Safety2 min read

More Cybersecurity Tools Often Mean Less Protection

By , Senior AI ConsultantPublished

New threat data shows hackers now break in and move across a network in under 30 minutes on average, while the typical company runs over 80 disconnected security tools that cannot share information fast enough to stop them.

The World Economic Forum recently made a point that should worry any executive who assumes more security software means more safety. Often, it means the opposite. Fresh data backs this up in a way that is hard to ignore.

Start with speed. CrowdStrike's 2026 Global Threat Report found that AI-enabled attacks increased 89 percent in a single year, and the average time it takes an attacker to break in and start moving toward valuable data fell to just 29 minutes, with the fastest recorded case happening in only 27 seconds and one intrusion beginning data theft within four minutes of first access.

Now look at how most companies are set up to respond. An IBM study found that the average organization runs 83 separate security tools from 29 different vendors, each with its own screen, its own alerts, and often its own team watching it. When an attacker can move in under half an hour, a warning that takes an hour to reach the right person is worthless.

The cost of that gap shows up in IBM's breach research. Incidents where company data was spread across multiple systems cost an average of 5.05 million dollars and took 276 days to fully identify and contain, compared to 4.01 million dollars for breaches confined to on premise systems. That gap is less about the data itself than about how long it takes disconnected teams to realize they are looking at the same attack.

Attackers are also getting help from AI in ways that make old defenses weaker by the month. Phishing detection firm Hoxhunt found that AI-written phishing messages, which made up under 5 percent of attacks for most of 2025, jumped 14 times over in December to 56 percent of all attacks detected. These messages are harder to catch because they no longer contain the typos and awkward phrasing that used to give scams away.

Small and mid-sized companies should pay close attention too, since the idea that hackers only chase large corporations is outdated. Data from the Verizon Data Breach Investigations Report shows ransomware appeared in 88 percent of breaches at small and mid-sized businesses, more than double the 39 percent rate at large organizations, largely because smaller firms hold enterprise-level data with a fraction of the budget to defend it.

This is also why the security industry itself is consolidating. Large vendors including Microsoft, Palo Alto Networks and CrowdStrike are now capturing a growing share of security spending by selling bundled platforms instead of single-purpose tools, a shift that mirrors exactly what the WEF is describing: buyers are tired of managing dozens of disconnected products.

There is a real cost to staffing this properly in house too. Running a security team that watches for threats around the clock typically requires 8 to 12 full-time analysts, pushing personnel costs alone past 1.6 million dollars a year before any software is purchased, which is why many mid-sized firms choose a specialized partner instead of building this from scratch.

Cyber insurance data suggests the fix works where it happens. Insurer Coalition reported that claims frequency rose 3 percent in 2025, yet the average claim payout fell 19 percent to 116,000 dollars, a sign that faster, better coordinated response is cutting the damage even as attacks keep climbing.

The lesson is not to buy fewer tools or more tools. It is to stop counting tools altogether and start asking whether the ones you already own can act as a single team instead of a stack of alarms nobody is watching together.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable