cyber-security – Osterman Research https://ostermanresearch.com Insightful research that impacts organizations Mon, 10 Mar 2025 04:02:31 +0000 en-US hourly 1 https://i0.wp.com/ostermanresearch.com/wp-content/uploads/2021/01/cropped-or-site-icon.png?fit=32%2C32&ssl=1 cyber-security – Osterman Research https://ostermanresearch.com 32 32 187703764 Making the SOC More Efficient https://ostermanresearch.com/2024/10/09/making-the-soc-more-efficient/ https://ostermanresearch.com/2024/10/09/making-the-soc-more-efficient/#respond Tue, 08 Oct 2024 18:29:33 +0000 https://ostermanresearch.com/2024/10/09/making-the-soc-more-efficient/ Setting the research agenda at Osterman Research is a never-ending process of looking at possibilities, gathering early intel on the importance of each topic, and filtering a larger list to focus on the critical topics that can move-the-needle for cybersecurity at organizations. Many projects that end up on our agenda come about naturally from our ongoing wider research programs. Some, however, are suggested to us.

Our latest research agenda program fits in the latter category. When we were looking at possibilities for 2024, a client suggested:

Something around how the security industry is evolving to make the SOC more efficient and reduce stress and burnout would be good. For example, the H/M/L prioritization of alerts didn’t really do much. What are vendors doing that works, and what doesn’t work? (There could be a little AI in here, but it would be good to go beyond that.)

That nudge (thanks, Bob!) became the origin point for our latest report, Making the SOC More Efficient (available on the main Osterman Research site). It’s a long paper (26 pages) that attempts to deal thoughtfully and in-depth with the topic, exploring the data points we captured through the survey and advocating a way forward. There is more than “a little AI” in the report, though, as this has become both the greatest threat (82.4% of security leaders said that “the use of AI by cyberthreat actors in cyberattacks” was “very impactful” or “extremely impactful” – the highest-rated trend in this research) and one of the greatest tools for defenders (via the rise of AI-enabled cybersecurity solutions).

Some of the key takeaways from the research:

  • Current SOC approaches have hit the wall
    Confidence in the ability of the SOC to protect against the threats detected by their security tools has dramatically increased during the past two years, but this increase in confidence is expected to rapidly crater. The innovations that drove increased SOC performance over the past two years do not contain the necessary ingredients to continue driving performance over the next two.
  • Specialized threat intelligence to eliminate false positives, AI for behavioral analysis, and autonomous remediation seen as top innovations
    The three innovations seen as most likely to drive SOC efficiency and reduce stress and burnout among SOC analysts are the use of specialized threat intelligence to eliminate false positives; using AI for behavioral analysis in investigating alerts and autonomously creating or updating detection rules; and autonomously remediating incidents without SOC analyst intervention. Almost half of respondents gave two AI-powered defensive innovations the highest rating.
  • New innovations improve SOC metrics by a composite average of 35%
    All organizations in this research are already experimenting with at least one new approach to improving the efficiency of their SOC. The most impactful innovations on key SOC metrics (time to begin working on an issue, time to close an incident, and number of false positives) are AI behavior analysis with autonomous rule creation/updating, AI behavioral modeling for detecting baseline deviations, and autonomous remediation of incidents.

If SOC efficiency is in your wheelhouse, we’d love you to get a copy.

This program was sponsored by Dropzone AIHYAS InfosecRadiant Security, and Sevco Security.

]]>
https://ostermanresearch.com/2024/10/09/making-the-soc-more-efficient/feed/ 0 4629
Cybersecurity Perspectives 2024: Enterprises Race to Defend Against Accelerated Pace of Emerging Threats https://ostermanresearch.com/2024/05/24/scalevp-perspectives-2024/ https://ostermanresearch.com/2024/05/24/scalevp-perspectives-2024/#respond Thu, 23 May 2024 22:38:29 +0000 https://ostermanresearch.com/2024/05/24/scalevp-perspectives-2024/ Osterman Research announces the publication of a new white paper – Cybersecurity Perspectives 2024: Enterprises Race to Defend Against Accelerated Pace of Emerging Threats. This white paper was commissioned by Scale Venture Partners. 

This is the eleventh year that Scale has produced this research (in collaboration with Everclear Marketing, we’ve helped over the past three years). The survey and report look at evolving threats and solutions, investment priorities for cybersecurity technologies and strategies (make sure you see the top 10 chart for this year and the changes from last year), and funding and buying patterns. The data is from senior-level decision-makers at organizations with 500 or more employees. AI has an increasing focus in this year’s research – as you would expect. 

Key findings:

  • Data breaches increased, led by phishing and third-party attacks.
  • CISOs prioritised cloud infrastructure and data center security.
  • Attackers targeted AI models while security played catch up.
  • Security budget growth showed signs of slowing.
  • Market gaps found in software supply chain security and ADX. 

For details on how to get yourself a copy, please check out our portfolio

]]>
https://ostermanresearch.com/2024/05/24/scalevp-perspectives-2024/feed/ 0 4603