Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Data ROI and telemetry value: what security teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Telemetry ROI should be measured by value created, not only by GB/day reduction, because cutting logs, context, and enrichment can slow investigations and weaken compliance outcomes, according to DataBahn. The practical shift is to treat data pipelines as value-bearing security controls, not just cost centres.

NHIMG editorial — based on content published by DataBahn: Why are Legacy SIEMs a problem? ROI is the metric that shows up in dashboards, budget reviews, and architecture discussions

By the numbers:

Questions worth separating out

Q: How should security teams decide which telemetry belongs in the SIEM?

A: Start with investigative value, not source count.

Q: Why do identity and authentication logs matter so much in data ROI decisions?

A: They are often the records that explain whether an action was routine, risky, or abusive.

Q: What breaks when enrichment happens only after SIEM ingestion?

A: Three things usually break together: cost control, detection speed, and retention discipline.

Practitioner guidance

  • Inventory telemetry by security value Map the logs, events, and metadata fields that support investigations, access review, secret detection, and compliance evidence.
  • Preserve identity and authentication context Keep the fields that explain who or what authenticated, from where, with what privilege, and through which workload or service account.
  • Move enrichment upstream Attach context before routing decisions so the pipeline can distinguish between high-value events and low-value noise.

What's in the full article

DataBahn's full article covers the operational detail this post intentionally leaves for the source:

  • How the pipeline distinguishes high-value telemetry from low-value noise before routing decisions are made
  • Examples of enrichment stages that attach context in motion rather than after ingestion
  • The specific operational scenarios where value-based routing improves investigations and compliance readiness
  • How the platform frames cost reduction as a byproduct of controlled data handling rather than the goal

👉 Read DataBahn's analysis of data ROI in modern security pipelines →

Data ROI and telemetry value: what security teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Data ROI should be treated as a control effectiveness problem, not a finance metric. Cost per gigabyte is easy to measure, but it says very little about whether the retained data improves investigation quality, compliance confidence, or resilience. When teams optimise only for spend, they often remove the context that makes security analytics work. The right question is whether the pipeline preserves the evidence needed for action.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

A question worth separating out:

Q: How do teams know whether data ROI is improving security outcomes?

A: Look for faster investigations, cleaner detections, lower reconciliation effort, and stronger audit readiness, not just lower spend. If the programme saves money while analysts lose context, ROI has improved on paper but declined operationally. The right signal is whether retained data consistently helps teams make better decisions.

👉 Read our full editorial: Data ROI is a security governance problem, not just a cost issue



   
ReplyQuote
Share: