NEW REPORT · THE TAG ANALYSTS
More tools found more problems, so the budget grew.
So what does it cost to keep finding the same problems? TAG's Dr. Edward Amoroso modeled a large enterprise running three clouds, then modeled the same enterprise with enforcement moved into the architecture instead.

INSIDE THE REPORT
- The itemized before and after budget, line by line
- The full ROI derivation and every rate behind it
- The method for estimating engineering hours recovered
- Where CSPM, CWPP, CIEM and CNAPP spend can be rationalized
Fill out the form to read the report now.
Every tool added made the queue longer.
A CSPM for posture, a CWPP for workloads, a CIEM for entitlements. Each one does its job, and each one hands your engineers a queue and the queue is the cost.
Spend rises faster than security improves because these tools are built to find problems after they exist. Enforcement changes what is possible. A control is either in place at the provider core or it is not, and whole classes of findings stop being work to triage.
Most platforms focus on identifying problems after they occur. Relatively few focus on preventing those problems from occurring in the first place.
TAG put a number on it.
$2.5M to $2.1M
Annual cloud security operating cost, modeled
159%
Return, as TAG calculated it
Not headcount
Tooling overlap, incident set-aside, contractors
Not from cutting security engineers, which TAG refuses to model. From overlapping assessment tools, an incident set-aside that shrinks once controls are enforced rather than detected, and contractors hired to keep pace with the queue.
Cutting cost without cutting people is a harder case to make than promising that automation will replace your team. It is also the one that holds up when finance asks where the savings actually come from.