Cloud security licensing: avoiding the compliance tax.
Cloud security has become the fastest-growing line item in enterprise cloud budgets — and the most poorly negotiated. Native add-ons, identity tiers, and a sprawl of third-party tools now rival compute costs. This note maps where the overpayment sits and how disciplined buyers reduce security spend 30–50% without cutting coverage.
There is no single "cheapest" way to secure a cloud estate — but there is a systematically overpriced one. For a $30M-cloud enterprise, security now routinely reaches $4–8M annually across native add-ons (Defender for Cloud, GuardDuty/Security Hub, SCC), identity tiers, and third-party tools. A structured audit typically recovers 30–50% of that spend without reducing protection — most of it from ISV overlap and default-on native coverage that no one revisits.
01 Key findings
Cloud security is now a compute-scale cost, not a rounding error. Native platform services, identity licensing, and ISV tooling combine into a budget that rivals infrastructure spend for security-conscious enterprises.
Default-on native coverage is the quiet leak. Enterprises enable every Defender plan or the full GuardDuty log set at deployment and never revisit it — paying for protection on resources that do not justify it, at up to double the necessary cost.
Third-party ISV sprawl is the single largest opportunity. A typical Fortune 500 runs 40–70 security tools; 30–40% of ISV spend duplicates native capability or other ISV tools in the portfolio.
Microsoft licensing is double-paid more often than not. Standalone Defender for Cloud plans routinely re-license capability already bundled in M365 E5 — an audit recovers 20–35% of that standalone spend.
Security is bought by security teams, not procurement. Single-vendor purchases, auto-renewals at list, and no benchmarking leave 20–40% on the table against major ISVs that negotiate like any other enterprise software vendor.
02 The cost structure
Enterprise cloud security costs fall into four categories, each with different commercial dynamics and optimisation levers. Mapping spend to the category structure is the first step to finding savings. For broader commercial context, see our Cloud Contract Negotiation Guide.
- Tier thresholds create step-changes managed by architecture
- Custom native pricing achievable but rarely negotiated
- Entra ID P1 vs P2 vs E5-bundled rarely optimised
- Premium features deployed estate-wide by default
- Portfolio duplication across overlapping capability areas
- Fragmented procurement, no consolidated volume
- Premium prices for tools overlapping native capability
- Frameworks re-licensed per business unit
03 Security service pricing matrix
The native security services carry sharply different pricing models and enterprise cost bands. Each has a distinct optimisation lever that reduces spend without reducing visibility.
| Service | Platform | Pricing model | Typical enterprise cost | Primary optimisation lever |
|---|---|---|---|---|
| GuardDuty | AWS | Per GB of logs analysed | $500K–$2M | Exclude low-value log sources; filter before ingestion |
| Security Hub | AWS | Per finding, per account | $100K–$500K | Severity filtering & suppression rules |
| Macie | AWS | Per GB of S3 scanned | Highly variable | Risk-based selective scanning, not full-estate |
| Defender for Cloud | Azure | Per resource, per plan | $1M–$4M | Selective plan coverage; de-duplicate E5 entitlements |
| Security Command Center Premium | GCP | Percentage of GCP spend | Scales with spend | Negotiate pricing cap or flat-rate arrangement |
| Chronicle | GCP | Per GB ingested | Highly variable | Committed-use terms inside the enterprise agreement |
04 Cost at scale
Where does the $4–8M go? Illustrative annual security spend for a $30M-cloud enterprise, by category. Third-party ISV tooling — not the native platform — is consistently the largest slice and the deepest reduction opportunity.
Native services scale with usage, but ISV spend accumulates through years of decentralised procurement — which is why the largest bar is also the softest. Model each category net of achievable consolidation before assuming any line is fixed.
05 The compliance-tax trap
The "compliance tax" is the premium enterprises pay when protection is bought without commercial discipline: coverage duplicated across layers, native capability re-purchased from ISVs, and frameworks licensed repeatedly across business units. It hides in plain sight because each individual purchase looks defensible on security grounds.
Redundancy dressed as diligence. The most common patterns: three-plus CSPM tools on the same environments (one native, one primary ISV, one legacy); separate cloud and on-prem SIEMs both ingesting the same cloud logs; container tools overlapping native scanning (ECR, Defender for Containers); identity governance duplicating native IAM audit; and compliance tools bought independently by each regulated unit for the same frameworks. Every purchase is justifiable alone; together they are the tax.
06 Third-party ISV rationalisation
The single largest reduction opportunity is not the native platform — it is the accumulated layer of third-party ISV products. A typical Fortune 500 security team runs 40–70 distinct tools across its cloud estate, many addressing the same capability areas with overlapping coverage.
Rationalisation starts with capability mapping: catalogue every tool, map it to its primary capability (CSPM, CWPP, SIEM, IAM governance, vulnerability management, compliance), and identify overlaps. In large portfolios, 30–40% of ISV spend duplicates native tools or other ISV tools. Presenting a consolidated selection — fewer vendors, higher volume, multi-year commitment — then delivers a further 20–30% unit-price reduction against the fragmented procurement it replaces.
The commercial levers are identical to any enterprise software negotiation: multi-year commitment for better pricing, volume consolidation across units, credible competitive alternatives, and timing to the vendor's quarter-end. For large relationships — Palo Alto Networks, CrowdStrike, Wiz, Lacework — the gap between list and negotiated price is typically 20–40% for buyers engaging professionally. For Microsoft-specific detail, see our Microsoft Security Licensing and Reducing Microsoft Spend guides.
07 Optimisation framework
Four levers drive the 30–50% reduction. Sequence them from the fastest structural wins to the negotiation that locks in the rest.
Native tool right-sizing
Audit GuardDuty log sources, Security Hub finding severity, Macie scan scope, and enabled Defender plans. Cut coverage on resources that do not justify it — typically half the native bill on default-on estates.
Identity licensing tiers
Resolve Entra ID P1 vs P2 vs E5-bundled decisions against actual feature usage, and stop deploying premium identity features estate-wide by default.
ISV portfolio rationalisation
Map every tool to a single capability owner, eliminate the 30–40% overlap, and consolidate spend into fewer preferred vendors for volume leverage.
Commercial negotiation discipline
Apply procurement rigour to what remains: multi-year commitments, benchmarking, competitive alternatives, and quarter-end timing — worth 20–40% against major ISVs.
08 Our recommendation
If most spend is GuardDuty, Security Hub or full Defender plans, the fastest win is coverage discipline — log filtering, finding suppression, selective plans. Negotiate custom native pricing for very large environments explicitly.
Standalone Defender for Cloud plans routinely re-license E5-bundled capability. A systematic audit recovers 20–35% of standalone Defender spend before any negotiation begins.
With 40–70 tools deployed, map capability ownership, eliminate overlap, then present consolidated volume to preferred vendors — 30–40% overlap plus 20–30% unit-price reduction compound.
Reduce your cloud security spend
Our Cloud & FinOps practice runs the full audit — native tools, identity licensing, ISV portfolio — and negotiates the commercial terms that correct the overpayment.
The Licensing Edge
Weekly cloud and licensing intelligence for enterprise IT leaders. 3,000+ subscribers.