Claggy software ecosystems full to the brim with underutilised SaaS tools have created a quagmire IT and security professionals are desperate to not sink in: the dreaded tool sprawl.
The ever-expanding selection of tools at company’s disposals, as well as their associated complexity, can often hamper IT teams, leading to less productivity, and expanding attack surfaces by introducing new platforms, only increasing cybersecurity pressures.
Red Canary’s 2024 Security Operations Trends report detailed the fallout of tool sprawl, which has impacted the attack surface for 73% of respondent in the past two years, by an average of 77%.
The urgency of technology adoption often creates new security gaps, with the pressure to compete often trumping the need for caution.
The report found that SOC teams have on average over 90 different security tools, but two thirds of respondents say that turning threat intelligence into action is difficult, and time consuming.
In fact, 85% have admitted that the detection deficit – the time between detecting and resolving an incident – has either increased or stayed the same in the past 12 months.
More concerning is the fact that 87% said that their organisation had a security incident in the past 12 months that they were unable to detect and neutralise before it had a negative impact on the business.
And this is despite security budgets growing – 63% of security leaders had an increase in their budgets in the past year, but only 37% felt that it was enough to stay secure.
Recommended reading
- Are Non-IT Leaders Overconfident in Cybersecurity Capabilities?
- IT Leaders Split on Generative AI’s Role in Cybersecurity
- Cyber Leaders Reveal Compliance and Boardroom Struggles
Most (67%) feel they are too busy keeping the proverbial lights on rather than improving their operations or strategy, with teams on average spending twice as long on operational tasks compared to cyber-readiness.
Part of this is to do with tool sprawl, but security teams also say they are drowning in data, with 60% saying there is too much noise and too many security alerts to deal with effectively.
The advent of AI appears to only be making matters worse: 64% of organisations admit to having knowledge and skills deficits around new technology, with all experiencing challenges when it comes to cloud security, and 62% saying AI has made it more difficult to stay secure.
Finding the right talent to help mitigate these issues is also a struggle, with 83% of organisations saying it is only getting more difficult to recruit and retain skilled security professionals, while 62% are experiencing higher levels of churn due to overwork and stress.





