curiousecurity

Enterprise architecture and security governance, from the board seat

  • Posts
  • About
  • Career
  • Education
  • Contact
  • LinkedIn
  • GitHub
  • Email
You are here: Home / Architecture / Best of Breed Is Usually the Wrong Call: The Integration Bill Comes Due Later

Best of Breed Is Usually the Wrong Call: The Integration Bill Comes Due Later

August 20, 2026 by The Architecture Desk

Best-of-breed is a procurement decision wearing an architecture costume. It gets treated like the rigorous choice, because somebody ran a bake-off, scored the features against a checklist, and picked the tool that came out on top, and that feels like diligence. It isn’t, not fully. Feature depth was never the whole question, it was just the question that was easy to score. The real question is what it costs to connect that tool, secure it, and carry it for the next five years, and that number never lands on the comparison sheet, because nobody was ever asked to price it at selection time (why would they be, when the RFP template doesn’t have a line for it).

That cost doesn’t vanish just because nobody priced it. It just goes quiet for a while, and then it resurfaces, as an integration nobody wants to own, an on-call rotation nobody budgeted for, or, in the worst case, a breach notification with your company’s name sitting right there on the distribution list.

Klue Wasn’t the Target, It Was the Door

In June 2026, Salesforce disabled the app integration for Klue, a competitive intelligence point solution, after attackers used a legacy credential from an abandoned 2022 prototype to get into Klue’s integration infrastructure and harvest OAuth tokens. From there they queried the Salesforce CRM data of roughly 195 to 200 customer organizations, according to The Hacker News. Nobody picked Klue because they wanted an attack surface, obviously. They picked it because it was the strongest tool in its category, and wiring it straight into Salesforce is what made it worth having in the first place. What none of those roughly 195 companies bought, on purpose anyway, was a dependency on a vendor’s abandoned prototype credentials from four years earlier, sitting there unrotated the whole time.

That’s the piece a best-of-breed evaluation structurally skips, and I don’t think it’s because anyone’s being careless, it’s just not what the process was ever built to score. You’re never scoring a tool in a vacuum. You’re scoring a tool plus every credential, token, and API path that ties it back to the systems you already depend on, and none of that connective tissue shows up anywhere on a feature matrix.

Why the Spreadsheet Never Catches Up

One best-of-breed pick is a defensible bet, I’ll sign off on that all day. Three hundred of them is a balance sheet problem. The average enterprise now runs around 275 SaaS applications, with 52.7 percent of purchased licenses sitting idle and roughly $21 million a year wasted on unused or underused seats, per Zylo’s 2025 SaaS Management Index. Every single one of those tools cleared its own bake-off, on its own merits. What nobody ever did was run the total against what the platform they’d already licensed could have done instead, because that comparison happens at a different altitude than any one selection decision, and by the time somebody’s looking at the whole portfolio, three hundred decisions are already sunk cost.

The market’s correcting for this now, on a timeline and at a price nobody actually chose. Gartner projects that 70 percent of organizations will consolidate their cloud-native application vendors down to a maximum of three strategic providers by 2027, and the same analysis notes that integration and migration costs typically eat 40 to 70 percent of the first year’s projected savings once consolidation actually starts, per a 2026 vendor consolidation analysis. None of that integration cost is new, by the way, it was always owed. Best-of-breed selection just moves it off the ARB agenda and drops it onto a consolidation project’s budget three years out instead, where it shows up with a much worse ROI story stapled to it.

Two Bars, Not One

I’m not against best-of-breed on principle, and I want to be straight about that up front. Some capability gaps are real, and worth carrying even at extra cost. What’s changed for me is the default: fit-for-purpose within the platform footprint we already operate wins the argument unless the point solution clears two bars, not one.

  • The feature bar. Does it solve a problem the incumbent platform genuinely can’t, not one it just solves less elegantly.
  • The five-year carry bar. Fully loaded, what does the integration actually cost: who owns the connector, who rotates the credentials, what’s the blast radius if this vendor turns out to be the next Klue, and does the capability gap still hold up once that liability is priced in.

The second bar is the one a vendor pitch will never bring to the table on its own, no salesperson opens the demo with “and here’s what this costs you to rotate credentials on in year four.” So it has to be a governance requirement, not a courtesy extended to whoever thinks to ask.

Where the Decision Has to Live

This is the same discipline I’ve argued for on reuse before buy before build, skipping the cheaper, already-integrated option because the newer thing demos better is the same failure mode wearing a different vendor’s logo. The decision, the integration owner, and the renewal date belong in the EAM system as a tracked node, not buried three replies deep in a Slack thread from the original RFP that nobody can find again. That’s why I run every one of these through LeanIX as the system of record instead of trusting a spreadsheet to still be accurate by the time the renewal comes back around, because it won’t be. Spreadsheets never are.

Skip that pricing exercise and the failure mode is predictable, I’ve watched versions of it play out more than once: the integration debt keeps compounding quietly, invisible to any single ARB decision because no single decision ever looks bad on its own, until it either surfaces as a breach notification with a vendor you can’t give a real reason for trusting, or as a consolidation project that burns three years of savings unwinding a decade of connections nobody priced going in. Price the carry cost at selection time. Not at incident time.

Photo by Anna Dudkova on Unsplash

Related

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture