Back to Resources

The Blind Spots Live Between the Platforms

Every major platform in a large Australian enterprise gives a strong view of its own territory. The costliest problems tend to start in the territory none of them owns.

Nobody sets out to build a fragmented technology estate. It accumulates, one sensible decision at a time. Productivity and identity standardise on Microsoft. The network is built on Cisco. Workloads land in Azure, then some in AWS when a business unit or an acquisition brings them along. Operational technology arrives from whichever vendors the plant, the depot or the grid was originally built around. Security tooling is layered over the top as new risks emerge, each product chosen on its merits.

Every one of those decisions can be defended on its own terms. The trouble starts on the day an organisation needs to see across all of them at once: when an application slows for an entire region, when a security event begins in one domain and ends in another, or when the board asks a plain question about exposure and the honest answer has to be stitched together from five different consoles.

That is the visibility gap. It is the predictable product of how enterprise technology is bought and built, and it is costing Australian organisations more than most of them realise.

Complexity Is Accumulated, Not Chosen

Multi-platform environments are now the norm. Around 90 per cent of Australian enterprises use more than one cloud provider to run their business (Forrester, cited in TechPartner News, 2025), and that figure says nothing about the on-premises infrastructure, SaaS estates and OT systems that sit alongside those clouds. For a large organisation in mining, utilities, transport or health, a single business process might touch a Cisco campus network, a Microsoft identity, an Azure-hosted application, a SaaS platform and an industrial control system before it completes.

None of this is a failure of planning. Organisations choose the strongest option for each job, and they should. Acquisitions bring their own stacks. Regulatory requirements push some workloads one way and others another. OT environments run on lifecycles measured in decades rather than refresh cycles. The result is an estate where every component is well chosen and the whole is harder to see than any of its parts.

The cost of that complexity rarely shows up as a line item. It shows up as time: the time between something going wrong and anyone being able to say, with evidence, what went wrong and where.

Every Platform Is Built to See Itself Best

The major technology vendors understand the fragmentation problem well, and they are investing heavily in it. Cisco launched its Data Fabric in September 2025, built on the Splunk platform, to unify machine data from across the enterprise and make it usable for analytics and AI (Cisco, 2025). Microsoft’s Sentinel data lake is designed to consolidate security data, including data from third-party sources, into a single copy for analysis (Microsoft, 2025). Both are serious, capable platforms, and both accept data from outside their own ecosystems.

But each is engineered around a centre of gravity, and that centre is its own platform. Native telemetry runs deepest where the vendor owns the stack. Integrations are richest with the vendor’s own products. Roadmaps prioritise the configurations its customers run most often. That is not a criticism. It is exactly how a platform business should be built, and it is a large part of why these platforms are as good as they are.

An organisation running both, which describes most large Australian enterprises, ends up with two well-engineered centres of gravity, each offering a view that is coherent on its own terms and partial in practice. Add an OT environment monitored by specialist tooling such as Claroty or Nozomi, endpoint protection from another provider and a firewall estate from a third, and the number of authoritative views multiplies. Each is accurate. None of them, on its own, is the whole picture.

A Business Problem Wearing a Technical Disguise

The consequences of fragmented visibility are usually described in technical language: correlation, telemetry, mean time to resolution. Where they actually land is on the business.

User experience degrades in ways nobody can attribute. A customer-facing application slows across a state, and each platform team can show, accurately, that its own domain is healthy. The investigation becomes a sequence of handoffs rather than a diagnosis, and the business absorbs the cost for as long as it runs.

Security incidents exploit the seams. A compromised identity, unusual traffic on the network and an anomaly on an operational asset may each look minor inside the tool that sees it. Seen together, they describe an attack in progress. The time it takes to connect those dots has a measurable price: Australian organisations that took more than 200 days to identify and contain a breach faced average costs of AUD 5.17 million, compared with AUD 3.26 million for those that responded faster (IBM, cited in IT Brief Australia, 2026). Visibility across domains is not the only factor in that difference, but it is hard to contain quickly what cannot be seen whole.

Board questions become harder to answer with confidence. When a director asks how exposed the organisation is, the answer is assembled from several partial reports, each produced with different assumptions and different blind spots. Leaders can give an answer. What they often cannot give is one they would stake their name on.

Procurement compounds the problem. When visibility is partial, the instinctive fix is another tool, which adds another view and, frequently, another island.

Australia’s national cyber authority treats cross-environment correlation as a baseline expectation rather than an advanced one. ASD’s ACSC guidance on event logging and threat detection names centralised log collection and correlation as one of four key factors in effective detection, across cloud services, enterprise networks, mobility and OT (ASD’s ACSC, 2024). Seeing across environments is not a refinement for mature organisations. It is the foundation the rest depends on.

Who Owns the View Between the Platforms

Once the gap is recognised, the harder question turns out to be organisational rather than technical. Each platform in the estate has an owner, a team and a vendor relationship. The seams between them belong to everyone, which in practice means they belong to no one.

Organisations tend to close that gap in one of three ways, and each carries a trade-off. The first is to nominate one vendor’s platform as the centre and route everything else into it. That can work well, provided the organisation accepts that the resulting view will reflect that platform’s priorities, and that the domains hardest to integrate, often OT, are the ones most likely to sit at its edge. The second is to build the cross-platform capability in-house. That offers full control, but it requires a team with equal depth across networks, cloud, security and industrial systems, keeping pace with every vendor’s roadmap at once, which is a significant and sustained investment. The third is to work with a partner whose role is to operate across the platforms rather than to own one of them.

What makes the third model distinct is not where the data ends up. In most environments it will still land in a data fabric, often one the organisation already owns, or whichever best suits its estate. The difference is who designs, integrates and operates it, and in whose interest. A partner with no data platform of its own to sell, no preferred cloud and no ecosystem to protect can choose the fabric on its fit for the organisation, then take responsibility for the domains that fabric sees least well, OT above all. The vendors’ own platforms remain the best instruments within their domains. The work is connecting what they see, not replacing them. That is the model Orro has chosen, working with Cisco, Microsoft, HPE, Fortinet, SentinelOne, Claroty and Nozomi, and across both IT and OT, rather than steering customers towards any one platform.

What Changes When the Whole Picture Is Visible

The difference shows up first in the questions an organisation can answer. When an application slows, triage starts from evidence across every domain the transaction touched, and the conversation with the relevant vendor begins with data rather than suspicion. When a security event crosses a boundary, it is visible as a pattern rather than as three unrelated alerts in three consoles. When the board asks about exposure, the answer comes from one coherent view rather than a reconciliation exercise.

It also changes how technology decisions get made. With a whole-of-environment view, investment can be directed at the actual weak point rather than the most visible one, and each platform can be judged on what it contributes to the whole. That is a better outcome for the vendors as well: their platforms deliver more value when they sit inside a picture that makes sense from end to end.

Perspective Before Tooling

Earlier Orro pieces have looked at why network uptime is the wrong thing to measure and how a governed data layer underpins effective observability. This argument sits one level above both. Before tooling, and before data governance, comes a question of perspective: whose view of the environment the organisation is relying on, and whether that view was built to see everything or built to see itself best.

For most large Australian enterprises, the answer will not be found in any single console. It will be found in deciding, deliberately, who is responsible for the space between them. Organisations working through that decision are welcome to talk it through with Orro.

Continuing the conversation: Orro will be at Cisco Live Melbourne, 9 to 12 November 2026, where data fabric and end-user experience are on the agenda.

Common Questions

What is cross-platform visibility?

Cross-platform visibility is the ability to see and correlate what is happening across every part of a technology environment at once, including network, cloud, security tooling and operational technology, rather than viewing each domain through its own vendor’s console.

Why doesn’t a single vendor platform provide complete visibility?

Major platforms such as Cisco Data Fabric and Microsoft Sentinel data lake are capable and accept third-party data, but each is engineered around its own ecosystem, where its native telemetry and integrations run deepest. Organisations running several platforms end up with multiple accurate but partial views.

How does fragmented visibility affect breach costs?

Slower detection and containment cost more. IBM’s 2026 research found Australian organisations taking more than 200 days to identify and contain a breach faced average costs of AUD 5.17 million, compared with AUD 3.26 million for faster responders.

Who should own visibility across a multi-vendor environment?

Organisations typically choose between centring on one vendor’s platform, building cross-platform capability in-house, or working with a partner that operates across platforms without owning one. Each carries trade-offs in bias, cost and coverage, particularly for OT environments that sit outside mainstream IT platforms.