By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: AnomaliPublished October 24, 2025

TL;DR: Security teams still overspend because legacy SIEMs, tool sprawl, alert overload, manual incident response, and weak continuous validation create slower detection and higher operating cost, according to Anomali. The core issue is not awareness but execution friction: modern threats outpace control systems built for a slower operational model.


At a glance

What this is: This is an independent analysis of five recurring cybersecurity operating inefficiencies and the cost and response penalties they create.

Why it matters: It matters because IAM, NHI, and security operations programmes all depend on timely visibility, clean telemetry, and repeatable controls that break down when workflows stay manual and fragmented.

By the numbers:

👉 Read Anomali's analysis of five cybersecurity inefficiencies and their cost impact


Context

Cybersecurity inefficiency is usually a control problem disguised as a tooling problem. When log volumes, alert noise, and fragmented workflows grow faster than operational maturity, teams pay more and learn less from the same environment. That pressure also affects identity governance, because access decisions and investigation quality depend on telemetry that is complete, timely, and usable.

The article's primary point is that costs rise when security programmes keep legacy operating models in place after the environment has changed. For IAM and NHI practitioners, the identity angle is straightforward: access, privilege, and workload behaviour cannot be governed well if the surrounding detection and response stack cannot see or validate them consistently.


Key questions

Q: How should security teams reduce identity workload when staffing is limited?

A: They should automate repetitive identity tasks first, then delegate bounded operational work to managed services where runbooks and escalation paths are explicit. The goal is to reduce manual handling without losing auditability or ownership. Teams should focus on high-volume work such as resets, fulfilment, and monitoring before trying to automate complex exceptions.

Q: Why do fragmented tools increase identity governance risk?

A: Because policy and enforcement stop moving together. When access changes are split across several tools, revocation slows, exceptions multiply, and teams lose confidence that the recorded state matches the real one. That makes it harder to prove who has access, when it changed, and whether the change actually took effect everywhere.

Q: What breaks when alert quality is too low for security operations?

A: Analysts stop trusting the queue, false positives crowd out real threats, and automation becomes brittle. In identity programmes, that means suspicious sign-ins, privilege changes, and anomalous account activity may not get the attention they deserve. Low-fidelity alerting turns detection into noise management rather than risk management.

Q: How do teams know continuous validation is actually working?

A: They should see fewer unknown gaps, faster confirmation of control drift, and more reliable response outcomes when access patterns change. If testing only produces reports but not operational correction, it is not validating control effectiveness. The signal of success is measurable improvement in what teams can prove and contain.


Technical breakdown

Why legacy SIEM architectures become expensive under modern telemetry

Legacy SIEMs were designed around log collection and correlation at a scale that no longer matches cloud-native estates. Their cost model often ties storage and ingestion to volume, which encourages selective logging and weakens detection coverage. They also depend on complex queries and delayed pipelines, so analysts spend more time waiting for answers than using them. In practice, the issue is not just vendor performance. It is the mismatch between static log-centric architecture and dynamic environments where workloads, identities, and events change continuously.

Practical implication: validate whether your SIEM can support real-time investigation of cloud and identity telemetry before you add more data sources.

How alert overload degrades identity and security operations

Alert overload occurs when detection coverage is broader than the team can triage. False positives consume analyst time, but the deeper problem is signal collapse: once everything looks urgent, nothing is consistently investigated. In identity-heavy environments, that means risky sign-ins, privilege changes, and anomalous service-account behaviour can blend into the noise. Automation also suffers because playbooks built on low-confidence alerts create more churn than value. Mature operations require fewer, better signals, not simply more detections.

Practical implication: tune detections around high-fidelity identity and NHI behaviours so investigation paths remain usable under load.

Why continuous validation matters more than periodic testing

Periodic assessments create a snapshot of control health, but modern environments need continuous validation because controls drift as systems, permissions, and integrations change. Pen tests and ad hoc simulations are useful, but they do not prove that monitoring, containment, and response still work after routine configuration changes. For identity programmes, this matters because a credential, role, or token can be over-permissioned long after the original review. Continuous validation closes the gap between policy intent and operational reality.

Practical implication: test identity, access, and response controls continuously enough to expose drift before an attacker does.


NHI Mgmt Group analysis

Legacy telemetry economics create governance blind spots. When log storage and ingestion are priced and operated as a scarce resource, teams make rational choices that reduce visibility. That becomes an identity problem when service-account activity, token use, and privilege changes are the first signals of compromise. The practical conclusion is that visibility economics shape governance outcomes as much as policies do.

Signal fatigue is now an operational control failure, not just an analyst workload issue. Too many low-value alerts weaken the reliability of the entire detection stack because teams stop trusting the queue. In identity and NHI programmes, that means the controls most likely to reveal misuse are also the ones most likely to be ignored if they are noisy. Practitioners should treat detection precision as a governance requirement.

Continuous validation is the difference between declared and actual security posture. Annual testing can show that a control existed at one point, but it does not prove that it still functions under current access patterns or data flows. This is especially relevant for workload identity and privileged access, where drift happens quietly. The field should treat validation as a living assurance process, not a compliance event.

Fragmentation increases the cost of every identity decision. When data lives across too many tools, access reviews, investigation steps, and response actions all take longer and become less reliable. Security observability sprawl: the more disconnected the telemetry, the more expensive it becomes to prove who did what, when, and with what privilege. The practitioner lesson is to align identity signals with a smaller number of operational workflows.

Automation only reduces cost when the underlying control signals are stable. Manual incident response remains expensive, but poorly tuned automation can make the situation worse by amplifying bad detections or inconsistent context. For identity teams, the issue is not whether to automate, but whether the events feeding automation are trustworthy enough to drive containment. Organisations should build automation around validated identity and privilege signals.

What this signals

Security inefficiency is increasingly an identity governance issue. When organisations cannot see who or what is accessing systems, they spend more to investigate less. That makes telemetry quality and identity context part of the cost base, not just an engineering concern. Teams should expect spending pressure to shift from tools alone to the operational quality of access evidence.

Security observability sprawl will keep inflating the cost of identity assurance until programmes reduce the number of places where access evidence must be stitched together. The practical change is to align cloud, endpoint, and identity telemetry around a smaller set of decisions, then validate those decisions continuously.

As AI-driven workflows expand, response speed will matter more because noisy operations leave less room for human investigation. That makes stable identity signals, deterministic response paths, and continuous validation the controls that preserve both cost discipline and security confidence.


For practitioners

  • Reprice your SIEM by decision value Map ingestion spend to the specific investigations, detections, and identity signals the platform actually supports. If the system cannot answer questions about privilege change, token use, or workload authentication in time to matter, the cost model is hiding operational risk.
  • Reduce tool sprawl around identity telemetry Consolidate the data sources that matter most for access and investigation workflows, especially endpoint, cloud, and identity events. The goal is not fewer tools for its own sake, but fewer handoffs before an analyst can confirm whether access was legitimate.
  • Tune alerts for high-confidence identity anomalies Prioritise detections that reveal credential misuse, unusual privilege escalation, and unexpected service-account behaviour. A smaller set of trusted alerts is more operationally useful than a broad queue that analysts learn to ignore.
  • Replace annual assurance with continuous validation Test identity controls, response paths, and monitoring assumptions on an ongoing basis so drift is visible before it becomes an incident. Validation should cover the controls that actually gate access and containment, not only the policies written to satisfy audit.

Key takeaways

  • The article argues that cybersecurity costs rise when legacy workflows, fragmented telemetry, and noisy detections slow response more than the threat landscape itself.
  • Identity governance is affected because access, privilege, and workload evidence lose value when the surrounding security stack cannot surface or validate them quickly.
  • The operational answer is continuous validation, cleaner telemetry, and tighter signal quality, not just more tools or larger control inventories.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Continuous monitoring and detection are central to the article's SIEM and alert-quality concerns.
NIST SP 800-53 Rev 5AU-6Audit review and analysis directly support the article's emphasis on usable logs and investigation speed.
CIS Controls v8CIS-8 , Audit Log ManagementThe article's SIEM inefficiencies map directly to log collection, retention, and analysis quality.
MITRE ATT&CKTA0007 , Discovery; TA0006 , Credential Access; TA0040 , ImpactThe control gaps discussed affect how defenders spot attacker discovery and credential abuse.
NIST AI RMFMEASUREThe article's validation theme aligns with measuring whether controls work in practice.

Tie SIEM efficiency to detection coverage and verify that monitoring still answers identity and access questions quickly.


Key terms

  • Security Observability Sprawl: Security observability sprawl is the condition where useful evidence is spread across too many disconnected tools, formats, and workflows. It raises operational cost because teams must stitch together context before they can decide whether an event is real, relevant, or escalating.
  • Signal Fatigue: Signal fatigue is the point at which analysts receive so many low-confidence alerts that they stop treating the queue as reliable. It weakens detection quality, slows triage, and makes automation less effective because response logic is built on noisy inputs instead of trusted indicators.
  • Continuous validation: Continuous validation is the practice of re-checking user, device, or session risk after login instead of trusting access indefinitely. It recognizes that identity assurance can drift during a session, especially when endpoint state or user context changes after authentication.
  • Identity Telemetry: Identity telemetry is the collection of signals generated by authentication, session, and access events across human and non-human identities. It becomes useful for governance when teams can baseline normal behavior and detect drift in source, privilege, or access frequency.

What's in the full article

Anomali's full article covers the operational detail this post intentionally leaves for the source:

  • Specific examples of where SIEM cost and latency show up in day-to-day investigations
  • The webinar discussion around how teams reduce tool sprawl without losing coverage
  • The full breakdown of manual response bottlenecks and where automation can realistically help
  • The practical cost-reduction discussion behind continuous validation and modern SOC workflows

👉 The full Anomali post covers the webinar discussion, the operational bottlenecks, and the cost-reduction themes in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the wider security operations and governance work their programmes depend on.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org