Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

SANS SOC survey results: what it means for response teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: The 2021 SANS Security Operations Center Survey results highlight how SOC teams are prioritising threat response, log analytics, and false-positive reduction, according to Anomali. The real issue is not visibility alone, but whether detection and response workflows can be operationalised fast enough to reduce analyst overload and improve control execution.

NHIMG editorial — based on content published by Anomali: 2021 SANS Security Operations Center Survey Results

By the numbers:

Questions worth separating out

Q: How should security teams turn threat intelligence into operational action?

A: They should map each intelligence type to a specific workflow such as detection, hunting, blocking, ticketing, or escalation.

Q: Why do false positives create such a large SOC risk?

A: False positives erode trust in the alert pipeline, which leads analysts to discount both bad and good signals.

Q: What breaks when identity events are not part of SOC detection strategy?

A: Without identity events in the detection strategy, the SOC misses early signs of compromise such as unusual privilege use, service-account abuse, or access anomalies.

Practitioner guidance

  • Map detections to response actions Tie high-value alert types to specific containment steps, escalation owners, and suppression criteria so analysts know what action follows each signal.
  • Reduce false positives at the source Review the noisiest log sources, tune correlation rules, and suppress repeated benign patterns before expanding telemetry coverage.
  • Operationalise threat intelligence into controls Establish a workflow that moves indicators into detections, blocklists, and investigation logic with clear expiry and ownership.

What's in the full report

Anomali's full white paper covers the operational detail this post intentionally leaves for the source:

  • Survey response patterns from SOC practitioners and how they prioritise detection and response work.
  • Operational examples of threat-informed response acceleration and intelligence-to-control execution.
  • Specific approaches to log source analytics and false-positive suppression in SOC workflows.

👉 Read Anomali's SANS Security Operations Center Survey Results →

SANS SOC survey results: what it means for response teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Detection quality is a governance problem, not just an engineering problem. A SOC can ingest large amounts of telemetry and still fail if the operating model cannot distinguish useful signals from noise. That creates analyst fatigue, inconsistent triage, and slow containment. The practical conclusion is that detection engineering and governance need to be managed together.

A question worth separating out:

Q: How do you know if threat-informed response is actually working?

A: You know it is working when detections consistently lead to the right containment action, false positives decline, and intelligence updates are deployed quickly enough to affect ongoing attacks. If the SOC produces more alerts but no faster decisions, the model is not functioning as intended.

👉 Read our full editorial: SANS SOC survey results frame the gap in operational response



   
ReplyQuote
Share: