Panel: Modernizing Security Architecture: Platforms or Best-of-Breed, What Works?
Nullcon Goa 2025 · Panel
Overview
In an insightful panel discussion at Nullcon, moderated by Rahul Neil Money from Information Security Media Group, leading cybersecurity executives delved into one of the most persistent dilemmas facing modern enterprises: whether to adopt comprehensive security platforms from single vendors or opt for a best-of-breed approach by integrating specialized tools from multiple providers. The discussion, featuring CISOs Shrihari Kotani (Geo Finance), Pragal Kulkarni (Grow), and security leaders Ketan Vas (TCS) and Satyawati Deadri (Freshworks), highlighted the complexities, trade-offs, and evolving strategies in designing resilient security architectures.

Key moments
- 0:00 Moderator's opening and panel topic introduction
- 1:26 Introduction of the expert panelists
- 2:10 Setting the stage: Best-of-breed vs. Platformization
- 4:45 Shrihari Kotani's perspective: Historical context and balanced approach
- 7:50 Ketan Vas's view: Offensive vs. defensive tools, praising pentesters
Panel: Modernizing Security Architecture: Platforms or Best-of-Breed, What Works?
Speakers: Rahul Neil Money (Moderator), Shrihari Kotani (CISO, Geo Finance), Ketan Vas (Head of Application Security, TCS), Satyawati Deadri (Deputy CISO, Freshworks), Pragal Kulkarni (CISO, Grow)
Conference: Nullcon
YouTube: https://www.youtube.com/watch?v=GyQNbrZNrdg
Overview
In an insightful panel discussion at Nullcon, moderated by Rahul Neil Money from Information Security Media Group, leading cybersecurity executives delved into one of the most persistent dilemmas facing modern enterprises: whether to adopt comprehensive security platforms from single vendors or opt for a best-of-breed approach by integrating specialized tools from multiple providers. The discussion, featuring CISOs Shrihari Kotani (Geo Finance), Pragal Kulkarni (Grow), and security leaders Ketan Vas (TCS) and Satyawati Deadri (Freshworks), highlighted the complexities, trade-offs, and evolving strategies in designing resilient security architectures.
The core of the debate revolved around managing complexity, optimizing costs, and ensuring effective protection against an ever-evolving threat landscape. As organizations grapple with an average sprawl of 40 to 50 security products, the appeal of consolidation through platforms is strong. However, the panelists explored whether these all-encompassing solutions truly meet diverse organizational needs or if niche, specialized products still offer superior capabilities in critical areas. This article provides a comprehensive analysis of their perspectives, uncovering the nuanced considerations that drive architectural decisions in today's dynamic cybersecurity environment.
Background
▶ Watch: Moderator's opening and panel topic introduction (0:00)
The journey of cybersecurity architecture, as articulated by the panelists, has seen significant shifts over the past two decades. Shrihari Kotani recalled a time, some 20 years ago, when the CISO's primary dilemma was the scarcity of security solutions. Technologies like disk encryption and privileged access management (PAM) were either nascent or non-existent, and the focus was on adding point solutions as they emerged, starting from foundational elements like VPNs. This era led to a rapid proliferation of tools, with organizations accumulating anywhere from 40 to 50, or even more, distinct security products to address various risks and compliance requirements. This best-of-breed strategy, while ensuring specific needs were met, inevitably introduced immense complexity in management, integration, and operational overhead.
However, the industry has witnessed a concerted push over the last four to six years towards consolidation and platformization. Cybersecurity vendors, through both organic development and aggressive acquisitions, have expanded their portfolios dramatically, aiming to offer a one-stop shop for a wide array of security functions. The promise of these platforms is reduced complexity, simplified vendor management, and potentially lower costs by bundling multiple capabilities. Yet, as the panel explored, this vendor-driven narrative often clashes with the practical realities faced by CISOs. The debate is far from settled, with strong arguments still supporting the agility, specialized features, and competitive edge offered by best-of-breed solutions, especially when platforms struggle to deliver on all their promised functionalities or meet specific, high-stakes requirements.
Key Findings
▶ Watch: Introduction of the expert panelists (1:26)
The panel discussion revealed a consensus that there is no universal "right" answer to the platform versus best-of-breed debate; instead, a hybrid approach is pragmatic and necessary for most organizations.
- No Single Solution: Satyawati Deadri emphasized that no single platform can solve "the entire universe's problem," whether it's EDR, XDR, cloud security, or IoT. The decision often boils down to the ease of adding modules, cost-effectiveness, and the superior features offered by niche products.
- Offensive vs. Defensive Distinction: Ketan Vas introduced a fresh perspective by categorizing products into offensive and defensive. He suggested that niche products are often more useful on the offensive side (e.g., for penetration testers and bounty hunters), while platforms excel in defensive areas requiring stability and sustained support. He candidly admitted, "there is no tool which can currently beat the pentesters who are bounty hunters."
- Cost and Feature Trade-offs: The panelists acknowledged that while vendors claim platforms save money, they often require buying separate modules, negating some cost benefits. Furthermore, platform modules might not always meet specific requirements or be fully mature. Satyawati highlighted the challenge of justifying additional budget for a platform module when a different, specialized product offers better features in that niche. Pragal Kulkarni stressed that cost is always a matter, despite claims otherwise, and CISOs must prove the value of their investments.
- Vendor Competition and Innovation: Satyawati noted that having multiple vendors (even competitors) supplying different products can keep them "on their toes," fostering competition and driving better results during renewals. This competitive dynamic can lead to better features and pricing.
- Emerging Problem Statements: The panel identified critical areas where platforms are currently falling short, presenting opportunities for specialized solutions or in-house development:
- AI Model Security: The need to defend against AI model poisoning, bias, and drift was highlighted by Satyawati as a "niche subject" where current Security Operations Center (SOC) tools are inadequate.
- Browser Extension Security: An audience member raised the significant challenge of end-users downloading browser extensions that go undetected and unblocked by existing security tools, even best-of-breed ones. This led to an organization developing its own custom solution.
- Passwordless Authentication: Satyawati pointed out that even "the oldest problem to solve," password management and the move towards passwordless, still sees hundreds of innovative products emerging, demonstrating that even fundamental issues can spawn niche solutions.
- The Human Element: Pragal emphasized the critical role of "smart people on the team" who can "figure out the tools." Satyawati reinforced this by stating, "systems do not introduce vulnerabilities. It is humans who introduce vulnerabilities," underscoring the need for skilled personnel who understand how to effectively use security tools, even the best ones.
Ultimately, the key finding is that a successful security architecture leverages the strengths of both platforms for foundational stability and best-of-breed solutions for critical, specialized, or emerging challenges, all while being underpinned by a capable internal team.
Technical Deep Dive
▶ Watch: Setting the stage: Best-of-breed vs. Platformization (2:10)
While a panel discussion does not typically delve into code or specific protocol implementations, the conversation provided significant technical considerations and identified specific domains and types of security solutions. The panelists explored the technical capabilities and limitations of both platformized and best-of-breed approaches across various cybersecurity areas.
Platformization: Promises and Pitfalls
Shrihari Kotani noted that major vendors now offer a vast array of products, sometimes 85-90 items, aiming for comprehensive coverage. The perceived technical advantages of platforms include:
- Consolidation: A single pane of glass for management, potentially reducing integration headaches.
- Cost Savings: While often debated, the idea is that bundling leads to economies of scale.
However, the technical reality can be complex. Shrihari pointed out that platforms are often modular, meaning organizations still "have to pay for the module" for each product, similar to buying individual solutions. More critically, he highlighted that some products offered by platforms "may not be actually meeting your requirements," either because they are evolving or "not fully ready." This technical immaturity or lack of specialized features often necessitates looking beyond the platform.
Best-of-Breed: Niche Superiority
The panelists consistently argued for the technical superiority of best-of-breed solutions in specific, critical areas.
- Niche Features: As Satyawati articulated, specialized vendors "offer the best in that particular niche area." This is crucial for functionalities where no compromise is acceptable.
- Offensive Security: Ketan Vas's observation that "niche products are very useful" on the offensive side, especially for penetration testing and bounty hunting, underscores their specialized capabilities in adversarial simulation and vulnerability discovery.
- Specific Problem Domains:
- DLP (Data Loss Prevention): Shrihari explicitly mentioned that while DLP platforms might claim to offer comprehensive solutions, they often "are not able to do it," requiring organizations to seek specialized DLP products.
- IAM (Identity and Access Management) / Identity Governance: Similar to DLP, Shrihari stated that platforms often struggle to fully address the complexities of IAM and identity governance, necessitating dedicated products.
- EDR/XDR: Pragal Kulkarni categorized XDRs and EDRs as areas where "the best in breed of the product vendors... have honed their capabilities over years" and are unlikely to be fully replaced by platform offerings as a first approach.
- Cloud-Native Security Controls: Satyawati emphasized the need for "cloud native security controls that make our product delivery faster" for dynamic, fast-moving organizations, implying that specialized, agile solutions are preferred over potentially monolithic platform components.
Emerging Technical Challenges and In-house Innovation
The discussion ventured into nascent technical domains where existing solutions, whether platform or best-of-breed, are largely inadequate.
- AI Model Security: Satyawati pointed to the critical need for defense mechanisms for AI models against poisoning, bias, and drift. She noted that "none of the sock tools... are addressing AI related vulnerabilities or configuration misconfiguration ideas into sock." This represents a significant technical gap. An audience member, Rajiv Behel from St. Fox (and OAS Foundation), further elaborated on AI red teaming tools and the need for continuous evaluation in AI, citing work by OAS AI exchange and their own forthcoming tool. This highlights a new frontier in security requiring specialized technical approaches.
- Browser Extension Security: An audience member described a common yet unaddressed problem: end-users downloading browser extensions that bypass detection by "any of the security tools." Their organization addressed this by developing a custom solution:
- Collecting all browser extensions from 85,000 endpoints using internal bots.
- Creating a reference set in their SIEM tool.
- Blocking detected hash files at the EDR level.
This demonstrates a technical gap filled by in-house engineering and open-source tools, as Shrihari suggested, "better to solve it yourself because the turnar around by sometimes the vendors is so long."
- GenAI-based DLP Operations: The most striking example of in-house technical innovation came from the CEO of CIO for Fractal Analytics, who shared their development of a "completely autonomous GenAI-based DLP operations application." This solution, built in-house in "a couple of months," replaces manual L1/L2 operations, works 24/7, has "false positives down to zero," and is "completely real time." This is a significant technical disruption, leveraging Generative AI to solve a long-standing, labor-intensive problem where traditional DLP OEMs often fall short.
Prioritizing Future Defensive Areas
Ketan Vas suggested focusing on automating manual work, especially in SOC operations, to combat alert fatigue. He also highlighted the need for "a right data set... for building the security models" as a critical area for future defensive innovation, particularly in the context of AI. Shrihari added attack surface management, brand monitoring, and bug bounty programs as areas currently delivering "great value" for CISOs, indicating their technical effectiveness in proactive defense.
The technical discussion, therefore, transcended a simple product comparison, exploring the architectural choices, the specific capabilities required for different threats, and the increasing role of internal engineering and emerging technologies like GenAI in filling critical security gaps.
Demo / Proof of Concept
▶ Watch: Shrihari Kotani's perspective: Historical context and balanced approach (4:45)
As a panel discussion, this event did not feature a live technical demonstration or a traditional proof of concept. The format was entirely conversational, with speakers sharing their experiences, insights, and opinions on the complex topic of security architecture.
However, the discussion did highlight examples of successful conceptual proofs of concept and in-house implementations that serve a similar purpose. Notably, the representative from Fractal Analytics shared their achievement of developing a "completely autonomous GenAI-based DLP operations application" in-house within a few months. This initiative, which replaced manual L1 and L2 operations, achieved real-time data protection with zero false positives, effectively serving as a powerful proof of concept for leveraging emerging technologies to solve persistent security challenges outside the traditional vendor ecosystem. Similarly, the audience member's description of their custom solution for detecting and blocking browser extensions across 85,000 endpoints, using bots, SIEM integration, and EDR-level blocking, functions as an operational proof of concept for addressing a specific security gap through internal engineering. These examples underscore the capability of organizations to build effective solutions when commercial offerings fall short.
Defensive Implications
▶ Watch: Ketan Vas's view: Offensive vs. defensive tools, praising pentesters (7:50)
The insights from the panel provide crucial guidance for security defenders navigating the complex landscape of modern security architecture. The overarching implication is the necessity of a strategic, hybrid, and adaptive approach rather than rigid adherence to either platforms or best-of-breed solutions.
- Embrace a Hybrid Architecture: Defenders should recognize that a blend of platforms and specialized tools is almost always the most pragmatic path. For foundational security controls, platforms can offer stability, consolidated management, and cost efficiencies. However, for highly critical, niche, or rapidly evolving threats, best-of-breed solutions often provide superior features and responsiveness. As Pragal Kulkarni suggested, areas where you "don't want to compromise" should leverage best-of-breed, while "peripheral" or "non-critical" areas can experiment with platforms.
- Prioritize Risk-Based Tool Selection: Security leaders must meticulously evaluate solutions based on their specific risk appetite and organizational context. Shrihari Kotani emphasized that if a platform's offerings don't meet requirements, defenders "should not compromise" and must acquire the necessary point solution. This involves thorough Proof of Concept (PoC) testing of vendor claims, rather than simply accepting forward-looking statements.
- Invest in Internal Engineering Capabilities: A recurring theme was the increasing importance of in-house engineering teams. These teams are vital for:
- Making solutions work: As Shrihari stated, CISOs "recruit the engineering team which makes the solutions works."
- Filling gaps: Developing custom tools, like the GenAI-based DLP at Fractal Analytics or the browser extension blocker, to address problems unserved by commercial vendors. This often involves leveraging open-source tools, ELK stacks, and APIs.
- Automating operational tasks: Ketan Vas advocated for automating manual work, especially in SOC operations, to combat alert fatigue and improve efficiency.
- Vendor independence: Reducing reliance on vendors for every problem, especially when vendor turnaround times are long.
- Focus on Emerging Threat Vectors: Defenders must proactively address new and evolving threats that current tools may not adequately cover.
- AI Security: Prioritize securing AI models against poisoning, bias, and drift. This requires exploring new AI red teaming tools and potentially developing internal guardrails.
- Endpoint and Browser Security: Given the prevalence of unmonitored browser extensions, organizations need to implement robust controls, which may involve custom solutions, endpoint monitoring, and strict policy enforcement.
- Strengthen Foundational Controls and Resilience: Beyond specific tools, the panel stressed the importance of core security practices:
- IT General Controls (ITGC): Shrihari highlighted that strong ITGC processes are fundamental, especially for recovery from attacks like ransomware, which often exploit authentication weaknesses rather than just vulnerabilities.
- Strong Authentication and MFA: Satyawati emphasized the critical role of "strong authentication mechanism and strong MFA in place" as a basic yet powerful defense.
- Assume Breach Mentality: Defenders should operate under the assumption that a breach is inevitable. Satyawati advocated for regular preparation exercises like war rooms and tabletop exercises to test incident response plans.
- Breach and Attack Simulation (BAS): Ketan Vas suggested BAS not only for systems but also "on people" to empower them to make decisions and gain experience.
- Empower and Develop People: The human element is paramount. As Pragal Kulkarni stated, "smart people on the team they will figure out the tools." Defenders should:
- Invest in training: Ensure teams are proficient with all deployed tools.
- Foster critical thinking: Encourage teams to understand how tools work and identify vulnerabilities in systems and human processes.
- Empower decision-making: Allow teams to make decisions, even if they sometimes fail, to build experience and resilience.
By integrating these defensive implications, organizations can build a more robust, agile, and future-proof security architecture capable of adapting to the rapid pace of cyber threats and technological evolution.
Key Takeaways
- Hybrid Approach is Key: There is no single answer; a strategic blend of comprehensive security platforms and specialized best-of-breed tools is essential for most organizations.
- Prioritize Risk and Requirements: Choose best-of-breed for critical, niche functionalities where compromise is unacceptable, and platforms for broader coverage or less sensitive areas. Thoroughly test vendor claims with PoCs.
- Invest in Internal Engineering: Build and empower in-house engineering teams to integrate tools, automate operations (e.g., SOC tasks), and develop custom solutions for unique or unaddressed problems (e.g., AI security, browser extensions).
- Focus on Emerging Threats: Proactively address new challenges like AI model poisoning, bias, and drift, as well as often-overlooked issues like malicious browser extensions, where commercial tools may be lacking.
- People Over Products: The effectiveness of any security architecture ultimately hinges on the skills, intelligence, and preparedness of the security team. Invest in training, critical thinking, and empowering personnel.
- Build Resilience, Assume Breach: Develop a mindset of anticipating breaches. Implement strong foundational controls (ITGC, MFA), conduct regular incident response drills (tabletop exercises, war rooms), and perform breach and attack simulations to enhance organizational resilience.
About the Speaker(s)
- Rahul Neil Money (Moderator): Rahul works for Information Security Media Group, holding a dual responsibility for introducing the panel and moderating the discussion. He emphasizes audience participation and aims to speak the least during the panel.
- Shrihari Kotani: Shrihari serves as the CISO of Geo Finance. With over 20 years of experience in the security domain, he provides a historical perspective on the evolution of security solutions and the challenges CISOs face.
- Ketan Vas: Ketan is the Head of Application Security at TCS. He offers a unique perspective by categorizing security products into offensive and defensive, highlighting the efficacy of niche tools in offensive security.
- Satyawati Deadri: Satyawati is the Deputy CISO of Freshworks. She contributes insights on the practical challenges of integrating platform modules versus best-of-breed products, focusing on detection speed and response capabilities.
- Pragal Kulkarni: Pragal is the CISO of Grow, a financial institution. He advocates for a hybrid approach to security architecture, emphasizing the importance of internal team capabilities and the need for smart people to leverage security tools effectively.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A panel that mistakes practitioner war stories for strategic insight, delivering a 'hybrid approach is best' conclusion that any CISO already knew before sitting down. The conversation occasionally surfaces interesting anecdotes — the GenAI-DLP build, the browser extension home-brew — but never gets specific enough about tradeoffs, costs, or failure modes to be genuinely useful.
Heather Calloway (CISO) — SOLID
A competent practitioner panel that validates what most experienced CISOs already know: hybrid wins, people matter, emerging gaps exist. The conversation is honest and grounded, but it doesn't move the needle — it confirms received wisdom rather than sharpening it into decisions.