TL;DR: Security teams still overspend because legacy SIEMs, tool sprawl, alert overload, manual incident response, and weak continuous validation create slower detection and higher operating cost, according to Anomali. The core issue is not awareness but execution friction: modern threats outpace control systems built for a slower operational model.
NHIMG editorial — based on content published by Anomali: 5 Inefficiencies in Cybersecurity (and Why They Still Exist)
By the numbers:
- Companies use 60 different tools.
Questions worth separating out
Q: How should security teams reduce identity workload when staffing is limited?
A: They should automate repetitive identity tasks first, then delegate bounded operational work to managed services where runbooks and escalation paths are explicit.
Q: Why do fragmented tools increase identity governance risk?
A: Because policy and enforcement stop moving together.
Q: What breaks when alert quality is too low for security operations?
A: Analysts stop trusting the queue, false positives crowd out real threats, and automation becomes brittle.
Practitioner guidance
- Reprice your SIEM by decision value Map ingestion spend to the specific investigations, detections, and identity signals the platform actually supports.
- Reduce tool sprawl around identity telemetry Consolidate the data sources that matter most for access and investigation workflows, especially endpoint, cloud, and identity events.
- Tune alerts for high-confidence identity anomalies Prioritise detections that reveal credential misuse, unusual privilege escalation, and unexpected service-account behaviour.
What's in the full article
Anomali's full article covers the operational detail this post intentionally leaves for the source:
- Specific examples of where SIEM cost and latency show up in day-to-day investigations
- The webinar discussion around how teams reduce tool sprawl without losing coverage
- The full breakdown of manual response bottlenecks and where automation can realistically help
- The practical cost-reduction discussion behind continuous validation and modern SOC workflows
👉 Read Anomali's analysis of five cybersecurity inefficiencies and their cost impact →
Cybersecurity inefficiencies in operations: what teams need to fix?
Explore further
Legacy telemetry economics create governance blind spots. When log storage and ingestion are priced and operated as a scarce resource, teams make rational choices that reduce visibility. That becomes an identity problem when service-account activity, token use, and privilege changes are the first signals of compromise. The practical conclusion is that visibility economics shape governance outcomes as much as policies do.
A question worth separating out:
Q: How do teams know continuous validation is actually working?
A: They should see fewer unknown gaps, faster confirmation of control drift, and more reliable response outcomes when access patterns change. If testing only produces reports but not operational correction, it is not validating control effectiveness. The signal of success is measurable improvement in what teams can prove and contain.
👉 Read our full editorial: Five cybersecurity inefficiencies that keep costs and risk rising