Volume Without Value – Part One: Volume Is Not Risk
Security data volume is growing for reasons that have almost nothing to do with how much risk your organisation is carrying. Understanding why is the first step to doing something about what you spend.
Ask a security leader what changed about their budget conversation over the last three years and the answer is rarely about a new category of threat. It is about volume. The line item that used to come up once a year at renewal now comes up every quarter, and the question has shifted from what the platform does to why it costs what it costs.
There is a structural reason for this, and it has very little to do with the risk the organisation is actually carrying.
How The Pricing Model Works Against You
Security information and event management platforms have historically been priced against the volume of data they take in. The specific commercial model varies by vendor, and several have introduced alternatives based on compute, workload or committed tiers rather than raw ingest. The dominant logic for a long period, though, has been simple: the more data you send, the more you pay.
That model was reasonable when the data sources were relatively stable. A finite set of firewalls, servers and directory services produced a predictable amount of log data, and the volume moved roughly in line with the size of the estate.
That is no longer the environment anyone is operating in.
What Is Actually Driving Your Volume Growth
When security data volume rises sharply, the cause is usually somewhere in the following list. None of these items represents an increase in the amount of risk the organisation faces.
- Cloud migration. Control plane activity, flow logs and storage access logs generate a category of telemetry that simply did not exist in the equivalent on premises estate.
- Verbose defaults. Modern platforms log more per event than their predecessors did, with richer context attached to each record. The event count may not have moved much. The bytes per event have.
- Software as a service growth. Every new business application added over the last five years came with its own audit log, and security was rightly asked to monitor it.
- Endpoint telemetry. Detection and response tooling produces a continuous stream of process, network and file activity rather than the periodic alerts that antivirus used to generate.
- Identity as a monitored surface. Authentication, authorisation and privilege activity has become one of the highest volume sources in most estates, and one of the most valuable.
- Retention obligations. Regulatory and contractual requirements often specify how long data must be kept, and organisations frequently satisfy that requirement by leaving everything in the platform it landed in.
Read that list again with a finance director in mind. Every item on it is the byproduct of the organisation working normally and modernising sensibly. Not one of them is a signal that the threat picture has worsened.
The cost curve and the risk curve have separated, and the commercial model still assumes they are the same line.
The Decision Nobody Wants To Be Making
The consequence is a category of decision that no security leader wants on their conscience. When a data source has to be dropped to stay inside a licence tier, the decision is being taken on price rather than on risk. The conversation may be framed in terms of value, but the constraint driving it is commercial.
The most common version of this is quiet, and that is what makes it dangerous. A source is not switched off in a meeting with minutes. It is simply never switched on. A new SaaS platform goes live, its audit log is assessed, the volume is judged unaffordable, and the source stays outside the monitored estate. Nothing is recorded as a risk acceptance because nothing was formally rejected.
There is no alert for a detection you never wrote. The gap does not surface in any dashboard, any coverage report or any board pack. It surfaces during an incident, when someone asks why there is no record of what happened between two points in a timeline.
Why A Better Discount Does Not Fix It
The instinctive response is to negotiate harder. Bring in procurement, run a competitive process, secure a better rate per unit.
That is worth doing, and it is not the answer. A discount changes the rate. It does not change the shape of the curve. If volume is growing at a rate the security function does not control, and it is, then a better unit price buys time rather than a solution. The same conversation returns at the next renewal with a larger number attached, and the negotiating position is weaker because the easy concessions have already been made.
The same applies to filtering at the edge as a standalone tactic. Dropping fields to reduce volume without a clear view of what those fields support is how organisations discover, eighteen months later, that a correlation rule has been silently returning nothing.
A Better Question
The question worth asking is not what the organisation should be paying per unit of data. It is which data needs to sit in the most expensive tier at all.
Most security estates contain data in at least four distinct categories: data that actively fires detections, data that analysts reach for during an investigation but which never triggers anything, data retained purely to satisfy a compliance obligation, and data that nobody has queried since it was first connected. Those four categories have very different value, very different access requirements and very different economics.
Almost no organisation prices them differently, because almost no organisation has separated them. Everything lands in the same place, is charged at the same rate and is retained on the same terms.
That is an architectural problem rather than a commercial one, which is why it cannot be negotiated away. It can, though, be designed away.
In part two we look at how to work out which of your data belongs in which category, and what to do with the three categories that do not need to be sitting where they currently are.
HOOP Cyber works with security teams to modernise security operations architecture and bring the cost of the security data estate back under control. If the volume conversation has become the whole conversation, we should talk.