What could make it better? Businesses that operate under compliance regimes (especially PCI, FedRAMP and HIPAA) are more or less required to buy and operate FIM to detect critical system configuration changes, but they often don't get much utility our of it.
Based on our founders' experience operating such systems, the main problem seems to be the conjunction of:
1) Static configuration: FIM solutions typically require the operator to define what is "critical" to monitor, so there's a base-OS configuration and beyond that they need to select particular installed applications, or manually add directories and file paths to the list.
2) Vast numbers of applications: While certain applications are dominant, a typical enterprise uses many open source and commercial tools, and most develop custom applications, thus exploding the complexity of defining what is critical.
3) Dynamic deployments: The installed applications are constantly changing, adding new dependencies, configuration files, and behaviors, without notice or a machine-readable way to track those changes.
The end result: waves of false positives, and a maintenance nightmare. Alert fatigue. Or arguably worse, missed dependencies that are actually critical, but unmonitored.
One of the premises of our company: shouldn't these systems configure themselves based on the actual system behavior? Remove the maintenance load from the operator; focus on what the system actually depends on.