The enterprise security industry is operating with a structural ceiling.

Every major security vendor in your environment runs above the operating system kernel. That was a reasonable architectural choice twenty years ago when the threat model looked different. It has become the ceiling that keeps the industry from making defense materially easier. The attacks that take down Fortune-scale organizations in 2024 and 2025 are operating at layers your agents are loaded after and your firewalls have no visibility into.

This is not a critique of any specific vendor. The incumbent EDR platforms, network appliance leaders, edge providers, and identity suites are competent, well-engineered products built by serious people. They share an architectural position, and that shared position is now the limiting factor on defender outcomes. The question is not whether to replace them. The question is what sits underneath them, and where the industry goes next.

Position 01
Attacks have moved below the kernel
Modern ransomware increasingly establishes persistence in firmware and boot-stage loaders. By the time Windows loads, the attacker is already resident. Every endpoint agent your organization runs is loaded after the fact. This is a property of the architecture, not a gap that more EDR will close.
Position 02
The security stack is a supply chain
SolarWinds, MOVEit, Kaseya, major identity-platform breaches, and the July 2024 kernel driver event have demonstrated that the security stack is itself a viable attack vector. A vendor compromise propagates to every customer. Defender posture has become coupled to the cumulative security posture of every vendor in the stack.
Position 03
Identity has become the primary vector
MFA bypass, session token theft, SIM swapping, and OAuth abuse have effectively neutralized the last generation of account-takeover defenses. Every vendor in the identity market sells MFA. None can reliably detect a valid session being used adversarially. The credential model has architectural limits that stacking more credentials will not solve.
Position 04
Defense economics are diverging from the attacker's
Ransomware-as-a-service, AI-assisted malware generation, and the professionalization of offensive operations have collapsed the cost of attacking. The cost of maintaining defensive parity has not. The two curves continue to diverge. Organizations that can change the shape of their attack surface have an advantage organizations that cannot will not.