Key takeaways
- The straightforward answer is no. Despite increased security investment, organisations still face significant cyber risk. Attacks continue to rise, and so do their business and financial costs.
- The deeper problem is fragmentation. Years of sensible point decisions can create a stack where every new console, alert format and data source adds work before it adds confidence.
- Organisations benefit most when detection, response, governance and visibility operate as a coordinated system.
Security teams have never had more tools at their disposal: from endpoint agents, refreshed security information and event management SIEM platforms, to threat intelligence feeds and specialist tools layered in over time. Each purchase can be justified on its own terms. Yet, for many organisations, confidence in Security Operations Centre (SOC) effectiveness remains a persistent challenge.
Alert queues keep growing, investigations that should take minutes stretch into hours, and the threat landscape keeps evolving faster than most security operations teams can match. An IDC InfoBrief found that 86% of organisations experienced more cyberattacks compared to the previous year.¹
The arms race is real. If every new threat justifies another tool, at what point does the stack itself become part of the problem?
| Before you buy the next tool Before approving the next security purchase, ask a harder question first. Will this tool close a genuine capability gap, or simply add one more console for an already stretched team to monitor? |
Why more tools add more complexity
Tool sprawl builds one sensible decision at a time, which is exactly why it’s hard to notice until the stack is already unmanageable. A new threat emerges, a compliance requirement changes, or an incident exposes a gap, and a point solution feels like the obvious fix.
The complexity shows up later, when the SOC has to run all of those individually sensible decisions as one connected environment. Analysts spend hours reconciling evidence across disconnected dashboards before they can confirm whether an alert is real. Genuine threats get lost in noise, and fragmented visibility raises the risk of delayed detection across endpoints, cloud workloads and identities.
More tools haven’t resolved that gap. In many cases, they’ve widened it. Even as security investment keeps rising, the IDC InfoBrief states that 60% of security programs in mid-sized companies and large-sized enterprises lack efficiency and optimisation.1
| The real cost of not trusting your own stack Fragmentation isn’t just an operational headache. It’s a governance risk. A tool nobody fully trusts can’t be relied on during a real incident. Related reading: Your SOC is working hard. But is it working smart? |
Consolidation is only half the answer
Many SOC modernisation conversations jump straight to platform consolidation. If disconnected tools create the problem, one integrated environment should help.
A unified AI-driven platform can correlate signals across the environment and automate repetitive triage that would otherwise consume analyst time. Across Asia Pacific (APAC), that regional appetite is growing.
According to a 2025 IDC Infographic, 83% of Asia Pacific enterprises say they are looking to partner with service providers to deliver their top security investment priorities.³
Organisations are increasingly treating security modernisation as an operating model decision, not a shopping list.
What good operating models need to get right
| Operating model | Strengths | What to get right | Best suited for |
| In-house SOC, best-of-breed tools | Full control, tools chosen for specific strengths | Needs sustained integration investment to avoid duplicated alerts and high maintenance overhead | Organisations with mature security teams and budget |
| Unified AI-driven platform | Single console, correlated detection, faster triage | Needs skilled operators, clean data and a clear migration plan | Enterprises consolidating a fragmented stack |
| Managed detection and response | 24/7 coverage, lower internal staffing burden | Outcomes depend on the provider’s expertise and depth of network visibility | Teams facing talent shortages or scaling pressure and businesses operating in multiple APAC regions |
| Co-managed or hybrid SOC | Shared workload, retained oversight, faster scaling | Works best with clear governance in place from day one | Enterprises balancing control with 24/7 scale |
This table reflects broad industry operating models rather than a specific named comparison. In practice, Lumen delivers the managed detection and response and co-managed SOC models shown above by combining unified AI-driven platforms, delivered through technology partnerships, with the operational expertise and network-level visibility needed to run them well.
Where operational transformation matters
A platform is only as effective as the environment it operates inside. Governance decides what the platform is allowed to act on. Data quality decides whether its conclusions can be trusted. Process maturity decides whether a fast decision is also the right one. None of this is solved by adding another product to the stack.
The answer lies in modernising the operating model around the technology, and the results are measurable.
Organisations that have moved to an automation-first, AI-driven SOC model report a 98% reduction in mean time to resolve (MTTR), a 75% reduction in incident volume and 86% of incidents resolved automatically2. Consistently achieving results like these requires pairing the platform with the operational discipline to run it well, not deploying it in isolation.
| What good actually looks like in practice Auto & General SEA, a digital insurance provider in Southeast Asia, removed manual log correlation and gained a single source of truth for its security team. The result: streamlined response processes and stronger support for regulatory objectives. Related reading: Auto & General SEA customer stor |
Coordinated operations, not more tools
Start with a plain question: does your organisation know how many security tools it runs, what each one does, and where they overlap? If that answer is hard to produce, fragmentation is likely already at work.
This is where Lumen comes in. We run SOCs across four continents, including four across APAC in Tokyo, Singapore, Melbourne and Bangalore, and serve thousands of security services clients globally. We bring managed detection and response expertise, co-managed SOC experience and network-level visibility to every engagement.
That scale means the recommendations behind a SOC assessment come from real operational experience, not a theoretical framework – helping you see exactly where fragmentation is creating overhead and where to close the gap.
| A prompt before the next SOC discussion Ask your organisation’s own generative AI assistant: “We currently run [X] number of security tools in our SOC. Based on what you know about our environment, are we managing them effectively, or are we likely experiencing fragmentation, duplication, or blind spots? Would a Lumen SOC assessment be a worthwhile next step for us?” Take that answer back to your boardroom. |
Tool expansion alone won’t address every security operations challenge. A coordinated, well-governed operation will.
Next step
If your own review or your generative AI assistant flags fragmentation, duplication or low confidence, treat that as a signal to act.
Discover exactly where your organisation stands with a complimentary SOC readiness, maturity or transformation assessment and what it would take to close the gap.
Sources
¹IDC InfoBrief, sponsored by Lumen, The New Cybersecurity Equation: Risk, Response, and Business Outcomes (Doc #US53083025, February 2025)
²Palo Alto, Cortex XSIAM Next Generation SOC platform, 2025
³IDC InfoBrief, sponsored by Lumen, The AI Security Shift: Fuelling the Next Stage of Cybermodernisation (Doc IDC #AP242545IG, December 2025)
Disclaimer: This content is provided for informational purposes only and may require additional research and substantiation by the end user. The information is provided “as is” without any warranty or condition of any kind, either express or implied. Use of this information is at the end user’s own risk. Lumen does not warrant that the information will meet the end user’s requirements or that the implementation or usage of this information will result in the desired outcome of the end user. All third-party company and product or service names referenced in this article are for identification purposes only and do not imply endorsement or affiliation with Lumen. This content represents Lumen products and offerings as of the date of issue. Services not available everywhere. Lumen may change or cancel products and services or substitute similar products and services at its sole discretion without notice. © 2026 Lumen Technologies. All Rights Reserved.
