kinetic8
Customer story · Financial services

Better with every source

A Gulf financial services institute connected three of the security tools it already owned. It had answers inside the first sync — and every source added since has made those answers sharper.

Sector
Financial services
Real estate size
~700 endpoints
Sources at go-live
3, more onboarding
Time to first finding
One sync
New agents deployed
None

A question that deserved a straight answer

The institute ran a mature stack: cloud identity for device registration, a vulnerability platform for scanning, and an allowlisting agent on the endpoints. Each was well run. Each produced a defensible inventory. They simply counted different things.

That left one question harder to answer than it should have been: how many machines do we have, and which ones matter? Coverage was reported against a denominator the team could not fully stand behind, and risk was reported per tool — so a single laptop could appear three times with three different scores, while a machine seen by only one tool looked, at a glance, perfectly healthy.

What three connectors returned on day one

~700
Real endpoints identified, against ~1,800 records across the tools
~2 in 3
Identity records were historic registrations, still listed as active
~half
Of scanned hosts arrived unnamed — scanning was running uncredentialed
~30%
Of the relationship map described software and hosts already retired

Four things that changed

Inventory

A device count worth putting in front of a board

Most of the surplus turned out to be years of device registrations that identity directories accumulate by design and never remove — valid objects, invisible in the directory’s own console. kinetic8 surfaced them with dates rather than deleting or quietly merging them, so the institute’s own infrastructure team ran the cleanup against a list it could defend. Reporting is reversible; deletion is not.

Data quality

A prioritised fix list for tools already owned

Around half the scanned hosts arrived without a name, and only a handful carried a scanner agent. One setting — scanning without credentials — explained four symptoms the team had been treating separately. The remedy came back ranked by leverage: enable credentialed scanning, extend agent coverage, then reposition scanners. Their scanning roadmap came out of an inventory platform.

Accuracy

A map that forgets, not only remembers

The team flagged a case where uninstalled software still showed as running on three machines at critical severity. They were right — one instance was real, two were history. About a third of the relationship map was retired, the genuine critical finding was kept at full severity, and retirement now runs continuously, standing down when a feed looks incomplete rather than mistaking a quiet source for a decommissioned fleet.

Risk

Risk that survives its own denominator

A laptop that exists three times has its exposure counted three times and its criticality averaged into noise. After reconciliation, risk from all three tools accrues to one record, so genuinely critical machines rise to the top of the list — and a device present in two controls but missing from the third finally reads as a control gap rather than another duplicate.

Where the risk actually fell — and what it did not cost

Both halves of this matter to a budget holder. The risk reduction came from correcting numbers that were wrong in the reassuring direction; the saving came from the fact that none of it required new spend.

Risk reduced

  • Critical machines stopped hiding in plain sight. Risk from three tools now accrues to one record instead of being averaged across a machine’s own duplicates, so the genuinely critical hosts rise to the top of the queue.

  • Vulnerability coverage was overstated. With around half the scanned hosts arriving unnamed and no operating system resolved, “we scan everything” was not the same as “we assess everything”. That gap is now measured rather than assumed.

  • Dormant access became visible. Roughly a thousand device registrations sat enabled and unused, some for years. Enabled and forgotten is standing attack surface, and it now appears on a list with dates.

  • Control gaps became assertable. A device present in two controls and absent from the third is now a stated fact rather than something indistinguishable from a duplicate.

  • Remediation aimed at the right host. A critical finding on software already uninstalled was withdrawn from two machines and retained at full severity on the one where it was real.

Cost avoided

  • No new sensors. Every finding came from tools already licensed and running — no agents deployed, no scanners bought, no infrastructure added.

  • Four workstreams collapsed into one fix. Four symptoms the team had been resourcing separately traced back to a single scanner setting.

  • A right-sized inventory is a commercial lever. Where endpoint tooling is licensed per device, paying against an inflated record count is paying for machines that no longer exist.

  • Fewer false remediation tickets. Retiring roughly a third of a stale relationship map removes work that was being raised against software and hosts already gone — one such ticket had already reached the team.

  • Audit preparation stopped being a project. One reconciled count, produced continuously, replaces a manual reconciliation each cycle.

Why the fourth source is worth more than the first

Not every duplicate resolved on three sources, and that is precisely the argument for onboarding more.

A join between two records is only trustworthy when something independent agrees. With two sources and a shared name there is one piece of evidence and no second opinion, so the platform holds back rather than guessing. Add a third system that sees the same machine and the pair clears on evidence instead of optimism. The tidy one-to-one duplicate is the hardest case to close — and the one a new source resolves immediately.

Sources also differ in what they can prove. A directory mints a new object on every registration event, so its record count is not a device count. An agent runs on the machine itself, so its count is the machine count — which is what lets duplicates collapse safely and genuinely distinct machines sharing a name be kept apart. A credentialed scanner supplies the strong identifiers that make every other join defensible. Each connector contributes something the others structurally cannot.

The first source produces a list. The second produces disagreement. The third makes that disagreement decidable. From the fourth onward, every connector both closes joins that were previously impossible and becomes a new lens on every asset already in the system — retroactively, with no re-work.

Coverage works the same way. A machine present in four systems and absent from the fifth is a control gap stated as a fact — and that question cannot be asked at all until the fifth system is connected. The curve does not flatten. It steepens.

What a CIO, CTO or CISO takes away

  • A defensible number. One asset count, with the reconciliation behind it available on demand for audit and regulator questions.

  • Spend directed by evidence. The biggest wins were configuration and hygiene in tools already paid for — not a licence still to be bought.

  • Risk reported on real machines. Criticality that no longer dilutes across duplicates, and coverage measured against a denominator that holds up.

  • Value inside the first sync. Three connectors, no new agents, no new scanners, findings on day one.

  • A return that compounds. Every source added improves the accuracy of everything already connected, instead of adding one more list to reconcile.

The institute did not buy a new sensor. It gained an arbiter for the sensors it already had — one that grows sharper with every sensor it is handed.


Anonymised customer story. The organisation is not named; hostnames, identifiers and personal names have been removed, and all figures are rounded. Each is drawn from measurements of that customer’s production environment.

Start with the sources you already own

Request a live demo — we'll map your environment in the session.

Request Demo