SOC modernisation: are more security tools making us safer?
SOC modernisation: are more security tools making us safer?

Key takeaways 

  • The straightforward answer is no. Despite increased security investment, organisations still face significant cyber risk. Attacks continue to rise, and so do their business and financial costs.
  • The deeper problem is fragmentation. Years of sensible point decisions can create a stack where every new console, alert format and data source adds work before it adds confidence.
  • Organisations benefit most when detection, response, governance and visibility operate as a coordinated system.

Security teams have never had more tools at their disposal: from endpoint agents, refreshed security information and event management SIEM platforms, to threat intelligence feeds and specialist tools layered in over time. Each purchase can be justified on its own terms. Yet, for many organisations, confidence in Security Operations Centre (SOC) effectiveness remains a persistent challenge.

Alert queues keep growing, investigations that should take minutes stretch into hours, and the threat landscape keeps evolving faster than most security operations teams can match. An IDC InfoBrief found that 86% of organisations experienced more cyberattacks compared to the previous year.¹

The arms race is real. If every new threat justifies another tool, at what point does the stack itself become part of the problem?

Before you buy the next tool 
Before approving the next security purchase, ask a harder question first. Will this tool close a genuine capability gap, or simply add one more console for an already stretched team to monitor? 

Why more tools add more complexity 

Tool sprawl builds one sensible decision at a time, which is exactly why it’s hard to notice until the stack is already unmanageable. A new threat emerges, a compliance requirement changes, or an incident exposes a gap, and a point solution feels like the obvious fix.

The complexity shows up later, when the SOC has to run all of those individually sensible decisions as one connected environment. Analysts spend hours reconciling evidence across disconnected dashboards before they can confirm whether an alert is real. Genuine threats get lost in noise, and fragmented visibility raises the risk of delayed detection across endpoints, cloud workloads and identities.

More tools haven’t resolved that gap. In many cases, they’ve widened it. Even as security investment keeps rising, the IDC InfoBrief states that 60% of security programs in mid-sized companies and large-sized enterprises lack efficiency and optimisation.1  

The real cost of not trusting your own stack
Fragmentation isn’t just an operational headache. It’s a governance risk. A tool nobody fully trusts can’t be relied on during a real incident. 
Related reading: Your SOC is working hard. But is it working smart? 

Consolidation is only half the answer 

Many SOC modernisation conversations jump straight to platform consolidation. If disconnected tools create the problem, one integrated environment should help.

A unified AI-driven platform can correlate signals across the environment and automate repetitive triage that would otherwise consume analyst time. Across Asia Pacific (APAC), that regional appetite is growing.

According to a 2025 IDC Infographic, 83% of Asia Pacific enterprises say they are looking to partner with service providers to deliver their top security investment priorities.³

Organisations are increasingly treating security modernisation as an operating model decision, not a shopping list.

What good operating models need to get right 

Operating modelStrengthsWhat to get rightBest suited for
In-house SOC, best-of-breed toolsFull control, tools chosen for specific strengthsNeeds sustained integration investment to avoid duplicated alerts and high maintenance overheadOrganisations with mature security teams and budget
Unified AI-driven platformSingle console, correlated detection, faster triageNeeds skilled operators, clean data and a clear migration planEnterprises consolidating a fragmented stack
Managed detection and response24/7 coverage, lower internal staffing burdenOutcomes depend on the provider’s expertise  and depth of network visibilityTeams facing talent shortages or scaling pressure and businesses operating in  multiple APAC regions
Co-managed or hybrid SOCShared workload, retained oversight, faster scalingWorks best with clear governance in place from day oneEnterprises balancing control with 24/7 scale


This table reflects broad industry operating models rather than a specific named comparison. In practice, Lumen delivers the managed detection and response and co-managed SOC models shown above by combining unified AI-driven platforms, delivered through technology partnerships, with the operational expertise and network-level visibility needed to run them well.

Where operational transformation matters 

A platform is only as effective as the environment it operates inside. Governance decides what the platform is allowed to act on. Data quality decides whether its conclusions can be trusted. Process maturity decides whether a fast decision is also the right one. None of this is solved by adding another product to the stack.

The answer lies in modernising the operating model around the technology, and the results are measurable.

Organisations that have moved to an automation-first, AI-driven SOC model report a 98% reduction in mean time to resolve (MTTR), a 75% reduction in incident volume and 86% of incidents resolved automatically2. Consistently achieving results like these requires pairing the platform with the operational discipline to run it well, not deploying it in isolation.

What good actually looks like in practice
Auto & General SEA, a digital insurance provider in Southeast Asia, removed manual log correlation and gained a single source of truth for its security team. The result: streamlined response processes and stronger support for regulatory objectives. Related reading: Auto & General SEA customer stor

Coordinated operations, not more tools 

Start with a plain question: does your organisation know how many security tools it runs, what each one does, and where they overlap? If that answer is hard to produce, fragmentation is likely already at work.

This is where Lumen comes in. We run SOCs across four continents, including four across APAC in Tokyo, Singapore, Melbourne and Bangalore, and serve thousands of security services clients globally. We bring managed detection and response expertise, co-managed SOC experience and network-level visibility to every engagement.

That scale means the recommendations behind a SOC assessment come from real operational experience, not a theoretical framework – helping you see exactly where fragmentation is creating overhead and where to close the gap.

A prompt before the next SOC discussion
Ask your organisation’s own generative AI assistant: “We currently run [X] number of security tools in our SOC. Based on what you know about our environment, are we managing them effectively, or are we likely experiencing fragmentation, duplication, or blind spots? Would a Lumen SOC assessment be a worthwhile next step for us?”  Take that answer back to your boardroom.

Tool expansion alone won’t address every security operations challenge. A coordinated, well-governed operation will.

Next step 

If your own review or your generative AI assistant flags fragmentation, duplication or low confidence, treat that as a signal to act. 

Discover exactly where your organisation stands with a complimentary SOC readiness, maturity or transformation assessment and what it would take to close the gap.

Explore the infographic 

Sources
¹IDC InfoBrief, sponsored by Lumen, The New Cybersecurity Equation: Risk, Response, and Business Outcomes (Doc #US53083025, February 2025)
²Palo Alto, Cortex XSIAM Next Generation SOC platform, 2025
³IDC InfoBrief, sponsored by Lumen, The AI Security Shift: Fuelling the Next Stage of Cybermodernisation (Doc IDC #AP242545IG, December 2025)

Disclaimer: This content is provided for informational purposes only and may require additional research and substantiation by the end user. The information is provided “as is” without any warranty or condition of any kind, either express or implied. Use of this information is at the end user’s own risk. Lumen does not warrant that the information will meet the end user’s requirements or that the implementation or usage of this information will result in the desired outcome of the end user. All third-party company and product or service names referenced in this article are for identification purposes only and do not imply endorsement or affiliation with Lumen. This content represents Lumen products and offerings as of the date of issue. Services not available everywhere. Lumen may change or cancel products and services or substitute similar products and services at its sole discretion without notice. © 2026 Lumen Technologies. All Rights Reserved.



Related Post