How One HR Giant Cut Its Security Bill by $250,000 — by Deleting Data It Never Needed
Vensure Employer Solutions was drowning in its own security logs. AI-assisted filtering cut costs, halved response times, and proved that collecting less can mean detecting more.

Key points
- Vensure Employer Solutions, an HR and payroll provider serving more than 95,000 businesses, watched its security-log ingestion costs nearly triple over two years.
- AI-assisted filtering cut firewall log volume by 83% without losing a single meaningful security alert.
- The changes saved approximately $250,000 per year in storage and processing costs.
- Analyst response times dropped by roughly 50% once the noise was removed.
Vensure Employer Solutions handles payroll and HR administration for more than 95,000 businesses: wages, tax records, personal details for millions of workers. So when Dwayne Smith, the company's SVP of Information Security and Global CISO, says his biggest headache wasn't hackers, it's worth a moment.
It was his own security system eating itself alive.
The log pile that broke the budget
Every serious security operation runs a SIEM, a Security Information and Event Management system, which is essentially a giant digital inbox collecting records of everything happening across a company's computers and networks. For years, the logic was simple: record more, spot more.
Storage was cheap, so teams logged everything. A firewall, the boundary wall between a company's internal systems and the open internet, approved a routine connection? Logged. A server confirmed it was still online? Logged. Benign background noise? All of it, pouring in.
As Vensure grew through acquisitions and absorbed outside infrastructure, the data volume didn't creep. It detonated. Smith estimates ingestion costs nearly tripled in two years.
"We were ingesting everything," he told Dark Reading. "People would shove everything they could in there."
Did throwing away data make Vensure less secure?
No, and that's the counterintuitive finding at the heart of this story.
Smith's team didn't blindly delete records. They applied machine learning and large language models inside the security data pipeline to sort incoming data before it hit permanent storage. The system learned to flag high-volume, low-value events: a firewall waving through a routine connection, a server heartbeat. Those got dropped. Threat alerts, authentication records, anything flagged as unusual got kept.
Firewall logs were the first test case. Raw connection records made up the majority of events but were almost never used in real investigations. After filtering, firewall log ingestion fell by 83%. No threat alerts were lost. The team ran comparisons against historical data and simulated attack traffic, and used AI models aligned to the MITRE ATT&CK framework to confirm the filtered data was still interpreted through the right threat context.
The result: cleaner dashboards. Analysts who'd spent hours wading through meaningless entries could suddenly see scanning activity and genuine anomalies. Our 1 July piece on detection engineering maturity made a similar point about signal quality: better rules, not more data, is what actually moves the needle.
"When we filtered those logs, we were actually able to understand our environment better," Smith says.
What changed in practice
The financial hit was direct: roughly $250,000 saved annually. Mean time to respond fell by around 50%. Administrator behavior became easier to track, tightening identity and access monitoring. Compliance reporting, tracking which data is stored where, a real obligation for payroll companies operating across multiple regions, got simpler.
Much of the industry conversation about AI in security chases autonomous response and agentic workflows. Smith's view is that cost discipline may be the most underappreciated near-term benefit. Collecting less, deliberately, is itself a security decision.
The failure mode the industry keeps repeating is treating data volume as a proxy for security maturity. A warehouse full of irrelevant records doesn't catch threats; it buries the signal that would. Smith's operational lesson is blunt: question every log source before you ingest it, not after three years of storage bills prove it was useless.
Should you worry?
If your SIEM bill has grown faster than your headcount, probably yes. The same pressure Vensure felt is hitting any org that scaled through acquisition, and the fix isn't more storage budget.



