Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Security spending is climbing, but why is remediation still lagging?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: 85% of organisations increased security spending this year, yet 56% of security professionals still say budgets are insufficient, exposing a detection-to-resolution mismatch rather than a simple funding problem, according to Pixee. The real constraint is remediation capacity, and that makes automation, consolidation, and exploitability-driven triage more urgent than adding another scanner.

NHIMG editorial — based on content published by Pixee: The $19M Paradox: Why Security Spending and Security Debt Both Keep Rising

By the numbers:

Questions worth separating out

Q: What breaks when security programmes keep adding detection tools but not remediation capacity?

A: Backlogs grow faster than teams can clear them, which means risk persists even when visibility improves.

Q: Why do security teams struggle to turn vulnerability findings into real risk reduction?

A: Because the bottleneck is often human remediation throughput, not discovery.

Q: How do organisations know if AD security tooling is actually working?

A: It is working when the findings lead to measurable reductions in exposed privileges, unresolved trusts, and unowned domains.

Practitioner guidance

  • Measure closure rates alongside discovery rates Track how many findings are fixed per week, per team, and per asset class.
  • Prioritise exploitability before remediation assignment Use reachability, authentication boundaries, and exposure context to separate theoretical findings from issues that can actually be abused.
  • Consolidate duplicated security intake workflows Deduplicate alerts across scanners and posture tools before they enter engineering queues.

What's in the full article

Pixee's full article covers the operational detail this post intentionally leaves for the source:

  • Budget allocation breakdowns across personnel, cloud security, managed services, and professional services
  • The breakdown of noise, false positives, and duplicated findings across layered security tool stacks
  • Examples of remediation automation and reachability analysis used to reduce backlog pressure
  • The full discussion of how teams are balancing consolidation against new investment decisions

👉 Read Pixee's analysis of the security budget and remediation gap →

Security spending is climbing, but why is remediation still lagging?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Detection without resolution is now a governance anti-pattern. Security programmes have spent years optimising for discovery, but discovery alone does not reduce exposure. When 61% of organisations test only a fraction of their application estate, the issue is not lack of insight, it is lack of closure discipline. The practical conclusion is that governance must measure fixed risk, not just identified risk.

A question worth separating out:

Q: Should security teams automate fixes before adding more tools?

A: Yes, when the same issues recur across many assets and manual repair is the main bottleneck. Automation should start with repetitive, well-defined actions such as patching, rotation, and revocation. If the programme cannot fix what it already knows, more tools will usually deepen the backlog rather than reduce it.

👉 Read our full editorial: Security budgets are rising while remediation capacity falls behind



   
ReplyQuote
Share: