Security spend won't buy more certainty

Datadog Inc

By Yadi Narayan, Field CTO for APJ at Datadog
Wednesday, 30 September, 2026


Security spend won't buy more certainty

What’s the point of having a top-of-the-line safe at home to protect your valuables — fireproof, drill-resistant and bolted to the floor — if it is rendered pointless by a sticky note with the combination stuck to the inside of a nearby drawer? Strength and spend doesn’t equal effectiveness if the weakness is somewhere that you never thought to defend.

The security budgets of Australian organisations have grown steadily for years, with Gartner projecting Australian organisations will spend more than $7.5 billion on information security (security software, services and hardware) in 2026, which would be a 9.5% increase from 2025. New tools are adopted, the latest budget gets stood up, and security operations grow alongside the attack surface.

Despite these compounding costs, breaches keep landing, with the Australian Signals Directorate’s (ASD) Australian Cyber Security Centre responding to more than 1200 cybersecurity incidents in 2024–25, 11% more than the year prior, and notifying entities of potentially malicious cyber activity over 1700 times. The need for vigilance and action to mitigate against these threats is clear, especially as board scrutiny intensifies and reputational stakes of getting it wrong continue to rise.

AI-powered attacks are only adding to the pressure, moving faster and adapting to make static defences look increasingly outmatched.

Much like anyone with a sticky note in a drawer, every security and technology leader has been left asking if all of that investment is worth it. They might be buying the newest, shiniest systems promising to protect every potential exposure of their business, but that doesn’t mean at least one of them won’t be beaten, and more worryingly it doesn’t mean they’ll know when it has been beaten. Leaders need to re-evaluate what security tools will actually give them confidence.

As we all know, seeing is believing. The ability to see a breach unfold in real time and trace how an attacker is moving through the environment is unmatched. No one needs more alerts and noise; they need clear and understandable readings. A high volume of alerts can naturally fatigue analysts and lead them to triage by instinct, sometimes overlooking alerts that are genuinely worth acting on, while confidence erodes if many others turn out not to be valuable.

It’s tempting to equate tool count with maturity, but a larger stack isn’t stronger in practice. Each additional point solution often creates its own silo, filled to the brim with its own logs, alerting logic and view of the environment. When there is a breach, security teams end up stitching together fragments from a dozen consoles, trying to reconstruct a single narrative of what happened and where it spread.

This reconstruction work takes time, which an organisation doesn’t have once an intrusion is underway. The gap between ‘an alert fired’ and ‘the team understands the full blast radius’ is where damage compounds and the incident that could have been contained in minutes stretches into hours or days. The Office of the Australian Information Commissioner (OAIC) reported that barely two-thirds of Australian organisations identify a breach within 30 days of it occurring, and a similar share take that long just to notify the regulator once they know.

Detection alone isn’t the hard part. Whether security teams can follow an attacker’s path across infrastructure, applications, identities and cloud services as a single connected story is where the challenges truly arise, and where many well-resourced security programs fall short.

Logs sit in one system, network telemetry in another, application performance data in a third, and identity activity somewhere else again. When an incident occurs, analysts are doing detective work across disconnected filing cabinets, often under extreme time pressure and with incomplete information.

AI is not simply adding another layer of complexity. Threat actors can use it to generate, vary and scale attacks at a pace that traditional, human-led security operations will struggle to match. This means the security operations centre (SOC) itself must evolve. Analysts cannot spend critical time manually correlating signals across disconnected tools while attacks adapt at machine speed. Security teams need connected telemetry, automated correlation and response, and AI-assisted investigation that reduces noise and provides analysts with the context to make faster and better-informed decisions.

An organisation that can’t see an attack as it happens, end-to-end, is always going to be reactive. A forensic report might reveal the true scope of a breach weeks later, but a complete and singular view of its operations can reveal what is happening in real time, containing an incident before it becomes a headline or regulatory notification or board-level crisis.

Cost shouldn’t be the main concern for Australian leadership teams. Asking “how much are we spending?” won’t stop you from investing incorrectly. The aim should be visibility, with teams asking, “What can we actually see, how quickly can we see it, and are we even looking for the right thing?” When it matters most, a consolidated, well-integrated set of capabilities providing continuous and correlated visibility will consistently outperform a large, fragmented stack of tools.

This should extend to how boards evaluate risk. Spend-per-tool metrics mean little to resilience, when time is the real value: time to detect, time to understand, time to contain. These numbers correlate with reputational and financial outcomes when an incident occurs, and they expose whether existing investment is delivering real protection or the appearance of it.

For Australian organisations, the path forward is insisting that whatever tools are in place deliver genuine, connected, real-time visibility and actually let teams know before someone else finds where the combination is written down.

Image credit: iStock.com/BlackJack3D

Related Articles

No, AI hasn’t replaced Australian tech jobs yet

Every software developer rightfully fears for their job, but there’s growing evidence that...

Threat modelling is taking on new importance as AI threats increase

Threat modelling has traditionally existed in the realm of security professionals, but now it...

Australian employees are losing half their week to admin

Research by Workday has shown that roughly 30% of ANZ employees now lose more than seven hours a...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd