Why more does not always mean better
Estimated reading time: 8 minutes
A billion dollar cybersecurity acquisition tells us something about the industry.
It might also tell us something about your organisation.
In July 2026, Cyera acquired Oasis Security for approximately US$1 billion. On the surface, it looks like another significant transaction in a market that produces them regularly. Another cybersecurity company buying another cybersecurity company.
Look closer and something more interesting emerges. The cybersecurity industry, which has spent two decades selling organisations more products, is now spending billions consolidating them. Vendors are combining capabilities into fewer, broader platforms rather than continuing to build standalone solutions. That shift is worth paying attention to, because the industry appears to be acknowledging something that many organisations have experienced firsthand.
Too many tools. Too much overlap. And not always a clear picture of whether the investment is actually improving protection.
Source: Cyera acquisition of Oasis Security for approximately US$1 billion, reported July 2026. Full citations in the References section below.
How Security Environments Become Complex
No organisation sets out to build a complicated security environment. It happens gradually, and almost always for good reasons.
A new threat emerges and a product is purchased to address it. A compliance requirement introduces another platform. A vendor relationship brings a bundled solution. A business acquisition adds a second set of tools that overlap with the first. A team adopts something without visibility from the broader security function.
Each decision made sense at the time. Each tool solved a genuine problem. Over several years, the result can be an environment with dozens of security products, each serving a purpose, but collectively creating something that is difficult to manage, expensive to maintain and hard to see across clearly.
This pattern is remarkably common. Research consistently suggests that mid to large organisations operate between 40 and 70 security tools. Some operate considerably more. It is worth noting that the same pattern drove the Cyera acquisition. When even the vendors recognise that their customers have too many disconnected products, the signal is hard to ignore.
A Familiar Pattern
Year one: A genuine security need is identified and a product is selected to address it.
Year three: Several more products have been added, each solving a specific problem.
Year five: The organisation has accumulated a complex security environment where capabilities overlap, teams manage multiple dashboards, and no one person has complete visibility over the entire landscape.
What Complexity Actually Costs
The cost of a sprawling security environment is not always visible in a single line item. It tends to accumulate across several areas at once, and some of the most significant costs are the ones that never appear on a vendor invoice.
| Area | What Happens |
|---|---|
| Overlapping capabilities | Multiple tools performing similar functions, each with separate licensing, maintenance and management overhead |
| Alert volume | More platforms generating more alerts, many of which duplicate or contradict each other, contributing to fatigue |
| Reduced visibility | Information spread across separate dashboards, making it harder to see the full picture quickly |
| Vendor management | More contracts, more renewal cycles, more relationship management, more time spent coordinating |
| Incident response | During an incident, teams may need to check multiple systems to understand what is happening, slowing response time |
| Staffing pressure | Each platform requires expertise. Skilled people are stretched across too many tools rather than focused on what matters |
None of these problems mean the individual tools are bad. Most are competent products doing exactly what they were designed to do. The issue is what happens when they accumulate without a strategic layer sitting above them.
Security teams end up managing platforms rather than managing risk. That distinction matters. And for finance leaders reviewing cybersecurity budgets, the picture can be equally unclear. Total spending may be rising each year while the actual return on that spending, measured in risk reduction, becomes harder to quantify. A CFO looking at six overlapping subscriptions is asking the right question when they wonder whether all of them are necessary.
For years, many organisations measured cybersecurity maturity by the number of products they had deployed. The more tools, the more protected the business appeared to be. The consolidation trend suggests a different measure may be more useful: not how many products are in place, but how well they work together.
The strongest security programme is not always the one with the most tools.
It is the one where every investment works together.
Why This Becomes a Governance Question
There is a point where operational sprawl stops being a technical inconvenience and becomes a leadership concern. When the security environment is difficult for the people running it to see across clearly, it is also difficult for the people responsible for the business to oversee confidently. That is the point where this becomes a governance question.
Duplication affects financial oversight. If the board cannot easily determine whether cybersecurity spending is efficient or redundant, investment decisions become harder to evaluate. Operational performance becomes harder to measure. And risk reporting, which depends on accurate information flowing from tools to dashboards to leadership, becomes less reliable as the number of disconnected sources grows.
The same dynamic that led the cybersecurity industry towards consolidation applies inside individual organisations. At a certain point, adding another product to the environment creates more operational burden than security value. Recognising that threshold requires disciplined information security management and regular executive attention.
Several questions can help surface whether this threshold has been crossed:
- Are all existing security tools still providing distinct value?
- Do different platforms perform similar functions?
- Is the organisation paying for capabilities it already owns elsewhere?
- Can the security team effectively manage every platform it is responsible for?
- Does executive leadership have visibility over the entire security ecosystem?
- When was the last time the security stack was reviewed as a complete picture rather than product by product?
If these questions are difficult to answer, the security environment may have grown beyond the oversight structures currently in place. That gap between what has been built and what leadership can confidently see is where risk quietly accumulates.
The Value of an Independent Perspective
When an environment has been built incrementally over several years by different people solving different problems, it can be genuinely difficult for anyone inside the organisation to step back and see the full picture. Decisions that made perfect sense individually may not make sense collectively. But recognising that requires a perspective that sits above any single tool, team or vendor relationship.
This is where independent advisory adds value. Through vCISO and Security Leadership engagements, SeComPass works with organisations to examine whether their cybersecurity investments are aligned with what the business actually needs. The role is not to sell technology. It is to provide the clarity that allows leadership to make better decisions about the technology they already have.
Sometimes that means identifying genuine capability gaps. Other times it means recognising that the most effective next step is to simplify, consolidate, or properly configure what already exists. The most useful outcome of a review is not always a recommendation to invest more. It can be the confidence that current spending is well directed.
An Honest Assessment
The goal of a strategic security review is not to recommend purchasing more technology. It is to understand whether the technology already in place is working together, working effectively, and working in service of the business.
Executive Reflection
The Cyera acquisition is a useful prompt for a broader conversation. If the cybersecurity industry itself is spending billions to consolidate because it recognises that more individual products do not automatically produce better outcomes, organisations might consider applying the same logic internally.
- How many cybersecurity platforms does your organisation currently use?
- When was the last time your security environment was reviewed as a whole rather than product by product?
- Are there overlapping capabilities across platforms?
- Could your security team confidently operate every platform during an active incident?
- Is the total investment delivering proportional risk reduction, or has spending increased while visibility has not?
- Does your board have a clear picture of what the cybersecurity budget delivers?
These are not criticisms. They are the kind of questions that mature security programmes ask themselves regularly.
The consolidation wave reshaping the cybersecurity industry did not happen because the products were poor. It happened because the market recognised that a collection of excellent individual tools does not automatically produce excellent security. Organisations face the same reality. The question is not whether to invest in cybersecurity. The question is whether each investment contributes meaningfully to business resilience, or whether the environment has become something the team manages around rather than manages through.
Periodically stepping back to ask that question honestly is one of the most valuable things a leadership team can do. Not to reduce investment, but to ensure that every dollar, every platform and every hour of skilled attention is pointed at the risks that actually matter.
Key Takeaways
- The cybersecurity industry is consolidating. The July 2026 Cyera acquisition is one signal of a broader shift towards fewer, more integrated platforms
- More security tools do not automatically produce better protection. Without oversight, they can introduce duplication, operational burden and reduced visibility
- Sprawling security environments can slow incident response, increase alert fatigue and stretch skilled teams across too many platforms to be effective
- Cybersecurity spending is also a financial decision. Boards and CFOs should have confidence that investment is producing proportional risk reduction
- Periodic independent reviews help ensure that tools, spending and capabilities remain aligned with what the business actually needs
- Simplifying where appropriate can strengthen resilience. The goal is not fewer tools for the sake of it, but an environment where every investment contributes
Review Your Security Investments
Is Your Cybersecurity Environment Working For You or Against You?
The Executive Readiness Review helps leadership teams understand whether cybersecurity investments, governance and capabilities are aligned with business objectives. It includes:
- A review of current cybersecurity governance maturity
- Visibility over how security investments align with business risk
- Identification of capability gaps or areas of unnecessary duplication
- Strategic priorities for the year ahead
Start by understanding where your organisation stands today.
Start the Executive Readiness Review →References
- Cyera acquisition of Oasis Security for approximately US$1 billion. Reported July 2026
- Industry research on cybersecurity platform consolidation trends and security tool proliferation in enterprise environments. Accessed July 2026
- Australian Cyber Security Centre (ACSC). Guidance for business leaders on cybersecurity strategy and governance. Accessed July 2026. cyber.gov.au
This article is for general informational purposes only and does not constitute legal, technical, or professional cybersecurity advice. SeComPass recommends engaging a qualified adviser before making decisions based on this content. Guidance referenced above was current as at July 2026 and is updated periodically by relevant government and industry bodies.