{"id":30930,"date":"2023-08-04T08:56:49","date_gmt":"2023-08-04T07:56:49","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=30930"},"modified":"2023-08-16T10:54:08","modified_gmt":"2023-08-16T09:54:08","slug":"research-reveals-significant-disconnect-between-security-operations-teams-and-the-effectiveness-of-threat-detection","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2023\/08\/04\/research-reveals-significant-disconnect-between-security-operations-teams-and-the-effectiveness-of-threat-detection\/","title":{"rendered":"Research reveals \u2018significant disconnect\u2019 between security operations teams and the effectiveness of threat detection"},"content":{"rendered":"\n<p><strong><em>Ninety percent of SOC analysts believe their current cyberthreat detection tools are effective &#8211; despite 97% reporting they fear of missing a relevant security event.<\/em><\/strong><\/p>\n\n\n\n<p>Vectra AI, a pioneer of AI-driven cyberthreat detection and response for hybrid and multi-cloud enterprises, has released the findings of its <em>2023 State of Threat Detection Research Report<\/em>, providing insight into the \u2018spiral of more\u2019 that is preventing security operations center (SOC) teams from effectively securing their organizations from cyberattacks.<\/p>\n\n\n\n<p>Today\u2019s security operations (SecOps) teams are tasked with protecting progressively sophisticated, fast-paced cyberattacks. Yet, the complexity of people, processes and technology at their disposal is making cyber defense increasingly unsustainable.<\/p>\n\n\n\n<p>The ever-expanding attack surface combined with evolving attacker methods and increasing SOC analyst workload results in a vicious spiral of more that is preventing security teams from effectively securing their organization.<\/p>\n\n\n\n<p>Based on a survey of 2,000 SecOps analysts, the report breaks down why the current approach to security operations is not sustainable.<\/p>\n\n\n\n<p><strong>Spiral of more threatens security teams\u2019 ability to defend their organization<\/strong><\/p>\n\n\n\n<p>Manual alert triage costs organizations $3.3 billion annually in the US alone, and security analysts are tasked with the massive undertaking of detecting, investigating and responding to threats as quickly and efficiently as possible while being challenged by an expanding attack surface and thousands of daily security alerts.<\/p>\n\n\n\n<p>The study found:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>63% report the size of their attack surface has increased in the past three years.<\/li>\n\n\n\n<li>On average, SOC teams receive 4,484 alerts daily and spend nearly three hours a day manually triaging alerts.<\/li>\n\n\n\n<li>Security analysts are unable to deal with 67% of the daily alerts received, with 83% reporting that alerts are false positives and not worth their time.<\/li>\n<\/ul>\n\n\n\n<p><strong>SOC analysts don\u2019t have the tools to do their jobs effectively<\/strong><\/p>\n\n\n\n<p>Despite a majority of SOC analysts reporting their tools are effective, the combination of blind spots and a high volume of false positive alerts are preventing enterprises and their SOC teams from successfully containing cyber-risk. Without visibility across the entire IT infrastructure, organizations are not able to identify even the most common signs of an attack, including lateral movement, privilege escalation and cloud attack hijacking.<\/p>\n\n\n\n<p>The study also found:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>97% of SOC analysts worry about missing a relevant security event because it\u2019s buried under a flood of alerts, yet, the vast majority deem their tools effective overall.<\/li>\n\n\n\n<li>41% believe alert overload is the norm because vendors are afraid of not flagging an event that could turn out to be important.<\/li>\n\n\n\n<li>38% claim that security tools are purchased as a box-ticking exercise to meet compliance requirements and 47% wish IT team members consulted them before investing in new products.<\/li>\n<\/ul>\n\n\n\n<p><strong>Analyst burnout poses significant risk to security industry<\/strong><\/p>\n\n\n\n<p>Despite the increasing adoption of AI and automation tools, the security industry still requires a significant number of workers to interpret data, launch investigations and take remedial action based on the intelligence they are fed. Faced with alert overload and repetitive, mundane tasks two-thirds of security analysts report they are considering or actively leaving their jobs, a statistic that poses a potentially devastating long-term impact to the industry.<\/p>\n\n\n\n<p>The study found:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Despite 74% of respondents claiming their job matches expectations, 67% are considering leaving or are actively leaving their job.<\/li>\n\n\n\n<li>Of the analysts considering leaving or actively leaving their role, 34% claim they don\u2019t have the necessary tools to secure their organization.<\/li>\n\n\n\n<li>55% of analysts claim they\u2019re so busy that they feel like they\u2019re doing the work of multiple people and 52% believe working in the security sector is not a viable long-term career option.<\/li>\n<\/ul>\n\n\n\n<p>David Sajoto, Vice President, Vectra AI, Asia Pacific and Japan, said: \u201cThese findings prove that a vicious \u201cspiral of more\u201d is overwhelming SOC teams across APAC. Hackers will always be looking for new ways to outwit defenders. Organizations must, therefore, focus on the things they can control, which goes beyond the ever-expanding corporate cyberattack surface or booming threat landscape. This means controlling the signal and burnout challenges that SOC analysts are currently facing. Effective security in the SOC doesn\u2019t mean detecting possible threat events but detecting and prioritizing real attacks with accuracy. The time is now for organizations to demand signal clarity from their security vendors.\u201d<\/p>\n\n\n\n<p>\u201cAs enterprises shift to hybrid and multi-cloud environments, security teams are continually faced with more &#8211; more attack surface, more attacker methods that evade defenses, more noise, more complexity and more hybrid attacks,\u201d said Kevin Kennedy, senior Vice President of products Vectra AI.<\/p>\n\n\n\n<p>\u201cThe current approach to threat detection is broken and the findings of this report prove that the surplus of disparate, siloed tools has created too much detection noise for SOC analysts to successfully manage and instead fosters a noisy environment that\u2019s ideal for attackers to invade. As an industry, we cannot continue to feed the spiral and it\u2019s time to hold security vendors accountable for the efficacy of their signal. The more effective the threat signal, the more cyber resilient and effective the SOC becomes.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ninety percent of SOC analysts believe their current cyberthreat detection tools are effective &#8211; despite 97% reporting they fear of missing a relevant security event. Vectra AI, a pioneer of AI-driven cyberthreat detection and response for hybrid and multi-cloud enterprises, has released the findings of its 2023 State of Threat Detection Research Report, providing insight [&hellip;]<\/p>\n","protected":false},"author":58,"featured_media":30934,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[11,3488,512,37,1030,43,514],"tags":[226,4742,483,606,553,292,1500,1009,4743],"class_list":["post-30930","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud","category-cybersecurity","category-main-story-newsletter","category-research","category-tech","category-top-stories","category-used","tag-ai","tag-ai-driven","tag-cyberattacks","tag-cyberthreat","tag-multi-cloud","tag-security-2","tag-soc","tag-threat-detection","tag-vectra-ai"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/30930","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/58"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=30930"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/30930\/revisions"}],"predecessor-version":[{"id":31109,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/30930\/revisions\/31109"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/30934"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=30930"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=30930"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=30930"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}