×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Vectra AI
  • Research by Vectra AI reveals a significant disconnect between security operations teams and the effectiveness of threat detection tools in preventing cyberattacks

Customer Press Room

Research by Vectra AI reveals a significant disconnect between security operations teams and the effectiveness of threat detection tools in preventing cyberattacks

by Grandangolo Communications / Wednesday, 19 July 2023 / Published in Vectra AI

90% of SOC analysts believe current threat detection tools are effective, although 97% fear missing a relevant security event

Vectra AI, a pioneer in AI-driven cyber threat detection and remediation for hybrid and multicloud enterprises, today announced the results of its 2023 State of Threat Detection Research Report, which provides insights into the so-called “spiral of more” – more attacks, more alerts, more work – that prevents Security Operation Center (SOC) teams from effectively protecting their organizations from cyber attacks.

Today, security operations teams (SecOps) are tasked with protecting organizations from increasingly sophisticated and fast cyber attacks. However, the complexity of the mix of people, processes and technology at their disposal is making it increasingly difficult to mount an effective cyber defense. The ever-expanding attack surface, combined with evolving attack methods and increasing workload for SOC analysts, results in a vicious spiral of “more” that prevents security teams from effectively protecting their organization. Based on a survey of 2,000 SecOps analysts, the report explains why the current approach to security operations is no longer sustainable.

The “spiral of more” threatens the ability of security teams to defend the organization

Manually triaging security alerts costs organizations $3.3 billion per year in the United States alone. Security analysts have the daunting task of detecting, investigating and responding to threats as quickly and efficiently as possible, while being challenged by an expanding attack surface and thousands of daily security alerts. The study found that:

  • according to 63% of analysts the size of the attack surface has increased in the last three years;
  • on average, SOC teams receive 4,484 alerts per day and spend nearly three hours of their day manually managing alerts;
  • Security analysts are unable to handle 67% of alerts received each day, with 83% believing the alerts are false positives and not worth their time.

SOC analysts don't have the tools to do their jobs effectively

While the majority of SOC analysts say their tools are effective, the combination of blind spots and the high volume of false positive alerts prevents companies and their SOC teams from successfully containing cyber risk. Without visibility into their entire IT infrastructure, organizations are unable to identify even the most common signs of an attack, such as lateral movement, privilege escalation and cloud attack hijacking. The study also found that:

  • 97% of SOC analysts fear missing a relevant security event because it is "buried" by a flood of alerts, yet the vast majority believe that their tools are effective overall;
  • 41% believe that alert overload is the norm, because vendors are afraid of not reporting an event that could prove important;
  • 38% say security tools are purchased to meet compliance requirements, and 47% would like IT team members to consult them before investing in new products.

Analyst burnout poses a significant risk to the security industry

Despite the growing adoption of AI and automation tools, the security industry still needs a significant number of workers to interpret data, initiate investigations and take corrective action based on the information received. Faced with the overload of alerts and the execution of repetitive tasks, two-thirds of security analysts are considering or have already decided to leave their jobs, a figure that will have a potentially devastating impact on the sector in the long term. The study further found that:

  • despite 74% of those interviewed declaring that their job corresponds to their expectations, 67% are thinking of leaving or are already leaving their job;
  • 34% of analysts who are thinking of leaving their role or are already leaving it say they do not have the necessary tools to guarantee the security of their organization;
  • 55% of analysts say they are so busy that they feel like they are doing the work of multiple people, and 52% believe that working in the security industry is not a viable long-term career option.

“As businesses move to hybrid and multi-cloud environments, security teams are continually faced with more: more attack surface area, more attack methods that evade defenses, more alert noise, more complexity, and more hybrid attacks,” he explains Kevin Kennedy, Senior Vice President of Products di Vectra AI. "The current approach to threat detection is no longer valid, and our report findings demonstrate that the glut of disparate, isolated tools has created too much background noise in detection for SOC analysts to successfully manage, and instead has created an ideal environment for attackers to enter. As an industry, we cannot continue to fuel this spiral: it's time to hold security vendors accountable for the effectiveness of their signal. The more effective the threat signal, the more resilient and effective the SOC becomes IT".

Click who to download the full report.

Tagged under: State of Threat Detection Research Report 2023, Vectra AI

About Grandangolo Communications

What you can read next

Vectra AI strengthens the executive team with the entry of strategic consultant Myrna Soto
Vectra AI Named Among Leaders and Outperformers for NDR in GigaOm Radar Report
Vectra AI announces the addition of Myrna Soto and David Reilly to the board of directors

Customer Press Room

  • Acronis Introduces MDR by Acronis TRU to Offer MSPs 24/7 Threat Detection and Response

    The service allows MSPs to offer customers...
  • SentinelOne expands strategic partnership with Google Cloud to deliver AI-powered autonomous security on a global scale

    The partnership will lead to the development of new...
  • Vertiv Announces Expansion of Manufacturing Capacity in Infrastructure Solutions, Energy and Rack Systems to Meet Growing Demand

    New and expanded production facilities in America...
  • Eon and SentinelOne partner to improve cloud data security and AI resilience

    The combination of features will broaden the ...
  • Vertiv expands thermal portfolio with new wall cooling system for edge and small data rooms in EMEA

    Designed to operate 24/7 in busy environments...

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP