Volume Without Value – Part Three: Walking Into Renewal With Something To Say
Sorting out the data architecture changes the renewal conversation before it starts. Here is what is different, and how to tell whether the work delivered.
The first two parts of this series made an argument in two steps. Security data volume grows for reasons unconnected to risk, and no discount fixes that. The way out is to work out which data genuinely needs to sit in the most expensive tier and to route everything else deliberately.
This final part deals with what happens afterwards, which is where the commercial return actually shows up.
What Changes At The Table
Most SIEM renewals are conducted from a position of some weakness. The security team knows its volume is rising, knows it cannot easily predict next year’s figure, and knows that walking away would mean a migration nobody has budgeted for. Those three facts are visible to the other side of the table, and they shape the outcome.
When the data architecture work has been done first, all three change.
You know your baseline, because you have measured it rather than inferred it from an invoice. You know your growth drivers, because you have identified which sources are expanding and why. And critically, you know what proportion of your data genuinely needs to be in that platform at all, which means you can size the commitment honestly instead of buying headroom to cover an uncertainty you have not resolved.
The conversation stops being about the rate and starts being about the scope. That is a considerably better conversation to be having.
Portability Is The Real Bargaining Position
The most valuable outcome of this work is rarely the one anyone puts in the business case.
If security data lands first in storage you own, normalised to an open schema, and is then forwarded to the analytics platform, the platform becomes something closer to a replaceable layer. The cost of moving to a different tool falls, because the data no longer has to be extracted, converted and re-onboarded from a proprietary structure.
That is a genuine change in position, and it does not require you to be planning a move. The fact that a move is feasible is what alters the dynamic. Vendors price and behave differently when switching costs are low, and every security leader who has been through a renewal knows it.
I would be careful about overstating this. Migration is never free, detection content still has to be rebuilt or translated, and analysts still need retraining on a new interface. What changes is the order of magnitude, and the order of magnitude is what determines whether an alternative is credible enough to be discussed.
Measuring Whether It Worked
Cost per unit of data is the obvious measure and it is the wrong one. It rewards the behaviour you are trying to move away from, which is treating all security data as an undifferentiated commodity to be minimised.
A more useful set of measures would include the following.
- Total cost of the security data estate, counting platform licensing, storage, egress and the engineering time to maintain it. Moving cost between line items is not a saving and this measure makes that visible.
- Detection coverage against a recognised framework, measured before and after. If coverage has fallen, the saving was not a saving.
- Number of sources declined or deferred on cost grounds over the period. If this figure has not moved towards zero, the underlying problem has not been solved.
- Time to onboard a new source, from request to production detection. This is a good proxy for whether the architecture is actually working.
- Analyst time spent on data wrangling during investigations, which is the benefit nobody forecasts and everybody notices.
The second of those is the one to insist on. It is entirely possible to cut the bill substantially and quietly reduce coverage at the same time, and the saving will be reported long before the gap is discovered.
The Twelve Month Picture
A year after this work is done properly, a few things tend to be true.
New data sources get connected on the basis of whether they are useful, because the marginal cost is known and modest. Detection engineers stop treating volume as a constraint on what they can write. The renewal conversation is scheduled rather than dreaded, and the number attached to it is one the security team produced rather than received.
The board level change is subtler. Security spending becomes explicable. A security leader who can account for what the organisation spends on its data estate, why, and what it buys, is in a materially different position when asking for anything else.
A Word Of Caution
This work is not a one off project that concludes. Data sources change, business applications get added, cloud estates expand, and an architecture that was correct in year one drifts if nobody is watching it.
The organisations that hold the gains are the ones that treat data routing as an ongoing operational discipline with an owner, a review cycle and a place on someone’s objectives. The ones that treat it as a cost reduction exercise find themselves having the same conversation three years later, having lost the institutional memory of why the decisions were made the first time.
The bill is the symptom that gets attention. The architecture underneath it is the thing worth fixing.
HOOP Cyber works with security teams on security operations architecture, security data engineering and the cost of running both. If the renewal is coming and the conversation has not started, it is not too early. Get in touch with us via .