The tooling is rarely the gap. Most organisations of any size already own capable products at every layer, the endpoint agent is fine, the identity provider supports conditional access, the firewall is modern. What is missing is that no single person or system can answer the question an auditor actually asks: what can this account reach, and how would you know if it did.
The reason is structural rather than negligent. Each tool was bought to solve the problem in front of it, configured by whoever owned that layer, and reviewed on its own console. The correlation between them was always somebody’s intention and never anybody’s job. So the endpoint console shows a clean fleet, the identity console shows sensible policies, and the combination permits a path neither of them was asked about.
The network layer is where this accumulates most visibly. Firewall rule sets grow monotonically because adding a rule is a five-minute change with a clear requester and removing one is a risk with no owner. After a few years the rule set encodes the organisational history rather than the current business, and nobody will touch it because the blast radius of being wrong is a production outage with your name on it.
The joiner-mover-leaver process is the quiet one. Joining works, because somebody complains immediately if it does not. Moving accumulates, people keep the access from their last role because removing it is nobody’s ticket. Leaving mostly works for the identity provider and mostly does not for the eleven systems that were integrated separately. The result is a population of accounts with more access than any current person needs, which is the precondition for most of the incidents worth worrying about.
None of this is visible from inside until something forces a look: a customer security questionnaire with real teeth, a cyber-insurance renewal, a public-sector bid, or an incident. The first three are inconvenient. The fourth sets the timetable for you.