Most orgs don’t have the brain trust required to implement and maintain a proper PKI and managed identity platform, both of which are critical to secure communications in C&C infrastructure. I’m a CISSP and have been involved with PKI implementation and management for 10 years. It’s the Achilles heel of many orgs.
Critical to make them secure, but not essential to make them work.
There ought to be a law.
Organizations with a competent “brain trust” are rare. And where they exist, you see multiple specialized platforms for configuration control. And multiple other platforms for monitoring, alerting and ticketing.
Or course, scale matters.
And that’s why we’re in business...well, except for me. I’m recently retired.
It all comes down to competent IT Management, which is more rare than a competent engineering staff. And quickly becoming extinct.