Most security teams are over budgeted on tools and under budgeted on people. The tool landscape in 2026 is mature enough that the free and the cheap options cover roughly 80 percent of what an enterprise security team does. That other 20 percent is where the actual incidents live. Here is what is worth paying for in 2026, what is not, and how to think about the line between them.
Where the cheap options are now genuinely good
EDR is the obvious example. Microsoft Defender for Endpoint, when properly configured with attack surface reduction rules and cloud delivered protection, scores in the top tier against the commercial alternatives. The 2025 MITRE ATT&CK evaluations put it within a few percentage points of CrowdStrike and SentinelOne on detection and protection. For most organisations, the real question is no longer whether Defender is good enough. It is whether the team can tune the policies to get the most out of it. If they can, the 60 to 80 dollars per endpoint per year saved by not buying CrowdStrike pays for a junior analyst.
The same is true for SIEM. Elastic Security and Wazuh are credible open source alternatives for teams with the engineering muscle to run them. The Splunk tax is real, and for organisations spending more than 200K a year on ingest, the case for staying is increasingly hard to make. For smaller teams, Panther or a well tuned Elastic cluster will cover the use case. The expensive SIEMs earn their keep on the data model, the correlation speed, and the analyst experience. If you do not have senior analysts who will use those features, you are paying for a sports car to drive in a parking lot.
What is worth the spend
Identity threat detection and response is the category where the gap between free and paid is widest in 2026. Microsoft Defender for Identity, Push Security, and Obsidian Security are doing things that Defender for Endpoint alone cannot. Detecting OAuth abuse, session cookie theft, MFA fatigue, and consent grant attacks requires a different kind of telemetry and a different kind of model. If you are in 2026 and you are not running some form of ITDR, you are exposed. The cheap option is to turn on every Defender for Identity signal and write the correlation logic yourself. The paid option is Push or Obsidian. Both are reasonable.
Cloud detection and response is the other category worth paying for. Wiz, Orca, and Lacework are not cheap, but the gap between them and a self built cloud security posture management stack is large enough that most teams cannot close it. The cloud estate changes faster than any human review cycle, and the context graph that the commercial CDR tools build across AWS, Azure, GCP, GitHub, and Kubernetes is genuinely difficult to replicate. If you are running serious cloud infrastructure, the price is justified. If you are running 12 EC2 instances, the price is not.
What is not worth the spend
Standalone vulnerability management in 2026 has been eaten by the platforms. Tenable and Qualys still have a place for some compliance use cases, but for actual risk reduction, the EDR, the CDR, and the identity provider are already telling you what is exploitable. Buying a separate scanner on top is mostly paying for a report the CISO will not read. Consolidate. Use what you have. Save the money for the categories above.
User and entity behavior analytics as a standalone product is also fading. The serious UEBA work is now baked into the SIEMs and the EDRs. Splunk UBA is on the way out. Exabeam is pivoting to a detection platform. If a vendor is still selling a separate UEBA product in 2026, ask hard questions about what it does that Defender, SentinelOne, and your SIEM do not.

The bottom line
ITDR and CDR are the two categories worth the spend. Defender for Identity, Push, or Obsidian for identity. Wiz, Orca, or Lacework for cloud. The standalone VM and the standalone UEBA are no longer worth the spend. Save the money. Hire the analyst.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



