If protection matters, it stands to reason that more tools must mean more safety. Choose a strong product for every risk, plug each gap, and the business is better protected.
It sounds sensible enough. But a recent Forrester Total Economic Impact™ study, commissioned by Microsoft in May 2026, suggests something different. For many organisations, fewer tools can reduce cost and improve security at the same time.
What the study found
As security environments become more complex, organisations often find themselves managing multiple tools, disconnected alerts and increasing operational overhead.
The latest Forrester Total Economic Impact™ study, commissioned by Microsoft, examined what happened when organisations consolidated multiple standalone security tools onto a single, integrated Microsoft Security platform. The findings showed that a more connected approach to security operations strengthened overall security while improving operational efficiency.
For the composite organisation modelled in the study, moving to an integrated platform reduced the likelihood of a security breach by up to 30% and lowered the cost of breaches that did occur by up to 25%. It also enabled security teams to detect and respond to threats more quickly.
One government organisation, for example, reported detecting and responding to threats around 50% faster. By using automated remediation in Microsoft Sentinel, it further reduced incident response times by 25%.
Over a three-year period, Forrester estimated the value of these security improvements at €1.4 million for the composite organisation.
Why simpler can be safer
When organisations rely on multiple standalone security tools, each product may perform its role well. The challenge is what happens between them.
Security signals become fragmented across different tools, teams move between multiple consoles, and related alerts aren’t always connected. Those gaps slow investigations, increase operational effort and can make it harder to identify and contain threats quickly.
An integrated Microsoft Security platform brings together signals from identities, devices, data and cloud environments, giving security teams a single, connected view of their security estate. This helps them:
- Identify risks earlier
- Correlate related signals more quickly
- Spend less time switching between tools and more time focusing on the incident
- Contain incidents before they spread
- Respond with greater context and confidence
This is where simplification starts to strengthen security, not simply by reducing the number of tools, but by removing the operational friction that slows teams down.
Why complexity becomes a risk
Security complexity rarely appears overnight. A new threat emerges, another tool is added, a contract renews, a team changes. Over time, what began as sensible decisions can become a security estate that’s increasingly difficult to manage.
As more standalone tools are introduced, visibility becomes fragmented and operational effort increases. Security teams spend more time switching between consoles, correlating alerts and escalating incidents. Response slows down, costs rise and maintaining a clear picture of risk becomes more challenging.
The Forrester study suggests that consolidation can help reverse this trend. One regional CIO in government reported that bringing data together through Microsoft Defender and Microsoft Sentinel made it much easier to correlate signals and apply security policies consistently. Tasks that had previously required multiple tools became simpler, giving the team greater visibility and enabling faster responses.
The cost picture improves too
The financial findings pointed in the same direction.
For the composite organisation, consolidating onto Microsoft Security reduced annual technology spend by up to 23%. Over three years, retiring duplicate licences, reducing consumption charges and lowering professional services costs delivered estimated savings of €10.04 million. The integrated platform also reduced manual effort, helping the organisation avoid increasing security headcount by up to 40% by the third year.
Overall, Forrester calculated a 124% return on investment, with a payback period of less than six months for the composite organisation.
These findings aren’t about replacing security professionals. They’re about reducing manual effort, simplifying day-to-day operations and enabling security teams to spend more time on high-value work instead of managing disconnected tools and repetitive tasks.
