When More Cyber Security Is Too Much

Cyber security: why less is often more

Cyber Security: When Less Is More

Many companies believe that more security tools offer better protection, but the opposite is often the case. Overloaded systems, a lack of integration and endless interfaces slow down reactions and create dangerous gaps. The key lies in simplification, as part of a clear security strategy: clarity instead of chaos.

The question: Does your current security stack really deliver protection, or just complexity?

Auf den Punkt gebracht:

  • Reduction of redundant security tools and data sources
  • Integration of central systems for faster detection and response
  • Focus on transparency instead of functional diversity
  • Standardization of security operations and monitoring
  • Greater efficiency through clear processes and responsibilities

Die Lösung: SAVECALL helps connect existing and new security solutions into one clear, integrated architecture, instead of stacking ever more tools side by side.

Worum es in diesem Beitrag geht: Why more security tools rarely mean more protection, what attackers really exploit, and how companies become safer through focus instead of feature sprawl.










More security tools create more complexity, not more security

The view that more security tools mean better protection still persists, but security researcher Etay Maor argues that success in cyber security lies in simplicity.

“Growth creates complexity, which requires simplicity” – Mike Krzyzewski.

There is a widespread misconception that the more security tools a company uses, the better its security situation. It is therefore not surprising that companies use more than 70 security products on average. Furthermore, it is hardly surprising that with each additional offering, complexity increases and efficiency decreases. While this may not be a major problem for Fortune 100 companies with their virtually unlimited security budgets, it is a challenge for everyone else.

One of the fundamental problems in cyber security is that product diversity leads to complexity. The layered security approach that organizations have adopted over the years is designed to protect against the ever-changing threat landscape and the growing complexity of attacks.

Why integration matters more than more tools

However, each layer consisted of several unconnected offerings, which meant that security researchers became integration engineers. They had to try to link all the elements together. How exactly do you capture and correlate signals and indicators from different sensors, filter them, normalize the data, scan for false positives, assess the relevance of the data to your requirements, and more? How are multiple threat feeds captured, prioritized and checked for false positives? How can you ensure that everything works seamlessly together to ensure the best possible security posture?

You can’t do that!

The proof is in the so-called dwell time: most threat actors linger in organizations’ networks for weeks, if not months, before launching their attack.

At this critical stage of the attack, IT has many ways to detect, contain and even prevent an attack. While on the organization’s network, attackers gather passwords and secure their continued existence on the network using tools already on the system, such as WMI or PowerShell (or LOL, which stands for “Living Off the Land”), through to custom tools performing privilege escalations, lateral movement to identify crown jewels, preparing exfiltration tunnels and more, all while bypassing security controls.

This disproves another old cyber security myth that says: “the attackers have to be right just once, and the defenders have to be right all the time.” This myth is an oversimplification of what really happens in a breach. In fact, the exact opposite is true. The attackers have to be right every single step of the way to achieve their goal, while IT has multiple potential choke points where they could have detected, mitigated or prevented the attack. Why do Sec Ops keep overlooking these signals?

More technology does not mean more security

In many of these cases, all the signals were present but somehow overlooked. This raises some key questions: do new tools add fat or muscle to the security stack? Do they make the analyst’s job easier, or do they just create more complexity? Do they now need to monitor another screen to detect a potential signal? Do we start a new integration project with every tool that takes weeks or months? Will the whole thing be delayed even more if team members leave? Will we lose focus on security and end up with integration and testing instead?

Attackers have several advantages over defenders: they have the initiative, are far more agile, adapt and change faster. However, a close look at many breaches revealed that they still use the same tools and techniques, phishing, password cracking and vulnerability scanning. It’s not the “what” that they have changed, but the “how”.

The right approach: focus instead of feature sprawl

We need to rethink our defenses. Instead of constantly adding new functions, we should make better use of what already exists in cyber security, not simplified, but clearer, more comprehensive and more manageable. The goal: efficiency through focus, not through function.





How SAVECALL creates security through simplicity

We do not support you with a multitude of different security systems from different providers, but instead help you establish security systems that bring exactly this simplification: more transparency and less effort.

Conclusion: fewer tools, more security

It is not the number of security tools that determines how well a company is protected, but how well they are integrated and how quickly a team can turn their signals into a decision. Companies that consolidate existing systems instead of constantly adding new ones regain transparency, relieve their security team, and close exactly the gaps that attackers exploit unnoticed for weeks in overloaded environments.

Frank Frommknecht, Key Account Consultant bei SAVECALL

Written by

Frank Frommknecht

Key Account Consultant, SAVECALL

Has supported companies for over 20 years in selecting and optimizing their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and finding the right strategic solution.

Why

Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

Sources

  • Etay Maor, security researcher, cited for the principle of simplicity as a security strategy
  • Mike Krzyzewski, “Growth creates complexity that requires simplicity”
  • MITRE ATT&CK, Living off the Land Techniques, last accessed 2026

Frequently asked questions about security complexity

Why don’t more security tools automatically make a company safer?

Companies use more than 70 security products on average, often without clean integration. Each additional tool creates its own interfaces, its own alerts and its own false positives that security teams must correlate manually. Instead of more protection, this creates more noise, and real signals get lost in the volume. What matters is not the number of tools but how well they work together and how quickly a team can turn them into a decision.

What does dwell time mean in a cyberattack?

Dwell time describes the period an attacker spends undetected in the network before launching their actual attack, often weeks to months. During this phase, attackers gather passwords, escalate privileges and prepare exfiltration paths, usually using tools already present in the system, such as PowerShell. This long phase gives IT several opportunities to detect and contain the attack, provided the existing signals are not overlooked amid tool complexity.

Is it true that attackers only need to be right once, but defenders always?

No, this common myth oversimplifies reality. Attackers have to be right at every single step of their attack chain, from initial compromise through privilege escalation to exfiltration. IT, meanwhile, has multiple potential choke points where it could detect, mitigate or stop the attack. The problem is rarely a missing signal, it is more often that the signal gets overlooked in an overloaded, poorly integrated security stack.

How do you tell if a new security tool actually helps or just adds complexity?

A new tool should make the analyst’s job easier, not create additional screens and integration projects that take weeks or months. Check whether it replaces existing data sources rather than merely adding to them, whether it fits seamlessly into existing processes, and whether it remains usable when team members leave. If a tool distracts from the actual security focus toward pure integration and testing, it adds fat rather than muscle to the security stack.

What do attackers actually change when they succeed: the tools or the method?

Closer analysis of many security incidents shows that attackers mostly use the same tools and techniques: phishing, password cracking and vulnerability scanning. What has changed is not the what but the how, meaning the speed, agility and adaptability with which attackers operate. Defenders therefore benefit less from ever more tools against new threats than from faster, clearer processes around existing security measures.

How does SAVECALL help companies achieve security through simplicity?

SAVECALL does not broker an arbitrary multitude of security systems from different vendors, but helps connect existing and new security solutions into one clear, integrated architecture. The focus is on simplification: fewer redundant tools, centralized detection and response, and transparency about actual security status, instead of one more screen to monitor.

Articles that may also interest you

What drives you forward – & what drives

Book a free expert consultation