SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Why adding more security tools could make businesses less secure

Why adding more security tools could make businesses less secure

Wed, 26th Aug 2026 (Today)
Matthew Lowe
MATTHEW LOWE Regional Director – Pacific Anomali

Australian and New Zealand companies are spending more than ever on cybersecurity, however a growing problem is emerging behind the investment: complexity.

For years, the conventional response to rising cyber threats has been straightforward. As attackers become more sophisticated, businesses add another security product. A new threat emerges and so another tool is deployed.

The logic is understandable. Cybersecurity is seen as a race in which businesses must continually strengthen their defences to keep pace with increasingly complex threats.

However there is a growing recognition that this approach has created a problem of its own. Many security teams are now responsible for dozens of overlapping products, each producing data, alerts and operational requirements.

Rather than giving executives and security professionals a clearer picture of their risk, the expanding technology stack can make that picture harder to see. The result is an uncomfortable paradox. Greater investment in cybersecurity can sometimes produce less clarity.

When more becomes too much

The issue is not simply the number of products a business owns, but what happens when those products have to work together. An enterprise running multiple security platforms must contend with integration costs, different systems and workflows, and the sheer volume of information being generated.

This creates operational friction at precisely the point where organisations need agility, and the burden also falls on people.

Security professionals already operate in an environment where threats can demand rapid responses, and adding more technologies does not necessarily make their jobs easier.

Instead, managing overlapping systems can consume time and resources that might otherwise be directed towards identifying threats and improving an organisation's overall security posture.

For executives and boards, the problem is even more fundamental. A long list of cybersecurity products can create the appearance of extensive protection without necessarily providing a simple answer to the question that matters most: is the business becoming more secure?

From security products to business outcomes

The emerging alternative is platform consolidation and the creation of more unified data architectures. Rather than continually adding individual products to address each new security challenge, businesses are beginning to consider whether fewer, more integrated technologies could provide better visibility and reduce operational complexity.

This represents a change in the way cybersecurity investment is evaluated. The number of tools deployed is relatively easy to count. However, measuring whether those tools are actually improving security outcomes is more difficult, but potentially far more valuable.

Executives can instead focus on measures such as whether incidents are being reduced, whether security teams can remediate problems more quickly and whether day-to-day operations are becoming more efficient.

This shift could have significant implications for technology strategies. A cybersecurity architecture designed around consolidation and unified data is not simply about reducing the number of products on an IT department's balance sheet. It is about making security information more usable and the overall operating environment less complicated.

A productivity issue

The case for simplification becomes particularly relevant for companies confronting broader economic uncertainty and productivity pressures.

Cybersecurity is often treated as a necessary cost of doing business. However the complexity created by security technology can itself become a cost, through integration requirements, operational friction and staffing pressures.

That means the question facing company boards may no longer be simply how much they should spend on cybersecurity. It may be whether their existing spending is producing the right outcomes.

The challenge will be to resist the assumption that stronger security necessarily requires more technology. In some environments, the opposite may be true: reducing duplication, consolidating platforms and creating a more unified architecture could make security operations more effective.

This does not mean that businesses can simply remove security tools and assume the problem is solved. Rather, it suggests that future cybersecurity strategies may need to place greater emphasis on how technologies work together and what they deliver for the business.

The defining cybersecurity question of the next decade may not be how many tools an organisation can deploy. It may be how effectively it can turn its technology investment into fewer incidents, faster responses and a more efficient operation.

After years of adding layers to defend against an expanding threat landscape, Australian businesses may be approaching a different phase of cybersecurity strategy.

The competitive advantage could increasingly lie not in having more security technology, but in making the technology already deployed work better.

In an era when businesses are being asked to do more with less, cybersecurity may be next in line for rationalisation. And the most valuable security upgrade may ultimately be simplification.