3rd
Rank of security tooling among least-optimized SaaS spend categories in the FinOps Foundation's 2026 report, behind data cloud platforms and AI
90%
Share of organizations managing or planning to manage SaaS spend through a FinOps practice in 2026, up from 65% in 2025
0
Reliable dollar figure this guide will give you for what any specific tool consolidation saves, because that number depends entirely on your own contracts and usage
2
Core primitives (tagging and showback) that every security FinOps practice in this guide depends on before any overlap audit or license review can run

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

A budget review lands on the security team's desk, finance asks for a 15 percent reduction in tooling spend, and the fastest available answer is to pick the three most expensive line items and cancel the ones that seem least essential. That approach works until the tool that gets cut turns out to be the one covering a compliance requirement, or the team discovers six months later that two platforms were quietly doing the same job at twice the cost of one. The FinOps Foundation's State of FinOps 2026 report lists security tooling as one of the least actively optimized SaaS and PaaS spend categories, trailing behind data cloud platforms and AI, which the report attributes to rapidly scaling spend, unpredictable usage patterns, and pricing models that do not yet have established optimization playbooks. Security teams are not exempt from the budget conversation finance is already having about cloud and SaaS spend elsewhere in the business, and showing up to that conversation without cost data of their own means someone else decides what gets cut. This guide covers how to build a repeatable, security-specific FinOps practice: tagging spend so it can be attributed, running showback so cost is visible to the teams generating it, auditing overlap so redundant coverage gets found before finance finds it, and reviewing consumption-based licenses so a renewal decision is based on actual usage rather than the vendor's proposed uplift. For the broader budget cycle this practice feeds into, see our guide to security budget planning for CISOs, and for how to translate the resulting numbers into board-level language, see our guide on using financial metrics to justify security budget to the board.

The problem: budget cuts without usage data cut the wrong thing

Security tooling spend has grown the way most SaaS spend has grown: incrementally, tool by tool, team by team, with each purchase justified on its own merits at the time and rarely revisited afterward. A SIEM contract signed three years ago, an EDR agent added after an incident, a cloud security posture management tool bought during a cloud migration, a vulnerability scanner inherited from an acquisition. Individually, each purchase made sense. Collectively, nobody owns a current picture of what all of it costs, who is actually using each seat or ingestion tier, and where two tools quietly cover the same ground.

When a budget review arrives, the fastest path to a number is a flat percentage cut applied across every line item, or a judgment call about which tools "feel" replaceable. Both approaches share the same flaw: they are not based on measured usage or documented overlap, so they carry real odds of cutting a tool that is load-bearing for a compliance control while leaving an underused, redundant license untouched simply because nobody looked. The FinOps Foundation's 2026 findings back this up indirectly. Security tooling sits among the categories organizations are least actively managing today, which means most security teams walking into a budget conversation right now do not have the tagging or showback data a cloud or platform team increasingly does. Building that data before the budget review, not during it, is the entire point of this guide.

Prerequisites

  • An inventory of every security tool currently under contract, with owner, renewal date, and contract type (seat-based, consumption-based, or flat-fee) recorded for each. If this inventory does not exist yet, building it is step one of the procedure below, not a separate project.
  • Read or write access to your cloud billing console (AWS Cost Explorer, Azure Cost Management, or GCP Billing) and to each SaaS security vendor's usage or admin dashboard, since tag-based and showback reporting depend on both.
  • A tagging or labeling convention already in use somewhere in the organization, even if it is only applied to cloud infrastructure today. A security FinOps practice extends an existing convention to security tooling; it does not need to invent one from scratch.
  • A named finance or FP&A counterpart who will receive the showback report. Showback only works as a forcing function if someone outside the security team is actually looking at the numbers.
  • Executive sponsorship to ask each tool owner for actual usage data (seats provisioned versus seats active, data ingested versus data licensed, API calls made versus API calls entitled). Some of this data lives with the vendor, not with you, and getting it sometimes requires a formal request through your account team.
Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Step-by-step: building the security FinOps practice

  1. Build the tool inventory. List every security tool with an active contract: SIEM, EDR/XDR, vulnerability management, cloud security posture management (CSPM), identity threat detection, email security, secrets scanning, SOAR, threat intelligence feeds, and any point tools acquired for a single project. For each, record the owning team, the contract type, the renewal date, and the nominal license count or consumption tier.

  2. Apply a consistent tagging scheme to security spend. Tag cloud-hosted security tooling (a self-hosted SIEM, a CSPM running as a SaaS-connected service, a custom detection pipeline) the same way you tag other cloud cost, by team, environment, and cost center, using your cloud provider's native tagging or labeling. For SaaS-billed security tools that do not run in your cloud account, maintain a parallel mapping in your inventory spreadsheet or a FinOps tool that supports manual cost allocation, since these vendors will not expose a tagging API you control.

  3. Attribute cost to the team or function that consumes it, not just the team that holds the contract. A SIEM licensed centrally by the security team but ingesting logs primarily from three product engineering teams should show cost allocated to those three teams' cost centers, not buried entirely under "security." This step is what makes showback meaningful instead of just a repackaged invoice.

  4. Run a showback report, not yet a chargeback. Publish, on a recurring cadence, what each team's security tooling consumption actually costs, without moving money between budgets. Showback surfaces the behavior change, a team that sees its own log ingestion volume driving SIEM cost tends to start filtering noisy sources, without the political friction of an actual internal billing mechanism.

  5. Audit for tool overlap. For each pair of tools with adjacent function (two CSPM tools, a SIEM plus a separate log analytics platform doing similar detection work, two vulnerability scanners covering the same asset classes), document exactly which capability each one uniquely provides. Overlap that exists for a documented reason, redundancy across a merger integration, a second tool required by a specific customer contract, is not automatically waste; overlap that exists because nobody has looked recently is the actual target.

  6. Pull consumption data for every consumption-based license before its renewal date, not after the renewal notice arrives. For seat-based tools, compare provisioned seats to active seats over the trailing 90 days. For ingestion-based or API-call-based tools, compare the licensed tier to actual trailing usage. A tool at 40 percent of its licensed capacity is a renegotiation target regardless of whether it is otherwise doing its job well.

  7. Bring the overlap findings and consumption data into the renewal or budget conversation as a ranked list: tools with clear, undocumented overlap and low utilization first, tools with partial overlap or moderate utilization second, and tools that are fully utilized and uniquely functioning left alone. This ordering is what replaces an across-the-board percentage cut with a targeted one.

  8. Automate the recurring parts. Policy-as-code tools such as Cloud Custodian can flag unused or idle cloud-hosted security infrastructure (an orphaned log collector, an unused scanning appliance) on a schedule instead of relying on someone remembering to check. A dedicated FinOps platform such as Harness Cloud & AI Cost Management or IBM Apptio Cloudability can extend the same tagging, allocation, and commitment-tracking discipline your cloud team already uses for compute spend to the security stack's cloud-hosted components, and give the security team a live dashboard instead of a spreadsheet that goes stale between quarterly reviews.

At a glance: automation options for the recurring work

ToolWhat it actually does hereWhere it fits
Cloud CustodianOpen-source, YAML-defined policy engine that finds unused or idle cloud resources and can act on them (stop, flag, tag) on a schedule, at no license costCloud-hosted security infrastructure you operate yourself: idle scanning appliances, orphaned log collectors, unused compute tied to a security tool's backend
Harness Cloud & AI Cost ManagementCommitment tracking, tagging, and allocation across AWS, Azure, and GCP, including reserved instance and savings plan utilizationTeams that already run cloud commitments and want security-hosted cloud spend folded into the same visibility and allocation workflow
IBM Apptio CloudabilityTag-based cost allocation, showback and chargeback reporting, and multi-cloud cost visibility, with allocation accuracy dependent on tagging disciplineOrganizations that need a dedicated showback reporting layer across security and non-security cloud spend alike

None of these tools reads a SaaS security vendor's internal usage data for you. Seat utilization inside your EDR console or ingestion volume inside your SIEM still has to come from that vendor's own admin dashboard or API, which is why the inventory and manual mapping in steps one and two remain necessary even with a FinOps platform in place.

Validation: confirming the practice is producing decisions, not just reports

Confirm the tool inventory reconciles against actual accounts payable records for a recent quarter. If the inventory is missing a contract that shows up in an invoice, or lists a contract that was already canceled, the rest of the practice is built on a stale foundation and needs to be corrected before anything else is trusted.

Confirm the showback report reaches the actual team leads it is meant to influence, not just the security leadership team. Ask one or two team leads directly whether they have seen their own team's number and whether it changed anything about how they use the tool. A showback report nobody outside security reads is not doing its job.

Pick one identified overlap pair and confirm the documented justification, or lack of one, by asking each tool's primary users a direct question: what does this tool do for you that the other one does not. If the answer is vague or nobody can name a concrete difference, the overlap finding is validated and ready to act on. If the answer names a specific capability, coverage gap, or contractual requirement, document that reason in the inventory so it is not re-flagged as waste next cycle.

Confirm the consumption data pulled in step six matches what the vendor itself reports, not just an internal estimate. A vendor's own usage dashboard is the number that matters in a renewal negotiation; an internally estimated utilization figure that does not match it will not hold up when the vendor's account team pushes back.

Failure cases

  • Tagging applied inconsistently across teams. If one team tags its security-adjacent cloud spend and another does not, the showback report will make the tagging team look like the bigger cost driver simply because its spend is visible, while the untagged team's equal or larger spend hides in an unallocated bucket. Enforce the tagging convention with a policy check, not a request, before trusting any allocation report built on top of it.
  • Overlap findings driving a cut without checking for a documented reason. A tool that looks redundant on paper sometimes exists specifically because a customer contract, an insurance requirement, or a compliance framework mandates a second, independent source of a given control. Cutting it without checking that first can create a compliance gap that costs far more than the license did.
  • Showback quietly becoming chargeback without anyone deciding that on purpose. Showback works because it changes behavior without moving budget; the moment a team's actual budget gets debited for security tooling cost without an explicit decision to do that, the practice has changed in a way that needs its own sign-off, its own dispute process, and its own communication, not just an unannounced shift in a recurring report.
  • Treating a consumption-based license's trailing usage as a permanent baseline. A vulnerability scanner's ingestion volume during a quiet quarter is not the number to renegotiate against if the team already knows a major infrastructure expansion is coming next quarter. Pair trailing usage with a forward-looking plan before locking in a smaller tier.
  • Automating resource cleanup (through Cloud Custodian or a similar tool) against production security infrastructure without a dry-run and an owner sign-off first. A policy written to stop or flag an "idle" scanning appliance can misfire against a system that runs on a longer cycle than the lookback window assumes, briefly disabling a control the team believed was continuous.

Security tradeoffs

Consolidating overlapping tools reduces cost and administrative overhead, but it also reduces the number of independent detection sources covering a given risk. Two tools that appear redundant sometimes catch different things in practice because they use different detection logic or different data sources, even when their marketed capability looks identical on paper. Document what is actually lost, not just what is saved, before finalizing a consolidation decision.

A showback and tagging practice makes security spend visible to people outside the security team, which is the point, but it also means non-security stakeholders now have a basis to argue for cuts to tools whose value is hard to quantify in dollar terms, such as a threat intelligence feed that has not yet prevented a specific incident. Be prepared to make the qualitative case for tools that a spreadsheet cannot fully justify on its own; our guide on translating security work into financial metrics the board understands covers how to frame that case.

Automation that acts on cost findings, stopping an idle resource, downgrading a license tier, needs the same change control discipline as any other production change to security infrastructure. A cost-optimization script and a security-relevant system change are the same category of risk when they touch the same asset; treat commitment orchestration or automated resource cleanup tools accordingly rather than as a purely financial workflow exempt from security review. For the related problem of cost surprises inside AI-driven security automation specifically, see our guide on troubleshooting runaway API cost overruns from AI agents.

The bottom line

A flat percentage cut applied to security tooling spend during a budget review is a guess dressed up as a decision, because it has no data behind it about which tools overlap and which are underused. Tagging security spend, running showback to the teams that actually generate it, auditing overlap with a documented reason requirement, and reviewing consumption-based licenses against real usage before a renewal turns that guess into a ranked, defensible list. The FinOps Foundation's 2026 data shows security tooling is still one of the least actively managed SaaS categories in most organizations, which means most security teams have room to build this practice before the next budget cycle forces the issue. None of the tools involved, Cloud Custodian, Harness, or Apptio Cloudability, replace the manual work of pulling usage data from each SaaS security vendor's own dashboard; they extend an existing cloud cost discipline to the security stack's cloud-hosted components and give the team a place to keep the resulting numbers current instead of rebuilding them from scratch every time finance asks.

Frequently asked questions

What is FinOps for security tooling?

It is the practice of tagging, allocating, and showing back the cost of security tools by owning team and function, so budget decisions can target genuine overlap and underused licenses instead of applying an across-the-board percentage cut during a review.

Why does the FinOps Foundation's 2026 report say security tooling is poorly optimized?

The report lists security tooling among the least actively managed SaaS and PaaS categories, behind data cloud platforms and AI, attributing this to rapidly scaling spend, unpredictable usage, and pricing models without established optimization playbooks yet.

What is the difference between showback and chargeback for security spend?

Showback reports a team's security tooling cost for visibility only, with no budget actually moved, while chargeback debits that cost against the team's own budget. Most security FinOps practices should start with showback before ever considering chargeback.

How do you find overlapping security tools without cutting something essential?

Compare tools with adjacent function and require a documented reason for any apparent overlap before treating it as waste, since some redundancy exists for a compliance requirement, a customer contract, or a genuine coverage gap between similar-looking tools.

Can Cloud Custodian or similar tools optimize SaaS security tool licenses directly?

No. Cloud Custodian and similar policy engines act on cloud infrastructure you control, such as idle compute or orphaned storage tied to a security tool's backend. Seat and consumption usage inside a SaaS vendor's own platform has to be pulled from that vendor's dashboard or API separately.

How often should a security team review consumption-based license usage?

Pull usage data before every renewal date, not after the renewal notice arrives, and treat any license running well below its licensed tier as a renegotiation candidate, while accounting for known upcoming changes in usage rather than trailing data alone.

Sources & references

  1. FinOps Foundation - State of FinOps 2026 Report
  2. Flexera - 13 Best FinOps Tools for Cloud Cost Management in 2026
  3. Harness Cloud & AI Cost Management overview
  4. IBM Apptio Cloudability product page
  5. Cloud Custodian documentation

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.