Comment simple things can be done... (Score 2, Informative) 63
I have seen a lot of places that insist on buying a "solution" to the problem, when in fact the solution barely touches the problem. it works around a lot of things, but never really hits right on it. So you've spent a lot of money on something that doesn't really do the job of a person in that role.
The funny part about security is that for all it's sex appeal, real security is actually pretty boring. Oh the hotness of configuration management using tools that are already available on the windows or linux box. How your endorphins get moving at the sight of a patched on patch day. Or the sheer porn of being able to look at your log files and know that all is good.
We all love honeypots and whatnot, but those things need to come well after patching, configuration management, removing/pruning user administrative permissions, and controlling which software you allow, and strong authentication enforcement. This doesn't have to cost a lot of money.