Count the software your company pays for. Not the ones you would name off the top of your head. All of them. The project tool the operations lead brought from her last job. The e-signature service. The second e-signature service somebody bought when the first hit its seat limit. The scheduling app, the two file sharing services, the form builder, the survey tool, the chat platform you use alongside the chat that came free with your email.
Most small businesses we meet run somewhere between thirty and sixty subscriptions. Almost none of them chose that number. It accumulated one reasonable decision at a time, and each of those decisions solved a real problem the day it was made. The trouble is not any single tool. It is what happens when nobody ever removes one. Consolidation is not about being cheap. It is about being able to describe your own environment in one conversation.
How a Twenty Person Company Ends Up With Forty Tools
Sprawl is not a discipline problem. It is the predictable result of three things being true at once.
- Buying is trivially easy. A credit card and four minutes gets anyone a business account, and the monthly charge is small enough to clear expense review unquestioned.
- Nothing forces a review. Subscriptions renew silently. A tool that stopped being useful in March still bills in November, because canceling requires somebody to notice and then care.
- New hires bring their favorites. Everyone arrives fluent in the stack from their last job and wants to use it. Do that four times and you have four overlapping systems.
We covered the security and legal side of unmanaged software in our piece on shadow IT. This is the sanctioned version of the same problem: tools you know about, pay for, and still cannot fully account for.
What Each Extra Tool Actually Costs
The subscription fee is the smallest line item. The real costs never hit an invoice.
- Another login to protect. Another password, another place multi-factor authentication is or is not turned on, another account that can be phished.
- Another company holding your data. You inherit their security, their outages, and their business decisions. If they get breached, your customer list was in there.
- Another thing to keep current. CISA’s Cyber Essentials guidance tells organizations to “remove unsupported or unauthorized hardware and software from systems,” because supported assets “allow you to receive updates and patches for vulnerabilities that otherwise are not available.” You cannot judge that for software you forgot you own.
- Another door a departed employee still holds. This one bites hardest. CISA’s guidance is explicit about the need to “identify and deactivate unused accounts” and to develop procedures “addressing changes in user status (transfers, termination, etc.).” Straightforward across five systems, nearly impossible across forty.
The Center for Internet Security puts asset inventory first among its critical security controls for this reason, describing it as actively managing “all enterprise assets” so an organization can “accurately know the totality of assets that need to be monitored and protected.” NIST frames the same idea as the Identify function of its Cybersecurity Framework: determine current cybersecurity risks to the business. Inventory is the precondition for every other control.
The Audit Question That Cuts Through It
Here is the exercise. Export twelve months of card and bank statements, list every recurring software charge, and put a name next to each. Then ask one question about each tool: if this disappeared tomorrow, what would actually break?
The answers sort into four piles fast, and the sorting is usually uncomfortable in a productive way.
- Nothing would break. Cancel it. Expect this pile to be bigger than you predicted, and expect at least one tool nobody can identify.
- One person would be annoyed. Worth a conversation. Often that person did not know the capability already exists in a platform you pay for.
- A process would stop. Keep it, and now you know it is load bearing. Give it documentation, a named owner, and a look at who currently holds accounts. That user list is where former employees and old vendor logins tend to be waiting.
- We would be down. This is your true critical list. It should be short, and every item on it needs a plan for the day the vendor has a bad week, a point we made in our piece on what a cloud outage means for your business.
Adequate and Configured Beats Excellent and Ignored
Here we will be openly opinionated. For a company under a hundred people, one platform that covers five needs adequately beats five best in class tools nobody has time to configure properly.
Not because specialized tools are worse. They are usually better at the specific job. It is that software delivers value in proportion to how well it is set up, adopted, and maintained, and your company has a fixed budget of attention. Split it across five systems and each gets a fifth of the setup, training, and care. A merely good tool everyone uses correctly beats an excellent one that three people understand and the rest work around.
The math runs in your favor on security too. Fewer platforms means fewer places to enable multi-factor authentication, fewer vendors to evaluate, fewer permission sets to review, and a shorter offboarding checklist. Those are exactly the tasks that go undone when the list gets long.
There are real exceptions. Keep the specialized tool when it is central to how you make money, when it is irreplaceable for a licensed or regulated workflow, or when switching costs run to years of historical data. Consolidation is a default, not a rule.
How to Consolidate Without a Painful Migration
Most consolidation efforts fail because they get run as projects: a big cutover weekend, everything moving at once, one bad surprise that convinces everyone the old way was fine. Do it slowly instead, one tool per month.
- Start with the “nothing would break” pile. Cancelling unused subscriptions is pure gain with no migration and no training, and it builds credibility for harder moves.
- Pick one duplicate pair. Two tools doing the same job is the easiest real consolidation, because you are not introducing anything new. You are choosing between two things people know.
- Run parallel briefly, then set a hard stop. Overlap a few weeks so nobody panics, then actually turn the old one off. Indefinite overlap is how you end up with both tools forever.
- Export before you cancel. Pull your historical data out first and store it somewhere you control. Vendors are not obligated to keep it after the account closes.
- Add one approval gate. New recurring software gets one named person’s sign off. Not a committee, not a form. One person who asks whether something you already own does the job.
The Bottom Line
The instinct when something is not working is to add a tool. Often the better move is to subtract two. Every subscription you remove is one fewer login to protect, one fewer vendor holding your data, one fewer thing to patch, one fewer place a former employee still has a way in.
Start with the statement review and the disappearance question. Cancel what nobody would miss. Consolidate obvious duplicates one at a time, with an export before each cancellation and a real end date for the old system. Keep what earns its place, and be honest about what does not. The goal is not a minimal stack for its own sake. It is a stack you can describe, secure, and hand to somebody else if you had to.
We run this audit regularly for businesses across Denton County: a full inventory of what you pay for, who has access, what overlaps, and a realistic plan to simplify without disrupting anyone’s week. Contact us today.
Sources:
Comments are closed