Controlling SaaS Costs Under Regulatory Pressure
Runaway software spending is a challenge for any organization, but for financial services firms, it carries added regulatory weight. When IT budgets are difficult to justify or audit, they attract scrutiny from compliance teams and regulators alike. App rationalization helps institutions take back control.
The rationalization process starts with a detailed inventory of all software running across the organization — surfacing redundant tools that serve the same function, unused or underused licenses, and shadow IT deployed outside IT’s visibility. Industry benchmarks underscore the waste at stake: The average Software as a Service (SaaS) spending per employee now exceeds $9,600 annually, and 25%–30% of SaaS licenses go unused or significantly underused, according to Zylo’s 2026 SaaS Management Index.
By retiring redundant tools and consolidating to a smaller, well-governed set of applications, financial services IT teams can reduce spending while building a software portfolio that’s easier to audit and explain to regulators.
READ MORE: How is artificial intelligence helping banks automate regulatory controls?
Strengthening Cybersecurity in the Industry’s Most Targeted Sector
Financial services entered 2026 as the industry most attacked on the internet — and application sprawl is making that problem worse. Flexera notes that unvetted applications expand an organization’s attack surface, providing additional potential entry points for cybercriminals and increasing the risk of a data breach. In financial services, the consequences are severe: The average cost of a data breach in the sector reached $5.56 million in 2025 — among the highest in any industry. According to Black Kite’s 2026 Financial Services Cybersecurity Report, direct ransomware attacks on financial institutions climbed to 202 incidents in 2025 — a 30% year-over-year increase — with early 2026 data already showing a 76% surge over the prior year's Q1.
App rationalization directly addresses these risks. By conducting a thorough inventory of the full application portfolio, IT teams can identify unvetted or redundant tools and retire them, reducing the number of systems that require patching, monitoring and access governance. Fewer applications mean a smaller, more defensible attack surface — a critical advantage for institutions handling sensitive financial data.
