Cybersecurity teams are wasting time, money, and effort dealing with tool sprawl and ‘multi-vendor ecosystems’
Tool sprawl is a problem that just won't go away for security teams
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Cybersecurity practitioners are growing increasingly overwhelmed managing tools from multiple vendors, according to new research from Kaspersky.
A recent study from the security firm found nearly three-quarters (74%) of companies in the UK rely on “multi-vendor ecosystems” – a trend which is putting them at increased risk and burning out staff.
Indeed, over one-third (36%) of UK cyber workers said their security stacks are “overly complex and time-consuming” to maintain, which in turn is hampering their ability to respond to emerging threats.
Maintaining disparate tools has a knock-on effect across the cybersecurity segment at most businesses, the study noted. Compatibility issues were highlighted as a key challenge, for example, with 43% of respondents indicating they cannot keep a handle on security processes because of a lack of cross-platform integration.
This, the study warned, often leads to manual interventions and increases the chances of human error or blind spots, leaving the business open to breaches.
Similarly, 36% said they struggle with “inconsistent threat visibility” due to the growing array of tools and solutions. As data is collected from various vendors, Kaspersky noted this also creates blind spots and reduces “overall situational awareness”
Ilya Markelov, head of unified platform product line at Kaspersky, said enterprises often rely on multiple vendors “by default, rather than through deliberate strategic planning”.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“While diversification of security solutions can offer certain benefits, such as risk mitigation and coverage breadth, an unchecked increase in complexity often leads to significant resource drain and operational inefficiencies,” Markelov said.
“Moreover, this complexity can create critical blind spots, making it harder to maintain comprehensive threat visibility and respond effectively to emerging risks.”
Tool sprawl is still plaguing cybersecurity teams
The study from Kaspersky is the latest in a string of warnings over tool sprawl in recent years. It’s not just an issue restricted to cybersecurity teams, however, with workers in other professions, such as software development, contending with the problem.
Analysis from Red Canary in October 2024 showed tool sprawl was a key challenge facing software development teams. The study came just weeks after separate research from IDC which examined the mental strain placed on teams as a result of tool sprawl, known as ‘context switching’.
Context switching refers to the process of moving from one environment or solutions stack to another in an employee’s daily workflow. Over two-thirds (70%) of respondents told IDC that switching between different tools reduced their efficiency.
Speaking at the time, Katie Norton, research manager for DevSecOps and software supply chain security at IDC, said context switching not only wastes an employee’s time, but also inflates costs.
Costs were another key issue highlighted by Kaspersky in its recent report, with the security firm warning 36% of UK businesses experience “budget overruns” due to overlapping solutions.
“These redundancies not only inflate costs but also complicate resource allocation and strategic planning,” the company said.
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Anthropic researchers warn AI could 'inhibit skills formation' for developersNews A research paper from Anthropic suggests we need to be careful deploying AI to avoid losing critical skills
-
CultureAI’s new partner program targets AI governance gains for resellersNews The new partner framework aims to help resellers turn AI governance gaps into scalable services revenue
-
Notepad++ hackers remained undetected and pushed malicious updates for six months – here’s who’s responsible, how they did it, and how to check if you’ve been affectedNews Hackers remained undetected for months and distributed malicious updates to Notepad++ users after breaching the text editor software – here's how to check if you've been affected.
-
CISA’s interim chief uploaded sensitive documents to a public version of ChatGPT – security experts explain why you should never do thatNews The incident at CISA raises yet more concerns about the rise of ‘shadow AI’ and data protection risks
-
Former Google engineer convicted of economic espionage after stealing thousands of secret AI, supercomputing documentsNews Linwei Ding told Chinese investors he could build a world-class supercomputer
-
90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move onNews Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos
-
LastPass issues alert as customers targeted in new phishing campaignNews LastPass has urged customers to be on the alert for phishing emails amidst an ongoing scam campaign that encourages users to backup vaults.
-
NCSC names and shames pro-Russia hacktivist group amid escalating DDoS attacks on UK public servicesNews Russia-linked hacktivists are increasingly trying to cause chaos for UK organizations
-
An AWS CodeBuild vulnerability could’ve caused supply chain chaos – luckily a fix was applied before disaster struckNews A single misconfiguration could have allowed attackers to inject malicious code to launch a platform-wide compromise
-
There’s a dangerous new ransomware variant on the block – and cyber experts warn it’s flying under the radarNews The new DeadLock ransomware family is taking off in the wild, researchers warn