Site navigation

“Tool Sprawl” Exacerbating Security Risks

Elizabeth Greenberg

,

tool sprawl
While security budgets may have gone up, more tools is only leading to more problems as attack surfaces expand and companies struggle to find skilled talent. 

Claggy software ecosystems full to the brim with underutilised SaaS tools have created a quagmire IT and security professionals are desperate to not sink in: the dreaded tool sprawl.

The ever-expanding selection of tools at company’s disposals, as well as their associated complexity, can often hamper IT teams, leading to less productivity, and expanding attack surfaces by introducing new platforms, only increasing cybersecurity pressures.

Red Canary’s 2024 Security Operations Trends report detailed the fallout of tool sprawl, which has impacted the attack surface for 73% of respondent in the past two years, by an average of 77%.

The urgency of technology adoption often creates new security gaps, with the pressure to compete often trumping the need for caution.

The report found that SOC teams have on average over 90 different security tools, but two thirds of respondents say that turning threat intelligence into action is difficult, and time consuming.

In fact, 85% have admitted that the detection deficit – the time between detecting and resolving an incident – has either increased or stayed the same in the past 12 months.

More concerning is the fact that 87% said that their organisation had a security incident in the past 12 months that they were unable to detect and neutralise before it had a negative impact on the business.

And this is despite security budgets growing – 63% of security leaders had an increase in their budgets in the past year, but only 37% felt that it was enough to stay secure.


Recommended reading


Most (67%) feel they are too busy keeping the proverbial lights on rather than improving their operations or strategy, with teams on average spending twice as long on operational tasks compared to cyber-readiness.

Part of this is to do with tool sprawl, but security teams also say they are drowning in data, with 60% saying there is too much noise and too many security alerts to deal with effectively.

The advent of AI appears to only be making matters worse: 64% of organisations admit to having knowledge and skills deficits around new technology, with all experiencing challenges when it comes to cloud security, and 62% saying AI has made it more difficult to stay secure.

Finding the right talent to help mitigate these issues is also a struggle, with 83% of organisations saying it is only getting more difficult to recruit and retain skilled security professionals, while 62% are experiencing higher levels of churn due to overwork and stress.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data