Research Note · Cloud · Security

Cloud security licensing: avoiding the compliance tax.

Cloud security has become the fastest-growing line item in enterprise cloud budgets — and the most poorly negotiated. Native add-ons, identity tiers, and a sprawl of third-party tools now rival compute costs. This note maps where the overpayment sits and how disciplined buyers reduce security spend 30–50% without cutting coverage.

By James Hill-WoodUpdated Dec 202213 min readCloud research cluster
Bottom line

There is no single "cheapest" way to secure a cloud estate — but there is a systematically overpriced one. For a $30M-cloud enterprise, security now routinely reaches $4–8M annually across native add-ons (Defender for Cloud, GuardDuty/Security Hub, SCC), identity tiers, and third-party tools. A structured audit typically recovers 30–50% of that spend without reducing protection — most of it from ISV overlap and default-on native coverage that no one revisits.

01 Key findings

  1. Cloud security is now a compute-scale cost, not a rounding error. Native platform services, identity licensing, and ISV tooling combine into a budget that rivals infrastructure spend for security-conscious enterprises.

  2. Default-on native coverage is the quiet leak. Enterprises enable every Defender plan or the full GuardDuty log set at deployment and never revisit it — paying for protection on resources that do not justify it, at up to double the necessary cost.

  3. Third-party ISV sprawl is the single largest opportunity. A typical Fortune 500 runs 40–70 security tools; 30–40% of ISV spend duplicates native capability or other ISV tools in the portfolio.

  4. Microsoft licensing is double-paid more often than not. Standalone Defender for Cloud plans routinely re-license capability already bundled in M365 E5 — an audit recovers 20–35% of that standalone spend.

  5. Security is bought by security teams, not procurement. Single-vendor purchases, auto-renewals at list, and no benchmarking leave 20–40% on the table against major ISVs that negotiate like any other enterprise software vendor.

02 The cost structure

Enterprise cloud security costs fall into four categories, each with different commercial dynamics and optimisation levers. Mapping spend to the category structure is the first step to finding savings. For broader commercial context, see our Cloud Contract Negotiation Guide.

Native platform services
Consumption-driven
What it is: GuardDuty, Security Hub, Defender for Cloud, Security Command Center — priced by resource, data or event volume.
Where it leaks
  • Tier thresholds create step-changes managed by architecture
  • Custom native pricing achievable but rarely negotiated
Identity & access
Tier-sensitive
What it is: IAM Identity Center, Entra ID (formerly Azure AD), GCP IAM — where premium-tier creep drives overruns.
Where it leaks
  • Entra ID P1 vs P2 vs E5-bundled rarely optimised
  • Premium features deployed estate-wide by default
Third-party ISV tools
Largest opportunity
What it is: CSPM, CWPP, CNAPP, SIEM — bought independently by security teams, often without commercial discipline.
Where it leaks
  • Portfolio duplication across overlapping capability areas
  • Fragmented procurement, no consolidated volume
Compliance & audit
Fastest-expanding
What it is: SOC 2, PCI DSS, HIPAA, ISO 27001 tooling — native plus specialised third-party platforms.
Where it leaks
  • Premium prices for tools overlapping native capability
  • Frameworks re-licensed per business unit

03 Security service pricing matrix

The native security services carry sharply different pricing models and enterprise cost bands. Each has a distinct optimisation lever that reduces spend without reducing visibility.

ServicePlatformPricing modelTypical enterprise costPrimary optimisation lever
GuardDutyAWSPer GB of logs analysed$500K–$2MExclude low-value log sources; filter before ingestion
Security HubAWSPer finding, per account$100K–$500KSeverity filtering & suppression rules
MacieAWSPer GB of S3 scannedHighly variableRisk-based selective scanning, not full-estate
Defender for CloudAzurePer resource, per plan$1M–$4MSelective plan coverage; de-duplicate E5 entitlements
Security Command Center PremiumGCPPercentage of GCP spendScales with spendNegotiate pricing cap or flat-rate arrangement
ChronicleGCPPer GB ingestedHighly variableCommitted-use terms inside the enterprise agreement

04 Cost at scale

Where does the $4–8M go? Illustrative annual security spend for a $30M-cloud enterprise, by category. Third-party ISV tooling — not the native platform — is consistently the largest slice and the deepest reduction opportunity.

Third-party ISV tools
~$2.4M
Native platform services
~$1.8M
Identity & access
~$1.2M
Compliance & audit
~$0.6M
Note

Native services scale with usage, but ISV spend accumulates through years of decentralised procurement — which is why the largest bar is also the softest. Model each category net of achievable consolidation before assuming any line is fixed.

05 The compliance-tax trap

The "compliance tax" is the premium enterprises pay when protection is bought without commercial discipline: coverage duplicated across layers, native capability re-purchased from ISVs, and frameworks licensed repeatedly across business units. It hides in plain sight because each individual purchase looks defensible on security grounds.

The trap

Redundancy dressed as diligence. The most common patterns: three-plus CSPM tools on the same environments (one native, one primary ISV, one legacy); separate cloud and on-prem SIEMs both ingesting the same cloud logs; container tools overlapping native scanning (ECR, Defender for Containers); identity governance duplicating native IAM audit; and compliance tools bought independently by each regulated unit for the same frameworks. Every purchase is justifiable alone; together they are the tax.

06 Third-party ISV rationalisation

The single largest reduction opportunity is not the native platform — it is the accumulated layer of third-party ISV products. A typical Fortune 500 security team runs 40–70 distinct tools across its cloud estate, many addressing the same capability areas with overlapping coverage.

Rationalisation starts with capability mapping: catalogue every tool, map it to its primary capability (CSPM, CWPP, SIEM, IAM governance, vulnerability management, compliance), and identify overlaps. In large portfolios, 30–40% of ISV spend duplicates native tools or other ISV tools. Presenting a consolidated selection — fewer vendors, higher volume, multi-year commitment — then delivers a further 20–30% unit-price reduction against the fragmented procurement it replaces.

The commercial levers are identical to any enterprise software negotiation: multi-year commitment for better pricing, volume consolidation across units, credible competitive alternatives, and timing to the vendor's quarter-end. For large relationships — Palo Alto Networks, CrowdStrike, Wiz, Lacework — the gap between list and negotiated price is typically 20–40% for buyers engaging professionally. For Microsoft-specific detail, see our Microsoft Security Licensing and Reducing Microsoft Spend guides.

07 Optimisation framework

Four levers drive the 30–50% reduction. Sequence them from the fastest structural wins to the negotiation that locks in the rest.

Lever 01

Native tool right-sizing

Audit GuardDuty log sources, Security Hub finding severity, Macie scan scope, and enabled Defender plans. Cut coverage on resources that do not justify it — typically half the native bill on default-on estates.

Lever 02

Identity licensing tiers

Resolve Entra ID P1 vs P2 vs E5-bundled decisions against actual feature usage, and stop deploying premium identity features estate-wide by default.

Lever 03

ISV portfolio rationalisation

Map every tool to a single capability owner, eliminate the 30–40% overlap, and consolidate spend into fewer preferred vendors for volume leverage.

Lever 04

Commercial negotiation discipline

Apply procurement rigour to what remains: multi-year commitments, benchmarking, competitive alternatives, and quarter-end timing — worth 20–40% against major ISVs.

08 Our recommendation

Native-heavy estates
Start with right-sizing

If most spend is GuardDuty, Security Hub or full Defender plans, the fastest win is coverage discipline — log filtering, finding suppression, selective plans. Negotiate custom native pricing for very large environments explicitly.

Microsoft-heavy estates
De-duplicate E5 first

Standalone Defender for Cloud plans routinely re-license E5-bundled capability. A systematic audit recovers 20–35% of standalone Defender spend before any negotiation begins.

ISV-sprawl estates
Rationalise, then negotiate

With 40–70 tools deployed, map capability ownership, eliminate overlap, then present consolidated volume to preferred vendors — 30–40% overlap plus 20–30% unit-price reduction compound.

Reduce your cloud security spend

Our Cloud & FinOps practice runs the full audit — native tools, identity licensing, ISV portfolio — and negotiates the commercial terms that correct the overpayment.

Request security cost review →

The Licensing Edge

Weekly cloud and licensing intelligence for enterprise IT leaders. 3,000+ subscribers.