The meter rather than the product drove the overspend, and sizing the gateway on total users instead of active ones inflated the count by 15 to 30 percent
Three pillars, three different meters. The tier conversation is loud and the counting conversation is where the money actually sits.
Prepared by Redress Compliance · August 19, 2026 · Cisco security renewals. 25 to 35 renewals benchmarked, 2024 to 2025.
Executive summary
The secure gateway was sized on total users rather than active users, inflating the count by 15 to 30 percent. Nothing about the product changed; the denominator did.
Access tiers were over specified. Buyers bought multi factor plus access where multi factor alone covered the stated requirement.
Monitored asset counts crept upward as inventory tools double counted endpoints and cloud instances. The asset count is the bill on that pillar.
Security now runs 25 to 45 percent of total Cisco subscription spend, and suite consolidation compressed the tier level leverage that used to sit in the SKU list.
Why does the meter matter more than the tier?
Because the portfolio shift from point products to suites compressed the tier level leverage. What is left sits inside the count and the bundle math.
Three shifts that moved the leverage
- Suite consolidation: three suites replaced fifteen plus standalone line items.
- Tier compression: each pillar reduced to three or four tiers.
- Agreement dominance: security increasingly transacts inside the enterprise agreement.
The line is now large enough to matter
Security spend runs 25 to 45 percent of total Cisco subscription spend in most enterprise accounts. It is no longer a rounding error attached to the networking conversation. The buying programs are described on the enterprise buying programs page.
How do the secure gateway tiers price?
Per user per year, split between DNS layer tiers and full secure internet gateway tiers. The tier ladder is steep and most estates start one rung too high.
| Tier | Scope | List per user per year | Best fit |
|---|---|---|---|
| DNS Essentials | DNS security, basic filtering | $24 | Smaller or branch coverage |
| DNS Advantage | DNS plus advanced filtering and intelligence | $36 | Mid market enterprise |
| SIG Essentials | DNS plus gateway plus cloud access plus firewall | $72 | Hybrid workforce |
| SIG Advantage | Full gateway plus data loss prevention and isolation | $120 | Regulated industries |
The gateway tier trap
Most enterprise buyers default to the first gateway tier on the account team recommendation. That tier carries about 70 percent more capability than most customers actually deploy in year one.
Stage the tier to the deployment
A staged approach starts one rung lower and moves up at the renewal, when the gateway and cloud access deployment is genuinely ready. The product scope sits on the Umbrella product page.
The Cisco enterprise agreement guide
How the agreement prices, where the security line sits inside it, and the buyer side moves before the commitment.
Get the brief →What 25 to 35 Cisco security renewals showed
Across roughly 25 to 35 Cisco security renewals benchmarked in 2024 and 2025, the meter, not the product, drove the overspend. Three patterns recur.
- The secure gateway was sized on total users rather than active users, inflating the count by 15 to 30 percent.
- Access tiers were over specified, with buyers purchasing multi factor plus access where multi factor alone covered the requirement.
- Monitored asset counts crept upward as inventory tools double counted endpoints and cloud instances.
Removing the count inflation was worth a median 22 percent before any tier or rate conversation started.
- Every risky clause flagged with the verbatim quote and page anchor
- Entitlements, caps and protections verified across your whole contract portfolio
- Paste ready replacement language and an evidence trail for the response
Which access tier does the requirement actually need?
Usually one below the one on the quote. The four tier ladder runs from a free tier for pilots to a full zero trust tier, and the middle is where most estates belong.
| Tier | Scope | List per user per year | Best fit |
|---|---|---|---|
| Free | Multi factor for up to ten users | $0 | Pilots and small teams |
| Essentials | Multi factor plus sign on plus device insight | $36 | Basic enterprise multi factor |
| Advantage | Essentials plus device trust plus risk based access | $72 | Hybrid workforce |
| Premier | Advantage plus remote access plus passwordless | $108 | Zero trust adoption |
Three asks that hold at the table
- Right size the tier, because most estates need the third rung rather than the fourth.
- Negotiate the bundle discount, since the three security pillars trade up together.
- Check for multi factor overlap, because the identity platform you already own may cover it.
The published ladder sits on the access pricing page, and the overlap question is the one most likely to remove a whole line rather than discount it.
Why does the monitored asset count drift?
Because the detection pillar bills on monitored assets rather than users, and the asset count includes endpoints, servers, network devices and cloud workloads.
| Tier | Scope | List per asset per year | Best fit |
|---|---|---|---|
| XDR Essentials | Detection and response across endpoint and network | $36 | Mid market operations |
| XDR Advantage | Essentials plus cloud and email telemetry | $60 | Full operations centre |
| XDR Premier | Advantage plus managed detection and response | $120 | Managed partnership |
Double counting is the default, not the exception
Inventory tools double count endpoints and cloud instances, so the number rises without anybody deploying anything. Reconciling the asset list is the single cheapest move on this pillar. The scope is set out on the detection product page.
Watch the briefing · 4:55Cisco Negotiations in 2026: How to Prepare, and the Tactics You Will FaceThe four tactics to expect, the consumption baseline, and spending capital on mechanics rather than headlines.
Where the common advice on Cisco security is wrong
The standard advice is to consolidate onto the suites and negotiate the headline discount hard. We disagree.
The discount applies to a count nobody checked
Across the renewals benchmarked, removing count inflation was worth a median 22 percent, and it came before any rate conversation. A better percentage on an inflated count is still an inflated bill.
The buyer side move is to reconcile active users, reconcile monitored assets, and match each tier to the deployed capability, then negotiate. Median renewal reduction across the file was 28 percent. The wider agreement mechanics sit in the enterprise agreement guide.
What the renewals measured, 2024 to 2025
Two cuts of the benchmark file, and the first produces the second.
From reconciling active users against total users and de duplicating the monitored asset list, before any rate discussion.
Across the benchmarked renewals, once the counts were corrected and the tiers matched to deployed capability.
The gap between the two is the part a discount contributed. The larger share came from counting.
Your first five moves
- Reconcile active users against the total user count, because sizing on the total inflated the gateway count by 15 to 30 percent.
- De duplicate the monitored asset list across inventory tools, since double counted endpoints and cloud instances drift the count upward on their own.
- Match each tier to the capability actually deployed, as the first gateway tier carries about 70 percent more than most estates use in year one.
- Check whether the identity platform you already own covers multi factor, which removes a line rather than discounting one.
- Only then negotiate the rate and the bundle. The Cisco practice and the spend health check run the count before the quote arrives.
Frequently asked questions
What actually drives Cisco security overspend?
The meter rather than the product. Sizing the secure gateway on total users instead of active users inflated the count by 15 to 30 percent on its own.
How large is the security line now?
Between 25 and 45 percent of total Cisco subscription spend in most enterprise accounts, which is why it no longer rides along with the networking conversation.
Why has tier leverage shrunk?
Suite consolidation replaced fifteen plus standalone items with three suites and compressed each pillar to three or four tiers, so the SKU list holds less room.
What is the gateway tier trap?
Defaulting to the first full gateway tier on the account team recommendation. It carries about 70 percent more capability than most customers deploy in year one.
Which access tier fits most estates?
The third rung rather than the fourth. Buyers routinely bought multi factor plus access where multi factor alone covered the stated requirement.
Can an existing identity platform cover it?
Often yes. Checking for multi factor overlap with the identity platform you already own is the one move that removes a line instead of discounting it.
Why does the asset count drift?
Because inventory tools double count endpoints and cloud instances. The number rises without anybody deploying anything new, and the asset count is the bill.
How much does correcting counts recover?
A median 22 percent across the benchmarked renewals, entirely before any rate conversation started.
What was the median renewal reduction?
28 percent. The gap between that and the 22 percent from counts is roughly what the rate negotiation itself contributed.
What order should the work run in?
Counts first, tiers second, rate last. A better percentage applied to an inflated count is still an inflated bill.