TL;DR: Security teams waste about 28% of per-user software spend and organisations running 50 or more security tools rate themselves 8% lower at detecting attacks and 7% lower at responding, according to Osterman Research and IBM Security with Ponemon. The real constraint is analyst capacity, not tool quality, and copilots do not fix that because they still depend on a human driver.
NHIMG editorial — based on content published by Dropzone AI: How Dropzone AI Helps You Get the Most Out of Your Existing Threat Detection Tools
By the numbers:
- Roughly 28% of per-user security software spend is underutilized or never used at all.
- Organizations using 50 or more security tools rated themselves about 8% lower at detecting attacks and 7% lower at responding than teams running fewer.
- About 21% of the applications organizations pay for are no longer used, and another 45% are underutilized.
Questions worth separating out
Q: How should security teams reduce shelfware without weakening detection coverage?
A: Start by mapping which alerts are actually investigated, which are routinely ignored, and which tools generate the most unconsumed telemetry.
Q: Why do teams with many security tools still struggle to respond quickly?
A: Because response speed depends on human capacity, integration quality, and investigation flow, not on how many licences are purchased.
Q: What do security teams get wrong about copilots in the SOC?
A: They often assume a copilot removes the bottleneck, when it usually only speeds up a human already doing the work.
Practitioner guidance
- Measure investigation throughput, not just tool coverage Track how many alerts are fully investigated per analyst hour across SIEM, EDR, cloud, and identity queues.
- Separate assistive AI from autonomous workflow execution Define which steps a copilot may suggest and which steps an agent may execute on its own, especially when investigations touch privileged identities or sensitive identity logs.
- Route identity telemetry into the same triage fabric as endpoint and cloud alerts Make privileged account activity, token use, and authentication anomalies available inside the primary investigation path so identity evidence is not trapped in a separate console.
What's in the full article
Dropzone AI's full post covers the operational detail this analysis intentionally leaves for the source:
- Step-by-step examples of how the SOC Analyst queries SIEM, EDR, cloud, identity, and email tools during an investigation
- The OSCAR methodology used to structure investigations and move beyond simple enrichment
- Implementation detail on how underused tools become data sources rather than separate consoles
- Case examples showing what changes when low-priority alerts are investigated instead of triaged away
👉 Read Dropzone AI's analysis of SOC shelfware and agentic investigation coverage →
Shelfware in the SOC: why tool spend is not translating to coverage?
Explore further
SOC shelfware is an operating-model failure, not a tooling failure. Organisations often interpret unused licences as a procurement problem, but the deeper issue is that detection tools need human hours to be useful. When the queue outruns the team, the marginal value of each additional console falls sharply. The practical conclusion is that coverage capacity belongs in the same governance conversation as tool selection.
A question worth separating out:
Q: How can analysts tell whether AI-driven SOC automation is actually working?
A: Look beyond alert volume and measure whether the platform produces accurate incidents, preserves tenant context, and shortens time to closure without creating rework. If analysts still need to reconstruct the story manually, the automation is reducing noise but not truly improving operational control.
👉 Read our full editorial: AI soc shelfware costs more than the tools themselves