Train From Home on Your Schedule with OnDemand - Special Offers Available Now


Subscribe to SANS Newsletters

Join the SANS Community to receive the latest curated cyber security news, vulnerabilities and mitigations, training opportunities, and our webcast schedule.

Survey Results In! Analytics and Intelligence Being Used But Not Effectively

Learn Full Results in Two Webcasts being Held on Oct. 1 and Oct. 3 at 1 PM EDT

  • Bethesda, MD
  • September 26, 2013

SANS announces the results of it's first-ever survey on awareness and use of analytics and intelligence to augment current monitoring practices. In it, only 10% of respondents felt confident in their organization's ability to analyze large data sets for security trends, although 77% are collecting logs and monitoring data from various systems and security devices.

"Respondents are trying to add intelligence and improve analytics of the security data they're collecting, but they're struggling in various ways," says Deb Radcliff, executive editor of the SANS Analyst Program. "The primary issue is they're not able to make the associations to detect security events among their event and log data."

The survey had 647 respondents and was cosponsored by Guidance Software, Hewlett-Packard, Hexis Cyber Solutions, LogRhythym and SolarWinds. This survey is a follow-up to the SANS Eighth Annual Log Management Survey, which revealed that organizations were falling behind in their ability to detect security threats because they were -- quite literally -- gathering too much information to sift through.

This new survey on analytics and intelligence indicates that most organizations are still relying heavily on their Log Management (49%) or SIEM Platforms (47%), while only 17% are making use of advanced threat intelligence and profiling databases.

"While most security operations teams are still relying on traditional SIEM and log management, there are new challenges facing many organizations that these products may not address," says senior SANS Analyst Dave Shackleford, who authored the report. "More scalable and flexible analytics platforms are gaining interest and attention from the security community, and will likely continue to do so; given the threats and attacks we face today."

Join our two-part webcasts on Oct. 1 and Oct. 3 at 1 PM EDT to learn the full set of results. Those who register for these complimentary webcasts will be given an advanced link to the associated report developed by Dave Shackleford.

Please visit webcast links, to register and attend:
Part one on Oct. 1:
Part two on Oct. 3:

SANS Media Contact

About SANS Institute

The SANS Institute was established in 1989 as a cooperative research and education organization. Today, SANS is the most trusted and, by far, the largest provider of cyber security training and certification to professionals in government and commercial institutions worldwide. Renowned SANS instructors teach more than 60 courses at In-Person and Live Online cyber security training events, and more than 50 courses are available anytime, anywhere with our OnDemand platform. GIAC, an affiliate of the SANS Institute, validates practitioner skills through more than 35 hands-on, technical certifications in cyber security. The SANS Technology Institute, a regionally accredited independent subsidiary, offers a master’s degree, graduate certificates, and an undergraduate certificate in cyber security. SANS Security Awareness, a division of SANS, provides organizations with a complete and comprehensive security awareness solution, enabling them to easily and effectively manage their ‘human’ cybersecurity risk. SANS also delivers a wide variety of free resources to the InfoSec community including consensus projects, research reports, webcasts, podcasts, and newsletters; it also operates the Internet's early warning system – the Internet Storm Center. At the heart of SANS are the many security practitioners, representing varied global organizations from corporations to universities, working together to support and educate the global information security community. (