Migrations die in the overlap — parallel agents, parallel bills, parallel alerts nobody trusts. Panaptico maps feature parity, models the dual-run explicitly, gates cutover on signed readiness, and tracks the sunset until the old vendor is actually gone.
Outgoing
Symantec Endpoint Protection
Incoming
CrowdStrike Falcon
Swap progress
8,940 / 14,112 hosts · 63%
Parity
4 caps
Adapted
4 caps
Retired
2 caps
Gap
1 cap
The gap
01
Feature archaeology is its own project. Half the policies that protect the business were toggled on by someone who left in 2022. Replacing the tool means discovering what the tool actually did.
02
Two agents, two consoles, two SIEM pipelines. The SOC sees every event twice and nobody trusts either one. Every week of overlap is a week of double bills.
03
The day the new system goes live, the project declares victory. Six months later the old vendor is still billing, still ingesting, still sending an audit report nobody reads.
Parity matrix
Every capability the outgoing vendor performs gets classified — kept, adapted, retired, or gap — and each classification ships with a plan signed by the owner who inherits it.
Real-time malware scanning
SEP AV engine
Falcon prevention
parityfeature-equivalent · signatures + NGAV
Behavioral detection
SEP Insight / SONAR
Falcon Charlotte AI
adaptedtelemetry schema differs · queries rewritten
Application / device control
SEP ADC policies
Falcon USB / app groups
parity23 rules auto-translated · 2 flagged for review
Firewall policy
SEP client firewall
Falcon firewall mgmt
adaptedsyntax conversion · 47 rules → 41 rules
EDR / telemetry
SEP EDR add-on
Falcon Insight
adaptedSIEM schema migrated · Splunk TA swapped
Tamper protection
SEP tamper
Falcon sensor protection
paritydefault on · policy exported
Disk encryption bind
SEP + BitLocker hook
Falcon + BitLocker hook
parityrecovery keys unchanged · Intune-held
Vulnerability scanning
SEP Risk Insight
Falcon Spotlight
adaptedCVSS model differs · thresholds re-signed
DLP (endpoint)
SEP DLP module
— not in Falcon
retiredmoved to Netskope · separate project
Web / URL filtering
SEP web control
— not in Falcon
retiredZscaler owns it · policy re-homed
Mobile device protection
SEP Mobile
— out of scope
gapIntune MAM keeps mobile · documented exception
Coexistence
The dual-run window is the riskiest stretch of any migration. Panaptico models it explicitly — which hosts run which agent, which alerts route to which console, how the overlap collapses day by day.
Overlap window
65 days
Dual-running hosts
8,940
Alerts de-duped
27.4K / wk
Double-bill days
65 · approved
Cutover readiness
Overall
86%
6 dimensions · gates CISO sign
SEP events → Falcon lake
180d of history archived · 30d of live events dual-written
47 → 41 rules
6 rules merged · 2 flagged for review · diff signed by CISO
9 SIEM + 3 ticketing
Splunk indices, ServiceNow queues, PagerDuty services · all swapped
18 of 29 runbooks
Queries rewritten for Falcon schema · remaining 11 on SOC backlog
117 of 164 analysts
3-session curriculum · Falcon Console + Charlotte + triage
RB-MIG-0014
SEP re-enable path · 4-hour RTO · signed IT Lead + CISO
Sunset ledger
Agents come off. Servers reclaim. Licenses terminate at renewal. Every asset the outgoing vendor touched gets a closing entry — with an owner, a date, and an evidence bundle that proves it's actually gone.
7 asset classes · all dated · $1.24M recovered
SEP endpoint agents
14,112 hostsUninstall wave · Day 75 – 90
IT Ops
Day 75–90
On-prem SEPM servers
3 VMsDecommission · VMware reclaim
Platform
Day 92
Symantec license
$1.24M / yrTerminate at renewal · procurement notified
Procurement
2026-08-15
SIEM TAs (Splunk)
3 TAsUninstall · dashboards re-pointed
SecOps
Day 78
Historical telemetry
180 daysArchive to cold storage · audit-retained 7y
Data
Day 80
Firewall ACL carve-outs
23 rulesRemove SEP update URLs · CHG-7491
Network
Day 88
Endpoint install records
Ansible rolesArchive repo · tag frozen · read-only
Platform
Day 95
Panaptico runs the migration end-to-end — parity mapped, overlap modeled, cutover gated, sunset ledgered. Nothing rots in the middle.