Skip to main content

NEW REPORT · THE TAG ANALYSTS

More tools found more problems, so the budget grew.

So what does it cost to keep finding the same problems? TAG's Dr. Edward Amoroso modeled a large enterprise running three clouds, then modeled the same enterprise with enforcement moved into the architecture instead.

TAG report cover — Quantifying Enterprise ROI for Native Security for Multi-Cloud Control Plane Protection

INSIDE THE REPORT

  • The itemized before and after budget, line by line
  • The full ROI derivation and every rate behind it
  • The method for estimating engineering hours recovered
  • Where CSPM, CWPP, CIEM and CNAPP spend can be rationalized

Fill out the form to read the report now.

Every tool added made the queue longer.

A CSPM for posture, a CWPP for workloads, a CIEM for entitlements. Each one does its job, and each one hands your engineers a queue and the queue is the cost.

Spend rises faster than security improves because these tools are built to find problems after they exist. Enforcement changes what is possible. A control is either in place at the provider core or it is not, and whole classes of findings stop being work to triage.

Most platforms focus on identifying problems after they occur. Relatively few focus on preventing those problems from occurring in the first place.
Dr. Edward AmorosoTAG

TAG put a number on it.

$2.5M to $2.1M

Annual cloud security operating cost, modeled

159%

Return, as TAG calculated it

Not headcount

Tooling overlap, incident set-aside, contractors

Not from cutting security engineers, which TAG refuses to model. From overlapping assessment tools, an incident set-aside that shrinks once controls are enforced rather than detected, and contractors hired to keep pace with the queue.

Cutting cost without cutting people is a harder case to make than promising that automation will replace your team. It is also the one that holds up when finance asks where the savings actually come from.