One platform instead of dozens of tools. How much does it save you?
Companies in an early growth phase often choose a best-of-breed approach: separate tools for individual problems. HubSpot as a CRM, Monday for projects, Zendesk for support. That lets them keep a high degree of flexibility and agility. But once a company starts to scale, new products, markets and services arrive, and with them more tools. Gradually an environment of dozens of solutions emerges, whose operation, integration and management demand ever more time and money. How does this cumulative growth in costs show up in security?

Esther Idris Beshirová
Technical copywriter with several years of journalistic experience. Enjoys writing about technology and cybersecurity.

According to Gartner, companies today run a large number of systems that were built earlier and were not designed for the current pace of growth. Maintaining these solutions then swallows 60-80 % of the IT budget, instead of the money going towards supporting further growth.
The growing number of tools and the links between them has two direct effects.
Financially it shows up as higher and less predictable costs. Operating overhead grows, so does the number of supporting roles and the volume of spending that disappears into onboarding, maintenance and integration costs. Technical teams, in turn, find that even routine changes have to be coordinated across several tools, security incidents are handled between several vendors and a shared operational context is missing.
The same problem shows up once in costs and a second time in the fact that even simple changes take a long time, operations are opaque and during outages it is unclear where the problem arose or who is supposed to fix it.
⇢ In fintech, every additional tool means not only higher operational complexity but also a bigger security and regulatory burden. Complex data synchronisation between systems raises operating costs and increases the pressure on the accuracy and availability of key services.
⇢ In e-commerce, the consequences of complexity show most during peaks, when systems are under the heaviest load. Failed integrations or delayed data translate immediately into revenue, margins and customer experience.
⇢ At SaaS companies, teams spend a considerable part of their time managing tools and their connections instead of working on the product. Missing links between data also increase the risk of overlooking the signals that lead to customer churn, so costs rise without the customer experience or the pace of development improving.
Visible costs
The visible costs of a security stack most often appear in two areas: in the licences of individual tools and in the direct impact of service performance and availability on revenue.
The most visible item is licences and subscriptions. Every security tool has its own pricing model; some charge per user, others per traffic volume, number of requests, rules or protected applications. As a company grows, so do the traffic, the number of users and the applications that need protecting. Costs therefore rise automatically according to each vendor's price list, regardless of whether the actual level of protection or efficiency improves accordingly.
The second visible area is the cost tied to performance and availability. Slow pages, outages or degraded service have an immediate and measurable impact on revenue, conversions, customer churn and the fulfilment of contractual obligations, and feed directly into business results.
According to a study by Boston Consulting Group, growing technological complexity has a direct impact on the performance of digital companies. The so-called complexity tax shows up as a drop of up to 30 % in the speed of bringing new products to market.
Growing traffic volume, moreover, does not necessarily mean a growing business. Roughly 51 % of all web traffic today comes from automated systems, and around 37 % is outright malicious bot traffic. With the rise of generative AI this trend is accelerating further: a large part of the traffic is generated by automated systems that systematically crawl web content and application interfaces without bringing any return in the form of conversions, revenue or real user activity.
Every such request loads the infrastructure just like a legitimate user. It consumes computing capacity, generates data transfer and increases the volume of information the security tools have to process. In an environment with several security vendors, moreover, one and the same request often passes through several layers of protection, monitoring and analytics in parallel. The result is that the company pays more for security and infrastructure without it leading to higher value for customers or faster growth.
Hidden costs
Integration, onboarding and training
Every new security tool means another project. It has to be deployed, tested, connected to the other systems, given processes for incidents, reporting and escalation, and then the teams have to learn to work with it. In a best-of-breed environment these activities repeat with every additional vendor.
According to MuleSoft, the average company with 1,000 employees today uses almost 900 applications, but only 28-29 % of them actually talk to each other.
When every tool has a different interface, different terminology and a different configuration logic, the training demands on staff grow. The teams are not learning security but how to work with specific products. Internal documentation swells, guides and exceptions multiply, and the dependence on the few people who truly understand the stack deepens. A security tool the team does not understand in the context of the other systems is then expensive regardless of the licence price.
Vendor management: contracts and unclear responsibility
With a growing number of vendors, the operational overhead outside the technical area grows too. Every vendor has its own contract, a different licence renewal date, a differently defined SLA, that is guaranteed availability and response times, and its own model of technical support and escalation.
In practice this means that during an incident a "blame game" often starts. The vendor of one tool claims the problem arose elsewhere, another points at the integration layer and a third at the input data. Meanwhile the business stands still, the company is not selling and is paying everyone involved to point fingers at each other. With an integrated solution the responsibility is clear; in a multi-vendor environment it dissolves between contracts and support desks.
Egress: the hidden tax on moving data
One of the least visible but fastest growing costs is the fees for transferring data between systems. As soon as a company uses several cloud services and security tools, data flows between them constantly: traffic, logs, events and API responses. So it is not just about "data leaving the cloud" but about how many times one and the same request has to cross the boundary between individual systems.
Imagine a single automated request, for example a bot:
- it passes through a CDN (vendor A),
- then a web application firewall (vendor B),
- bot protection (vendor C),
- an analytics tool (vendor D),
- and finally gets logged in a central event system (vendor E).
The result is that one single request is processed several times in a row, analysed again each time, stored in logs and often also transferred between different environments. The cost problem is therefore not the traffic volume itself but the number of boundaries the data has to cross in a fragmented architecture. According to Cloudflare data, optimising data flows and limiting unnecessary transfers can save customers 7.5-27 % of their monthly cloud bill.
Overlapping features: paying several times for the same thing
Modern security tools overlap in functionality. Basic bot protection, rate limiting, protection against application attacks or API security elements now appear across different products. Every tool solves the same problem from "its own angle", but as a separately priced feature.
The result is not stronger protection but multiple processing of the same traffic and multiple billing of similar functions. The cost here does not come from one bad decision but from the sum of individual choices that at a certain scale start to overlap and become expensive.
Security risk arises at the interfaces
In a fragmented security environment, incidents rarely play out in a single layer. A typical scenario combines several phenomena at once: a sudden surge in traffic, slower pages, errors in application interfaces and increased activity of automated systems. An attack or an operational problem therefore does not hit one tool but gradually spreads across the whole security environment.
This is exactly where the weakness of a multi-vendor architecture shows. Every tool watches only its limited slice of reality and reports that "everything is fine on its side". The team is meanwhile solving three questions at once: where the problem actually arose, who is responsible for it and which support to contact first. The incident resolution drags on not because of the technical sophistication of the attack but because of the missing shared context. Nobody has the whole picture and therefore no clear responsibility either. The response slows down, the attack is not stopped where it started and its effects gradually spread to other parts of the infrastructure.
Fragmentation of security tools has one more, often overlooked consequence: it encourages so-called shadow IT. It is a natural reaction of people to an environment that is complex, slow to change and split into dozens of different interfaces. If every vendor has its own dashboard, a different configuration logic and a different way of working with data, teams start helping themselves outside official processes. They acquire their own tools for monitoring, analysis or sharing information so they can work faster. The result is a loss of overview at management level and a further spread of security weaknesses.
Other surveys confirm the extent of the risk. According to data from the Capterra platform, 76 % of small and medium-sized companies consider shadow IT a moderate to high security threat. Almost half of cyber attacks have a direct or indirect link to unauthorised tools, and the average cost of resolving these incidents runs into millions of dollars.
When does consolidation make sense?
A typical sign of the tipping point is when the company's management loses a coherent overview of how the organisation works. Data stays scattered across different systems, reporting takes days and decision-making slows down. Business development recedes into the background and employees work in a fragmented environment that increases errors and frustration instead of simplifying their work. The departure of one key specialist can slow the whole process significantly or stop it completely.
At this point the originally rational best-of-breed strategy turns into "best-of-grief". Finance leadership watches spending on external consultants who maintain the connections between systems keep growing. Technical leadership watches teams that, instead of innovating, deal with broken interfaces and operational incidents. And the company's leadership as a whole faces an organisation that is modern on paper but slow in practice, exposed to security risk and struggling to deliver its business strategy. The solution is a single cloud platform that joins protection, performance and traffic management over the same data and one global network, and removes the hidden costs by eliminating unnecessary transfers, overlapping features, integration projects and unclear responsibility.
Integrity
news
Articles from our blog. The latest about the Cloudflare platform and everything around it.
.jpg)

.jpg)



