Announcing ESProfiler 2.0
ESProfiler has reached a major milestone. Our new release brings evidence to its core, providing a view of your security stack backed by knowledge from people on the ground and integrations directly with your tools. ESProfiler 2.0 ensures you have a clear grasp on your security stack: its gaps, consolidation opportunities and risks, not just now, but continuously into the future.

You cannot govern, cut, or defend millions of dollars of cyber investment against a stack you cannot describe.
ESProfiler is a living picture of your cyber maturity - all of your contracts, all of your products, and full coverage mapping against any compliance and cyber frameworks you operate with, all backed with evidence from people on the ground and integrations with the products themselves.
Not only that, but ESProfiler's underlying intelligence is continuously evaluating not just your security stack, but the entire cyber market. Every merger & acquisition, new product or vendor on the market, and every new capability shipped into the products you already own is surfaced within ESProfiler.
With ESProfiler you can be sure that your security stack is completely optimised whatever your budget constraints.
New with ESProfiler 2.0
Evidence Layer - Turning Theory into Reality
ESProfiler has built it's foundations on being able to map any product capability onto cybersecurity and compliance frameworks, however, these always showed an "ideal" scenario.
Until now, it assumed you were using every part of every product you own, and that just isn't the reality on the ground, so that's why in ESProfiler 2.0, we've introduce the "Evidence Layer".
Evidence Layer turns theory into reality with data gathered from people on the ground (Tribal Knowledge) and validates feature usage directly from the tools you have in your security stack (Integrations).
By combining continuous discovery and validation of tribal knowledge in your organisation and the evidence pulled directly from your security products, ESProfiler can now show you the reality of your security posture and maturity, all backed in auditable evidence.
As a result, ESProfiler now provides you much more clarity over where you need to focus your attention - whether that's through risks and opportunities raised by your team or areas where you're underutilising the tools you already own.
Tribal Layer - Uncovering Institutional Knowledge
Establishing security maturity is a costly exercise, it requires hundreds of hours of interviewing products owners and users on the ground to build a rich picture of how every security tool is implemented - this is where Tribal Layer comes in.
With ESProfiler we already have customers rolling out hundreds of specialist agents to run these interviews. Our expert agents collate the transcripts and then surface "Findings" and "Signals" - important items that our agents consider worthy of review.
Risks, opportunities, dependencies and more are all recorded and audited against every product in your security stack. All of this data is intuitively surfaced to you in the platform, as well as being used to update your security maturity views to ensure you always have the live picture on where your attention needs to be focused.
I knew that would happen
The phrase security experts here (or say) all of the time after every incident. With Tribal Layer there is no longer an excuse. This information will be surfaced internally long before it's found by your attackers.
Introducing "Workflows"
ESProfiler 2.0 sees the launch of our incredibly flexible and powerful new "Workflows" engine.
Workflows are available through our new intuitive drag & drop flow editor, providing two powerful features:
Automations: Workflows can be triggered on a schedule or by particular events, e.g. on M&A activity in your stack, or when you have an upcoming contract due for renewal. These automations can connect to Agentic Skills within ESProfiler, conduct market research, write reports for you based on your latest contracts or coverage and anything else you can think of.
Integrations: In ESProfiler integrations now allow you to directly connect to the tools in your security stack to validate configurations and check which features are and are not used.
Combining these together you can kick off automations that will save you weeks of research and investment:
"Alert me every time a new Merge or Acquisition effects my security stack, and tell me the impact it has on our security posture"
"Every time a contract enters a decision window, run a report on the products contained in that contract, summarise the financials and consequences of us replacing this, and what else could we replace it with?"
"When a new capability becomes available in a tool we already own - let me know. Tell me what it can replace or unlock in our stack and let me know if we can be saving money through consolidation."
Get the briefing, not the spreadsheet
Underpinning a lot of these new automations and intelligence layer is our new "Notebooks" engine, our new just-in-time reporting tool.
Notebooks can be produced in whatever format you need. You don't need to sit and crunch the numbers, ESProfiler does that for you and will present the results in an easy-to-consume format, tailored to you. If you need a slide deck for your upcoming board review, no problem, if it needs to be a rich A4 formatted report detailing your new investment strategy, easy. Notebooks are completely grounded in everything living within ESProfiler and can be edited manually or just using our in-built agent, ESPi.
Your Desk
With so much activity always going on across your security stack, it's very easy to get lost with the important actionable items that needs addressing. In ESProfiler these are surfaced as "Work Items" on "Your Desk".
Anything in ESProfiler can be converted to a work item. They can be used to track progress and actions over time. If ESProfiler identifies a gap in your security posture, open that as a Work Item and link that to the framework coverage. Set reminders to revisit the item in the future so that you can do a direct comparison of progress and report to your peers and seniors.
ESProfiler comes with a full project management interface to ensure you're making progress on enhancing your security maturity and that important risks and opportunities don't get lost into the abyss. If you don't want to use ESProfiler's in-built user experience, not a problem, Workflows, shared above, means that you can integrate ServiceNow, Jira, Paige or any other existing project management toolkits you have.
Decision Intelligence - Get Ahead
40% of a Security Architect's time is spent investigating and researching tooling due to an upcoming contract renewal. Our customers often have 100+ products in their security stack, and staying on top of the contract renewals at the right time is a difficult logistical challenge.
In ESProfiler we drive this through Decision Windows, which help you keep ahead of renewals, get products investigated at the right time, and ensure that you're not caught in the trap of unwanted spend on a product you're not using anymore.
Decision Windows consist of three parts:
Contract Notice: This is the latest date you have, written in your contract, by which you need to let the respective vendor know you want to cancel a contract.
Replacement Window: Whilst the contract notice is important, if you want to get rid of a product, it's likely you're looking to implement a replacement. Every product has an associated replacement period, which is the time estimated to replace this product with another.
Recommended Investigation: This is a buffer upfront of the replacement window + contract notice where ESProfiler recommends you start to investigate alternatives, and do an evaluation of the value of the products.
ESProfiler has built-in alerting for decision windows, and integrating that with "Your Desk" and "Workflows" means that you get a full brief written up into a trackable work item, and can trigger automated report generation or Tribal Interviews to be kicked off when the decision window begins.
With ESProfiler, you'll never get behind on a contract renewal again, you have full comfort in knowing you're protected with evidence backed by the expertise in your organisation and you can be certain that the money you're spending on your security stack is distributed in the most optimal way.
What's Next?
We aren't stopping here, our incredible product team is working hard behind the scenes as we speak to make ESProfiler better every week. If you want to find out what we're up to, and see first-hand how ESProfiler prevents capability overlap, covers gaps in your security posture and pays for itself along the way - reach out to us.
