obligations specified. This is the single highest-value clause and the one most often missing.
  • Term length against concentration. The more functions a vendor hosts for you, the shorter your commitment should be, or the stronger your protections must be to justify length. Most buyers do the opposite, trading long terms for discounts precisely where they can least afford lock-in.
  • Renewal price protection. Caps on renewal increases, in numbers, in the contract. Post-acquisition price shocks arrive at renewal; this is the clause that meets them.
  • Change-of-control provisions. Termination or renegotiation rights on change of ownership are hard to win, but even weaker versions — locked pricing for a defined period post-acquisition — are worth the negotiating capital for your most concentrated vendor.
  • Support and SLA commitments that survive. Named service levels with remedies, not marketing-tier descriptions that quietly reorganise after a deal.

Operational levers:

  • Rehearse the exit for your most concentrated function. Not a paper plan — an actual test: export the data, stand up an alternative in a lab, time it. The organisations that escaped the worst of the recent virtualisation squeeze were the ones who had already priced and piloted alternatives when the renewal quote landed.
  • Keep your telemetry portable. Where feasible, land security telemetry somewhere you control — even a cheap archive tier — rather than exclusively inside the vendor’s platform. Detection content rebuilt from scratch is painful; history you can never retrieve is worse.
  • Diversify the identity plane deliberately. Of everything being folded into platforms right now, identity is the function you can least afford to have degrade mid-squeeze. Whatever your consolidation posture elsewhere, know exactly how you’d move it.

And a disclosure that belongs in the body of this article, not the footer: this site earns affiliate commissions from security vendors — including, inevitably, vendors participating in the platformisation trend this article warns about. I’m telling you to score their acquisition risk anyway. That’s the deal here.


The bottom line

Symantec wasn’t an aberration. It was a demonstration of what the economics of security software permit: a category-defining company converted, in a matter of years, into a harvesting operation — with customers funding the harvest because leaving was harder than paying. VMware proved the playbook scales. And the current platformisation wave, whatever its genuine operational merits, is systematically manufacturing the precondition that makes the playbook work: concentrated, locked-in, hard-to-leave customer bases.

Consolidate if the operational case is real. But score the vendor first, fix your contract and your exits while you still have leverage, and never confuse “one throat to choke” with control. When the ownership changes — and in this industry, it changes — the hand on the throat may not be yours.


Plain Text Security earns affiliate commissions from some products we link to. This article contains no affiliate links — our analysis here, as everywhere, is based on practitioner experience. Read our full affiliate disclosure.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *