Skip to content

Exabeam Expands Behavior Intelligence to Secure the Agentic Enterprise — Read the News

Key Findings of the Exabeam 2019 State of the SOC Report

  • Jun 06, 2019
  • Joy Ma
  • 2 minutes to read

Table of Contents

    How does your SOC stack up? If you are asking the question, now you can compare your company’s security operations center to peer responses in the Exabeam 2019 State of the SOC Report. It’s our second annual comprehensive survey of U.S. and U.K. cybersecurity professionals who manage and operate SOCs.

    Exabeam’s May 2019 survey included CISO, CIO, frontline security analyst, and management roles. We asked respondents like you about basic SOC operations, hiring and staffing, operational processes, technology, and finance and budget. Based on responses, the survey algorithmically determined if a SOC was highly effective (35%), effective (40%), and less effective (25%) in its approach to safeguarding enterprise security.

    Some key findings from our report include:

    Basic Operations

    CIOs and CISOs are more concerned about incident response, automation, and threat hunting while SOC analysts are more focused on procedure and policy, monitoring security tools, and investigations.

    86% of CIOs / CISOs are involved with incident response (up from 65% a year ago)

    67% of CIOs / CISOs are involved with threat hunting (up from 51% a year ago)

    48% of SOC analysts use automation (up from 28% a year ago)

    50% of SOC managers are involved with automation

    Almost half of SOCs continue to outsource business activities. Malware analysis, threat analysis, and threat intelligence are the most frequently outsourced functions. SOC analysts are strongly involved in incident response and automation.

    55% of malware analysis expertise is outsourced (up from 40% a year ago)

    45% outsource threat intelligence services (up from 28% a year ago)

    37% outsource event/data monitoring (down from 47% a year ago)

    Hiring and Staffing

    SOC staffing remains an issue for many organizations and is most prevalent among less effective SOCs (46%) compared to more effective SOCs (29%). Retention remains strong due to competitive benefits (44%) and the good or challenging nature of SOC work (42%).

    Notably, while hard skills remain critical, 65% of SOCs are placing increased emphasis on soft skills, particularly personal/social.

    Process

    Generally, SOC effectiveness is unchanged, but the perception of auto-remediation effectiveness has declined; 54% of SOCs were unable to perform auto-remediation (down from 68% a year ago).

    All groups agree that too much time is spent on reporting and documentation, while the problem of inexperienced staff is greater in the eyes of CISOs and CIOs than with SOC staff and SOC managers.

    Technology

    Big data analytics, endpoint detection/response, network/cloud monitoring, and identity/access management remain top technology priorities. Keeping up with security alerts remains the top pain point for SOCs.

    Finance and Budget

    Technology investment as compared to staffing, facilities and management remains the most underfunded part of the SOC, a sentiment felt more strongly by Americans.

    Learn More About Exabeam

    Learn about the Exabeam platform and expand your knowledge of information security with our collection of white papers, podcasts, webinars, and more.

    • Report

      Gartner® Insider Risk Management Cookbook: Perfecting the Soup

    • eBook

      Building a Behavior-Driven Insider Threat Program: A 10-Step Playbook

    • Blog

      Exabeam vs. Splunk: Which Approach Improves Security Operations Outcomes?

    • Blog

      Why Insider Risk Detection Requires Long-Term Memory

    • Blog

      Five Ways Exabeam Delivers Better Detection and Security Outcomes Than Microsoft Sentinel

    • Webinar

      Building a Modern Insider Threat Program: Catching Rogue Agents in Action

    • Show More