Security News

Cybersecurity news aggregator

INFO News Dark Reading

When Too Much Security Data Became the Risk

  • What: Excessive security data can become a risk for organizations
  • Impact: Highlights challenges in managing and securing large volumes of security data
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Vulnerabilities & Threats Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. by Jeffrey Schwartz Jul 2, 2026 8 Min Read Application Security Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS by Alexander Culafi Jul 1, 2026 4 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America See All The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cyber Risk Threat Intelligence Endpoint Security Сloud Security Case Studies News, news analysis, and commentary on the latest trends in cybersecurity technology. When Too Much Security Data Became the Risk Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM. Joan Goodchild , Contributing Writer , Dark Reading July 1, 2026 4 Min Read Source: BrianA Jackson via Getty Images For years, conventional wisdom in security operations was simple: collect everything. Logs were cheap. Storage was plentiful. And the more data a team had, the more confident it could feel about detection and forensics. That assumption quietly broke as organizations scaled. At Vensure Employer Solutions, a privately held HR services and payroll provider supporting more than 95,000 businesses, telemetry volume did not just grow; it exploded. Rapid acquisitions, expanding infrastructure, and a growing customer base turned routine firewall traffic into a relentless stream of raw data flowing into the company's security information and event management (SIEM) environment. "We were ingesting everything," says Dwayne Smith, SVP of Information Security and Global CISO at Vensure. "People would shove everything they could in there." The breaking point was not a breach; it was the bill. As Vensure integrated more environments through mergers and acquisitions, the cost of ingesting logs began to climb at an unsustainable rate. Network traffic, routine firewall connection logs, flow records, and benign system events accounted for the bulk of the growth. By Smith's estimate, ingestion costs nearly tripled over two years. Related: Bugcrowd Launches EU Data Residency Option For Evolving Data Sovereignty Needs "It's not only the cost of storing it," he says. "It's maintaining it, managing it, and the policy and evidence around it." Just as concerning, the flood of low-value telemetry made it harder for analysts to see what actually mattered. Alerts were buried in noise. Investigation queues lengthened. Mean time to respond crept upward. "It wasn't sustainable," Smith says. Rethinking What Belongs in the SIEM Rather than cutting tools or headcount, Smith's team took a harder look at the data and security data pipeline that ingests, enriches, and routes telemetry across tools and teams. Not all logs, they realized, deserve equal treatment. Utilizing machine learning and large language models in the security data pipeline enabled Vensure to automate filtering incoming logs (e.g., DNS or firewall "allows") and identify and filter out high-volume, low-value data. This reduced SIEM costs and noise without losing critical alerts. Firewall telemetry became the first test case. While threat and intrusion alerts carried clear security value, raw connection logs, which made up the majority of events, were rarely used in day-to-day detection or response. They were kept "just in case." "Paying for all those logs, just to have them laying around, becomes a real business problem," Smith says. Related: What It'll Take to Make AI BOMs Usable in a Modern Security Program The result was an 83% reduction in firewall log ingestion, without eliminating threat, intrusion, or authentication events. Proving Signal Wasn't Lost Filtering data before ingestion is a high-stakes decision for any CISO. Lose the wrong logs, and detection gaps can follow. To validate the approach, Smith's team ran side-by-side comparisons using native firewall metrics, historical data, and simulated attack traffic. They also used artificial intelligence models aligned to frameworks like MITRE ATT&CK to ensure filtered data was still interpreted through the correct threat context. The goal was not just cost reduction. It was confidence. "When we filtered those logs, we were actually able to understand our environment better," Smith says. With fewer irrelevant events crowding dashboards, analysts could more clearly see scanning activity, vendor-initiated testing, and genuine anomalies. In some cases, the cleaner signal helped the team confirm whether external security tools were functioning as expected, something that had previously been obscured. Measurable Operational Gains The financial impact was immediate: approximately $250,000 in annual savings tied directly to reduced ingestion and storage costs. But the operational improvements mattered more. Mean time to respond dropped by roughly 50%, as analysts spent less time triaging false positives. Detection accuracy improved as broad signatures were refined into more precise indicators. Administrator behavior became easier to track, strengthening identity and access monitoring. Compliance reporting improved, particularly regarding regional data-handling requirements. Related: Is 2026 the Year AI Bills of Materials Get Real? "It led to the same amount of people doing not only more work, but better work," Smith says. Cost Control, Not Just Automation Much of the industry conversation around AI in security focuses on autonomous response, agentic workflows, and predictive analytics. Smith does not dismiss those use cases, but he believes cost discipline may be the technology's most immediate and underappreciated benefit by controlling the runaway spending on data. "This isn't sustainable," he says. "If AI can help reduce that pressure, that matters." For Smith, the lesson is not about adopting a specific tool or model. It is about questioning long-held assumptions, especially the belief that more data always equals more security. Read more about: CISO Corner About the Author Joan Goodchild Contributing Writer, Dark Reading Joan Goodchild is a veteran journalist, editor, and writer who has been covering security for more than a decade. She has written for several publications and previously served as editor-in-chief for CSO Online. See more from Joan Goodchild Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets Say Yes to AI: Securing Innovation Without Compromise More Webinars Latest Articles in DR Technology Vulnerabilities & Threats Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. Jul 2, 2026 | 8 Min Read Identity & Access Management Security Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions Jun 26, 2026 | 5 Min Read Application Security Robinhood Cuts Access Approval Time to Support High-Velocity Development Jun 25, 2026 | 7 Min Read Cybersecurity Operations Segmentation Works for OT If Operators Are Paying Attention Jun 11, 2026 | 5 Min Read Read More DR Technology Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us Newsletter Sign-Up Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home | Cookie Policy | Privacy | Terms of Use Your Privacy Choices

Share this article