The survey finds that 60% of cybersecurity professionals say vendors inundate them with unnecessary alerts to avoid liability for a breach, and 47% don't believe their tools work as expected
Vectra AI, Inc., a leader in artificial intelligence-based XDR (extended detection and response), today announced the results of the 2024 edition of the research “State of Threat Detection: The Defender’s Dilemma”. The survey finds that Security Operations Center (SOC) workers believe they are unable to identify and prioritize threats due to too many non-integrated tools and a lack of accurate attack signals. Furthermore, they highlight a growing distrust of vendors, believing that their solutions may be more of a hindrance than a help in detecting real attacks. This, however, contrasts with growing confidence in one's own abilities and an optimistic perception of the potential of artificial intelligence (AI).
In contrast, the hybrid attack landscape continues to intensify as organizations use GenAI-based tools to streamline processes and improve internal services. A trend that offers greater opportunities to attackers and poses new challenges for security professionals, already dealing with a growing number of alerts and false positives. While SOCs are more confident about their defenses than they were a year ago, many feel they lack the tools to effectively identify and act on real threats. Based on a survey of 2,000 cybersecurity professionals, the study analyzes why this discrepancy exists, how current threat detection solutions fall short, and the role AI plays in improving cybersecurity by providing targeted breach alerts and reducing workloads.
SOC confidence is improving, but too many legacy tools risk undermining it
Professionals have more confidence in their abilities, but feel they are losing ground when it comes to detecting and prioritizing real threats. In fact, many teams manage too many tools and are faced with an enormous number of alerts at the risk of losing sight of critical attacks. This is driving a loss of confidence in current tools, pushing SOCs to look for alternatives, such as extended detection and response (XDR) solutions. The study highlights that:
- Nearly three-quarters (71%) of SOC operators fear missing a real attack buried under the huge flow of alerts and 51% believe they cannot keep up with ongoing cyber threats;
- Nearly half (47%) don't believe their cybersecurity tools are working the way they need them to, while 54% say the tools they are using increase workloads rather than reduce them;
- 73% of SOCs use more than 10 tools and 45% more than 20 tools;
- 62% of teams have recently adopted or are evaluating extended detection and response (XDR) solutions.
Legacy threat detection tools are creating a lot of work for SOCs, resulting in growing distrust of vendors and dissatisfaction with their tools
SOC teams are increasingly frustrated with their current security tools, which cause more challenges than they solve. Many have to set aside central tasks to manage the sheer volume of alerts they receive. A situation that is contributing to increasing dissatisfaction with both the tools and the vendors who provide them. Additionally, SOCs also exhibit poor alert accuracy, as a significant number of alerts go unaddressed due to time constraints or insufficient software support. While there are indications of improvement in areas such as visibility in hybrid environments, the sheer volume of alerts remains a significant issue. The survey found that:
- 60% of SOCs say vendors offer threat detection tools that create too much noise and alerts, and 71% say vendors should take more responsibility if their solutions fail to stop a breach;
- 81% of SOCs spend more than 2 hours per day reviewing and evaluating security events;
- 50% believe that their security tools are more of an obstacle than a help when it comes to identifying real attacks, underlining that in practice they are only able to manage 38% of the alerts they receive and that they would classify only 16% of the alerts they receive as "real attacks";
- 60% say many of the security tools they use are purchased 'sight unseen' to ensure compliance.
The use of AI is growing, but suppliers must add real value
SOCs are increasingly adopting AI tools to improve threat detection and response, driven by growing expectations in the technology's capabilities. While many are optimistic about its potential to provide effective threat alerts to accurately identify and respond to cyber attacks, reduce workloads, and replace legacy tools, there are fears of additional complexity to an already overloaded operational workflow. Despite this, there is a strong intention to invest in AI-based solutions to improve the efficiency and effectiveness of cybersecurity. However, for AI to truly gain widespread acceptance, vendors must work to restore trust by providing tools that add real value without increasing the burden on SOC teams. The research found that:
- 85% of SOCs say the level of investment and use of AI has increased in the last year and 67% say it has had a positive impact on their ability to identify and resolve threats;
- 75% of teams highlight that in the last 12 months AI has reduced workloads and 73% that it has reduced the level of burnout;
- 89% plan to use more AI-based tools over the next year to replace current threat detection and response tools.
"It's promising to see that trust is growing among security professionals; however, it's clear that their current tools are creating growing frustration as, due to the lack of built-in attack alerts, they often create additional work rather than simplify processes. The data suggests that the solutions adopted for threat detection and response, along with the vendors that market them, are not holding up part of the bargain," commented Mark Wojtasiak, Vice President of Research and Strategy at Vectra AI. "In this scenario, SOC teams believe that AI will help them identify and prioritize breaches, speed up response times, and reduce over-alerts. However, vendors must work to make these expectations come true by continuing to demonstrate that AI-based offerings have a positive impact."






