Low budget, high expectations (7 min)
Cybersecurity is no longer a concern limited to large organizations. According to available data, nearly half of SMEs have already experienced some form of cyber incident, highlighting that the risk is both real and widespread.
Another timely question is entering the discussion: can L1 SOC functions in practice be replaced by AI? Automation and AI are already capable of effectively handling a large portion of routine detection and triage activities, reshaping both the economics and expectations of security teams. The question remains, however, whether this represents a full replacement or rather a shift in the human role toward oversight, interpretation, and the handling of more complex incidents.
Where companies overspend on cybersecurity and how much can be improved even without costly tools. From incident response practice came simple measures that work, from backups to restricting logins by geolocation. It’s not just about technology, but also about people, legislation, and sensible monitoring configuration. Money most often leaks away on licenses and products the organization doesn’t actually use—we buy what the “neighbor” has just to look modern. Outsourcing without clear communication is equally costly: if the partner doesn’t understand your needs, not even a top-tier tool will help. Meanwhile, the basics are forgotten, for example, having working and verified backups so the company doesn’t end up without data in a ransomware attack. Simple policies, such as restricting logins by geolocation or using features already available in services, often deliver more than yet another “box”.What we needlessly pay for in cybersecurity