The security team in 2026 has more tools than it has budget, more tools than it has people to run them, and more tools than it has processes to use them well. The result is a sprawl of under used licences and a stack of tools that the team is paying for but not getting value from. The field guide to the tools the security team should actually pay for, and the tools the security team should stop paying for.
The typical enterprise security team in 2026 has 40+ tools in its stack. SIEM, SOAR, EDR, CSPM, CIEM, DSPM, ASM, ITDR, the list goes on. The total cost is north of $1M per year for the mid size enterprise. The total value is significantly less than the total cost, because the team does not have the people to operationalise the tools, the processes to integrate the tools, or the maturity to use them well. The field guide covers the 6 tools that are worth paying for at almost any enterprise, and the 6 tools that almost no enterprise should be paying for.
The 6 tools worth paying for
Six tools, in roughly that order of how much value they deliver. SIEM, because every other detection tool feeds into it and the security team cannot run the SOC without one. EDR, because the endpoint tops the list of initial access vectors and the EDR catches the attack at the endpoint before the rest of the stack has to deal with it. Identity provider with MFA, because the credential leads the list of attack targets and the identity provider protects the credential at the protocol level. Backup with immutable storage, because the backup serves as the last line of defence against ransomware and the immutable storage makes the backup actually work as the last line. Email security gateway, because the email remains the top initial access vector in the social engineering data and the email security gateway catches the attack at the email before the user has to make a decision. Vulnerability scanner, because the vulnerability sits at the root of most breaches and the vulnerability scanner finds the vulnerability before the attacker does.
The 6 tools not worth paying for
Six tools, in roughly that order of how often they are bought and not used. SOAR, because the SOAR requires a level of process maturity that most enterprises do not have, and the SOAR without process maturity becomes an expensive way to automate the wrong things. CASB, because the CASB assumes the enterprise knows what its SaaS footprint is, and the typical enterprise does not know what its SaaS footprint is. UEBA, because the UEBA assumes a baseline of normal behaviour that the typical enterprise does not have, and the UEBA without a baseline becomes an expensive way to generate false positives. Threat intelligence platform, because the threat intelligence is freely available from CISA, MITRE, and the major vendors, and the platform becomes an expensive way to read what is already public. Deception platform, because the deception requires a level of operational maturity that most enterprises do not have, and the deception without operational maturity becomes an expensive way to deploy honeypots that nobody monitors. GRC tool, because the GRC tool becomes an expensive way to track the controls the auditor wants to see, and the controls the auditor wants to see are not the controls that prevent the breach.
How to make the call
Three moves if you are evaluating a new tool for the security stack. Calculate the total cost of ownership, not the licence cost, because the licence cost usually comes in at less than half of the TCO. The TCO includes the people to run the tool, the training for the team, the integration with the rest of the stack, the ongoing maintenance. If the TCO runs higher than the team can absorb, the tool costs too much regardless of the licence cost. Calculate the time to value, because the time to value separates a tool that pays for itself in 6 months from a tool that pays for itself in 3 years. A tool that takes 3 years to pay for itself will not pay for itself in the current budget cycle. Calculate the opportunity cost, because the team that runs the new tool cannot run the existing tools. The team has finite capacity. The new tool displaces the existing tool that the team would otherwise run. Choose carefully.

The bottom line
The security team in 2026 has more tools than it has budget and more tools than it has people. The 6 tools worth paying for are the SIEM, the EDR, the identity provider, the backup, the email security, the vulnerability scanner. The 6 tools not worth paying for are the SOAR, the CASB, the UEBA, the threat intel platform, the deception platform, the GRC tool. The call is TCO, time to value, opportunity cost.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



