Asymmetrica All articles
Security

Exhaustion as a Revenue Model: How the Security Industry Profits From Defender Burnout

Asymmetrica
Exhaustion as a Revenue Model: How the Security Industry Profits From Defender Burnout

There is a peculiar arithmetic at work inside most enterprise security operations. Headcount stays flat. Threat volume rises. Vendor contracts multiply. And somewhere in the middle of that equation, the people responsible for keeping the organization safe quietly begin to break down. What looks from the outside like a workforce management problem is, on closer inspection, something more deliberate — a structural arrangement in which the security industry's revenue model depends, in no small part, on the perpetual exhaustion of the defenders it claims to serve.

This is not a conspiracy. It is an emergent property of misaligned incentives operating at scale. But the outcome is no less damaging for being uncoordinated.

The Fatigue Loop Nobody Talks About

Security operations teams in the United States are operating under conditions that would be considered untenable in most other knowledge-work disciplines. According to multiple workforce surveys conducted over the past several years, analyst burnout rates in security operations centers consistently exceed those in adjacent IT functions. Alert fatigue is endemic. Mean time to respond creeps upward not because teams lack capability, but because they lack capacity.

The vendor response to this condition is instructive. Rather than addressing the underlying staffing deficit, the industry's standard prescription is more tooling. A new SIEM integration. An AI-assisted triage layer. A managed detection and response add-on that promises to absorb the overflow. Each solution arrives with its own licensing agreement, its own onboarding burden, and its own renewal cycle — all of which require the attention of the same exhausted team the tool was ostensibly purchased to relieve.

The loop is self-reinforcing. Fatigue creates demand for automation. Automation creates integration complexity. Complexity creates new fatigue. And at each turn of the cycle, a vendor collects a renewal check.

Asymmetric Economics in Plain Sight

The economic asymmetry here is worth stating plainly. A security vendor operates at scale. It develops a product once and licenses it across thousands of organizations. Its cost structure is largely fixed after development; each additional customer represents near-pure margin. The defender, by contrast, operates at the opposite end of the leverage curve. Every new tool in the stack requires human time to configure, monitor, tune, and renew. The marginal cost of each additional solution falls almost entirely on the team absorbing it.

This means that the vendor's rational interest — maximizing the number of deployed tools — is structurally opposed to the defender's rational interest, which is minimizing operational complexity per unit of security outcome. The industry's growth metrics celebrate tool proliferation. The defender's performance metrics suffer from it.

When a security team is too overwhelmed to rigorously evaluate whether a given tool is delivering value, renewal becomes the path of least resistance. Canceling a contract requires a justification process, a replacement evaluation, and a migration effort — all of which demand time that burned-out teams do not have. Renewal, by contrast, requires a purchase order. The asymmetry of effort ensures that underperforming tools persist in stacks long after they have ceased to earn their place.

The Talent Drain Compounds the Problem

Burnout does not merely reduce productivity. It drives attrition. When experienced analysts exit security operations roles — whether to vendor-side positions, consulting practices, or adjacent fields with less punishing on-call requirements — the institutional knowledge they carry leaves with them. What remains is a team that must rebuild competency from a lower baseline, typically while managing the same tool sprawl that contributed to the departure in the first place.

Vendors, it should be noted, benefit from this talent flow as well. The security industry employs a substantial number of former practitioners in sales engineering, customer success, and professional services roles. There is nothing improper about this; former defenders often make excellent vendor employees. But the structural effect is worth acknowledging: the industry systematically draws talent away from the defender side of the equation, concentrating expertise in organizations whose commercial interests do not always align with those of the teams left behind.

What Breaking the Cycle Actually Requires

Organizations serious about escaping the burnout-to-upgrade treadmill need to reframe the problem before they can address it. The instinct, when a security team is struggling, is to ask what technology they are missing. The more productive question is what operational burden they are carrying that technology will not resolve.

Several principles tend to distinguish organizations that manage this well from those that do not.

Tool consolidation as a security posture, not a budget exercise. Reducing the number of platforms a team must operate is not merely a cost-cutting measure. It is a direct investment in analyst capacity. Every tool removed from the stack is time returned to the team. Security leadership that frames consolidation in operational terms — rather than financial ones — tends to encounter less internal resistance and achieve more durable outcomes.

Contractual discipline at renewal time. The renewal moment is one of the few points at which defenders hold genuine leverage over vendors. Organizations that build rigorous outcome reviews into their renewal calendar — measuring actual detection efficacy, integration reliability, and analyst time consumption against the tool's stated value proposition — are far better positioned to make rational decisions than those that treat renewal as administrative routine.

Staffing investment as a force multiplier. The industry's emphasis on tooling as a substitute for headcount has been so thorough that many security leaders have internalized it. In practice, a well-staffed team operating a lean, well-integrated stack consistently outperforms an understaffed team managing a sprawling vendor portfolio. The math is not complicated; the organizational will to act on it often is.

Vendor accountability clauses. A growing number of sophisticated procurement teams in the US are embedding performance benchmarks directly into vendor contracts — requiring demonstrable outcomes rather than accepting capability claims at face value. This shifts at least a portion of the operational risk back toward the party best positioned to manage it.

The Structural Argument Vendors Prefer You Not to Make

The security industry is not monolithic, and many vendors operate with genuine commitment to customer outcomes. But the market structure within which even well-intentioned vendors operate creates incentives that compound against defenders over time. Recognizing this is not cynicism — it is the kind of asymmetric analysis that effective security leadership requires.

The organizations best equipped to navigate this environment are those that treat vendor relationships as adversarial in the contractual sense: structured, documented, and subject to rigorous performance review. Not hostile, but disciplined. The attrition cycle that benefits vendors depends on defenders being too fatigued to push back. Removing that fatigue — through consolidation, staffing, and contractual rigor — is how the cycle breaks.

The asymmetry, in other words, runs in both directions. Vendors profit from defender exhaustion. Defenders who refuse to be exhausted recover the leverage.

All Articles

Related Articles

Least Privilege, Maximum Leverage: How Scarcity of Access Defeats Both Insider Threats and Sophisticated Adversaries

Least Privilege, Maximum Leverage: How Scarcity of Access Defeats Both Insider Threats and Sophisticated Adversaries

Logged but Invisible: How Attackers Exploit the Architecture of What You Cannot See

Logged but Invisible: How Attackers Exploit the Architecture of What You Cannot See

Controlled Contrition: How Breach Disclosures Are Engineered to Protect Vendors While Customers Pay the Price

Controlled Contrition: How Breach Disclosures Are Engineered to Protect Vendors While Customers Pay the Price