The Cost of Security: Measuring the Operational Impact of Endpoint and SIEM Visibility

We measure what security tools detect. We measure much less often what they cost while doing it. We will focus on security controls and monitoring mechanisms for Linux endpoints and show how these controls behave under realistic production-like workloads. We will also examine how adversary simulation frameworks can help us evaluate not only whether a control produces a useful security signal, but also what that signal costs to collect, process, store, and investigate. The session approaches cost from multiple angles: endpoint resource consumption, telemetry volume, SIEM pipeline pressure, detection value, compliance expectations, and operational maintainability. We will also look at how hardening guidance and benchmark recommendations can become challenging in real environments when workload, logging, performance, and response capacity are considered together. Rather than presenting security monitoring as a simple “enable more visibility” problem, this talk centers on one practical question: does the value of a security control justify the operational cost it creates? We will share results from our own testing, compare different configurations, and use those results as a basis for discussion with the audience. The goal is to help security engineers, platform teams, detection engineers, and SOC teams evaluate security effectiveness and operational sustainability together. A useful control is not just one that detects. It is one whose cost we understand and can sustain.

    Speaker

    FURTHER SESSIONS

  • 1979 called. They already figured it out.

  • A Few Dollars to Disappear: Breaking C2 Beaconing Detection

  • Ants, Bricks and Spiders: Threat Emulation on the VMware Stack

  • Capture The Flag

  • Join us in Amsterdam!

    November 19, 2026

    Hang out, learn something awesome and make new friends.

    Get Tickets