TL;DR: Operational risk, not just external threats, can undermine security outcomes when understaffing, budget gaps, tool sprawl, and poor scaling leave teams unable to operate controls effectively, according to Safetica. The lesson for practitioners is that governance must cover people, process, and platform fit, because defenses fail when operational capacity lags the threat model.
NHIMG editorial — based on content published by Safetica: operational risk, tool sprawl, and security team capacity
By the numbers:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility.
Questions worth separating out
Q: How should security teams reduce operational risk when controls exist but capacity is limited?
A: Start by matching each control to an owner, a cadence, and a realistic workload.
Q: Why do too many tools weaken security operations?
A: Too many tools create overlapping alerts, inconsistent evidence, and manual handoffs that slow decisions.
Q: What breaks when security controls are not designed for growth?
A: Controls break when scaling introduces more users, more locations, or more infrastructure without a matching operating model.
Practitioner guidance
- Map operational ownership for every control Document who approves, runs, and reviews each security control, then check whether that ownership still holds during leave, turnover, and incident surges.
- Consolidate overlapping security workflows Identify duplicate tooling across logging, access, response, and governance, then remove handoffs that force teams to reconcile the same evidence in multiple places.
- Stress-test controls against growth scenarios Validate identity and security processes against expansion events such as new business units, cloud migrations, and user growth, then record where manual rework appears.
What's in the full article
Safetica's full article covers the operational detail this post intentionally leaves for the source:
- The resource allocation findings that show how staffing, budget, and skills gaps translate into security delays.
- The specific examples of tool mismatch and vendor sprawl that create operational drag in day-to-day security work.
- The discussion of how organisations should choose scalable, integrated platforms as environments expand.
- The supporting survey references behind the article's claims about training cuts and response impact.
👉 Read Safetica's analysis of operational risk, tool sprawl, and security team capacity →
Tool sprawl and under-resourced teams: what security leaders miss?
Explore further
Operational risk is now an identity governance issue, not just a security operations issue. When teams cannot staff, tune, and sustain controls, IAM, PAM, and NHI programmes lose effectiveness even if policy language is strong. The real failure mode is not missing policy, but weak execution capacity across the lifecycle. Practitioners should treat operating model quality as part of governance, not as a separate administrative concern.
A question worth separating out:
Q: How do teams know whether operational risk is becoming a governance problem?
A: Look for recurring delays, skipped reviews, unowned workflows, and controls that only work when specific people are available. Those are signs that governance depends on informal labour rather than repeatable process. When execution quality varies by team capacity, risk has become structural.
👉 Read our full editorial: Operational risk is the hidden security gap behind tool sprawl