A structured tool rationalisation that reduced mean time to detect by 3.2Γ β without adding a single new platform to the stack.
Security teams rarely recover 40% of their analyst capacity because someone bought a shinier dashboard. They recover it when someone has the nerve to ask a slightly rude question: which of these tools actually changes a decision?
That was the question at the centre of an eight-week engagement with a 1,200-seat Australian financial services group. The organisation was not immature. It had a modern SIEM, endpoint detection, identity controls, email security, a vulnerability scanner, threat intelligence feeds, ticketing, compliance tooling and reporting packs for management. It also had a familiar problem: every control had its own queue, every queue had its own owner, and every owner had a different definition of done.
The result was expensive operational drag. Analysts were busy, but too much of the work was swivel-chair triage, evidence copying, alert reconciliation and reporting archaeology. The SOC had plenty of signal. It was short on decision velocity.
The starting diagnosis was uncomfortable but useful. The SOC was not drowning because any one tool was bad. It was drowning because the tools had become the operating model. Analysts worked from the logic of licensing rather than the logic of investigations. A suspicious sign-in started in identity, moved to email, jumped to endpoint, detoured into the SIEM, then returned to a ticket where the evidence had to be pasted by hand. Somewhere in that journey, a human had to remember which dashboard was trustworthy this week.
The wider industry context made the finding more urgent. Panaseer reports enterprise environments using an average of 61 security tools and 58 dashboards β with teams spending more than a third of their time gathering, analysing and reporting data. Tines has found that analyst burnout is closely tied to tedious manual work, not a lack of commitment to the mission. Cyber teams are not short of screens. They are short of coherent flow.
Australian organisations are feeling that pressure directly. ASD's ACSC reported more than 84,700 cybercrime reports in FY2024β25 β an average of one report every six minutes β and an average self-reported business cybercrime cost of $80,850. When the vulnerability queue grows and the SOC workflow fragments, the business inherits risk in the form of delay.
"The SOC had plenty of signal. It was short on decision velocity. Analysts were not working from the logic of investigations β they were working from the logic of licensing."
GadgetAccess approached the work as an operating-model problem, not a procurement clean-up. The first step was to build a control-to-decision map. For each high-value use case, the team asked what the analyst needed to know, which tool produced the best evidence, which platform owned the workflow, and which person could approve the next action. This immediately exposed duplicate alerting and orphaned reports that existed because they had always existed.
The second step was deliberately practical. Every tool in scope was sorted into one of four categories. The distinction between the first two mattered most: a tool can be valuable without deserving a daily analyst console.
Tools that make active security decisions β blocking, detecting, enforcing policy. These stay in the analyst's daily path and remain primary workflow surfaces.
Tools that provide valuable signal but don't need daily console review. Their findings are normalised into the primary workflow rather than reviewed as standalone dashboards.
Tools with unique evidence value that need to feed a shared investigation flow β not maintain their own queue. Findings consolidated into a single case language.
Tools with duplicate coverage, stale integrations or no demonstrated decision-making value. Retired from the analyst path β and in several cases, from the licensing budget entirely.
Tool rationalisation is not a smaller shopping list. It is a clearer path from signal to decision.
For each high-value use case: what does the analyst need to know? Which tool produces the best evidence? Which platform owns the workflow? Which person can approve the next action? This immediately surfaced duplicate alerting and orphaned reports that had never been challenged because they had always been there.
Working through all 37 tools in scope, each was assigned to one of the four categories based on its decision-making value, not its licence cost or the seniority of the person who bought it. The output was a clear picture of which tools deserved analyst attention and which were producing noise that absorbed it.
Priority detections, vulnerability exceptions, control evidence and incident actions were mapped into a shared taxonomy. This made handover cleaner and reporting less theatrical. The goal: no analyst should need a spreadsheet sΓ©ance to explain whether a control is working β and no SOC lead should be uncertain whether a queue is genuinely growing or being counted in three places at once.
"Nobody should need a spreadsheet sΓ©ance to explain whether a control is working."
After rationalisation, the analysts still had access to specialist tools. What changed was the daily path. Alerts entered a common triage pattern, evidence was assembled automatically where possible, and low-value duplicates were suppressed or demoted. The SOC lead could see whether a queue was genuinely growing or merely being counted in three places.
SOC analyst capacity recovered from repetitive low-value work
Improvement in mean time to detect across priority use cases
Tools rationalised from 37 in scope to 13 active analyst consoles
From engagement start to measurable operational improvement
The recovered 40% was measured as analyst-hours removed from repeated low-value work over a normal operating month. Understanding where that capacity came from β and where it was reinvested β is more instructive than the headline number.
This is the part of SOC improvement that budget discussions often miss. A saved hour is only valuable if it is reinvested into better decisions β not silently absorbed by the next wave of noise. The group also changed how compliance evidence was handled. Control evidence was captured as part of normal operations. Essential Eight, PSPF, ISM, ISO 27001:2022 and NIST obligations were no longer treated as separate audit-season rituals.
The headline metric was mean time to detect. Across the agreed priority use cases, MTTD fell from 3 hours 12 minutes to 1 hour. That is a 3.2Γ improvement β but the number is less interesting than the cause. The improvement came from correlation, clean escalation paths and pre-agreed decision rights. When the analyst knew which evidence mattered and which action owner was accountable, the clock stopped being wasted on interpretation.
This distinction matters in the current threat environment. Vulnerability discovery is accelerating. Defensive operations must reduce waiting time between signal, prioritisation and action. Organisations that rely on complexity to feel comprehensive will find that complexity compounds their response delay at the worst possible moment.
"The most important saving was not the licence line item. It was the return of analyst attention β the scarcest asset in a busy security operation."
How a 1,200-Seat Financial Services Group Recovered 40% of SOC Analyst Capacity Β· GadgetAccess Β· April 2026 Β· Anonymised Case Study
How Australian security teams are absorbing hidden operational tax and what the data says about where it starts.
Webinar Summary Β· April 2026A practical session for security managers and compliance leads navigating ASD requirements.
Take our free 10-question SOC Complexity Diagnostic and get a scored read on where your hidden costs are starting β or book a briefing with one of our advisors to discuss your specific environment.