Strategy & CIO

Nearly Half of Security Teams Spend More Time Maintaining Tools Than Defending the Organisation

Splunk surveyed 2,058 security leaders across nine countries and found 46% spend more time on tool upkeep than on defence, while 78% describe their tooling as dispersed and disconnected. Half are thinking about leaving the profession.

September 3, 2026 · Strategy & CIO
An empty security control room with a wall of monitors and rows of unoccupied desks

Key Takeaways

  • Splunk's State of Security survey of 2,058 security leaders across nine countries found 46% spend more time maintaining tools than defending the organisation.
  • 78% say their security tools are dispersed and disconnected, and 69% say that fragmentation creates moderate to significant challenges.
  • 59% report too many alerts, 55% too many false positives, and 57% lose investigation time to data management gaps.
  • 52% say their team is overworked and 52% say job stress has prompted them to consider leaving cybersecurity altogether.

There is a number in Splunk's State of Security survey that should end a certain kind of budget conversation. Across 2,058 security leaders in nine countries, 46% said they spend more time maintaining tools than defending the organisation. Not configuring them once, not evaluating them, maintaining them: upgrades, connectors, parsers, agents, licence renewals and the endless reconciliation of what is supposed to be reporting against what actually is.

The accompanying figures explain how it got that way. 78% describe their security tools as dispersed and disconnected, and 69% say that fragmentation creates moderate to significant challenges. Each individual purchase was defensible. Together they produced an estate whose operating cost consumes the capacity the purchases were meant to create.

The Cost Nobody Put in the Business Case

Security tooling is bought on coverage and evaluated on features, and the recurring labour it creates is almost never modelled. A new detection platform arrives with an integration backlog, a data normalisation problem, a set of alerts that need tuning for six months, and a dependency on one person who understands its query language. Multiply that across an estate assembled over a decade by successive security leaders responding to successive incidents, and 46% stops looking like a failure of discipline and starts looking arithmetical.

The alert numbers follow from the same cause. 59% report too many alerts and 55% too many false positives, but volume is a symptom of fragmentation rather than an independent problem: uncorrelated tools each raise their own alert about the same event, and none of them has the context to suppress it. 57% say they lose investigation time to data management gaps, which is the same complaint from the other end, an analyst holding a question that requires three consoles to answer.

The Part That Is a Retention Problem

52% say their team is overworked, and 52% say stress has prompted them to think about leaving cybersecurity altogether. Not changing employers, leaving the field. In a discipline that has spent a decade describing itself as short of people, half the incumbent population considering the exit is a more urgent number than any hiring statistic.

It also identifies what the attrition is actually made of. People rarely burn out on interesting problems. They burn out on repetitive, low-judgement work that visibly fails to matter, which is a fair description of triaging false positives raised by a tool that lacks the context to know better. This publication's earlier reporting on IT retention found the same pattern outside security: the lever is removing toil, not raising compensation.

“Human oversight remains central to effective cybersecurity, and AI is used to enhance human capabilities to help where it truly matters: defending the organisation.”

Michael Fanning, Chief Information Security Officer, Splunk

The AI findings in the same survey are more measured than the market usually is. 59% say AI has moderately or significantly boosted SOC efficiency and 63% agree that domain-specific AI significantly or extremely enhances security operations, but 61% trust it only somewhat for mission-critical work and just 11% trust it completely. That distribution reads less like scepticism than like an accurate assessment: useful for the repetitive layer, not yet trusted with the judgement.

The same is true of engineering practice. 63% want to use detection as code frequently or always, against 35% who do so today, and 62% of those who have adopted it report that it unlocked test-driven development for detections. That is a large stated appetite for treating detection content as software, and it is exactly the kind of improvement a team spending 46% of its time on tool upkeep never gets to start.

Consolidation Is Not Automatically the Answer

The obvious inference is to buy fewer, larger platforms, and it is partly right. But consolidation projects have their own failure mode: they are long, they replace a working fragmented estate with a partially working unified one, and during the transition the team runs both. Several of these programmes have produced more maintenance labour for two years in exchange for less in year three.

The cheaper intervention is to measure the operating cost before restructuring the estate. Very few security teams can say how many hours a month a given tool consumes, which means nobody can identify the three products responsible for most of the 46%. That measurement is unglamorous and it is the only thing that turns this from a complaint into a decision.

Security has spent years arguing it needs more people and more tools. This data suggests the more accurate request is fewer tools, so that the people already employed can do the job they were hired for.

Share

More in Strategy & CIO

All Resources →