Group Purchasing
Group Purchasing

Unseen Threats Have Security Teams Rethinking Detection

The SANS 2025 Detection and Response Report found that endpoint detection and response tools remain the most trusted defense, with 89% rated effective or extremely effective. Automation now touches nearly every SOC, yet false positives and skill gaps continue to slow teams down, even as organizations plan to expand AI and machine learning adoption in 2026.

Top Takeaways

73%

cite false positives as their top detection challenge

90%

of organizations rely on automated tools for detection

76%

plan to expand AI and ML use in detection and response

28%

describe their detection and response budget as insufficient

Survey Methodology and Respondent Profile

The analysis draws on responses from security practitioners across banking and finance, technology, cybersecurity, government, healthcare, and other sectors. Respondents are globally distributed across the United States, Europe, Latin America, and Asia, with security administrators, SOC analysts, and incident responders making up the largest respondent roles. The survey examines detection tooling, automation, budget, and future AI and ML investment plans.

Global, Multi-Industry Scope

Respondents span banking and finance, technology, and cybersecurity (17% each), plus government (10%) and healthcare (8%), with operations across the United States, Europe, Latin America, and Asia.

Vendor Neutrality

As with all SANS research, this survey's sponsors funded the study but had no role in designing the survey questions, collecting respondent data, or shaping the findings presented in this report.

Meet the Author

Josh Lemon
Josh Lemon

Josh Lemon

Chief Digital Forensics and Incident Response Investigator at SoteriaSec

Josh leads global MDR at Uptycs, defending major international brands, while also serving as an independent DFIR expert advising legal, government, and commercial clients in Australia.

Read more about Josh Lemon

Thank You To Our Sponsors

More Key Findings From the 2025 Detection and Response Survey

  • Limited cloud security expertise (58%) and multicloud complexity (53%) continue to outpace defender capacity despite growing cloud-native tool adoption.
  • 60% of organizations encounter false positives frequently or very frequently, including 20% facing them at very high rates, up sharply from 13% last year.
  • Only 25% of organizations describe their detection and response budget as fully sufficient, and just 3% report more-than-sufficient funding.
  • 66% of organizations have integrated at least partial automated response, though full automation remains limited to 13% overall.
  • 59% cite a lack of skilled personnel as a top detection challenge, and 56% cite skill gaps as a leading barrier to response.

SANS 2026 Detection and Response Report Findings Are Coming Soon

SANS 2026 Detection and Response Survey analysis is underway. Save your seat for the related webcast, SANS 2026 Detection and Response Survey Report: Signals, Not Noise, to hear the SANS team break down what's changing for security operations.

Microphone

Explore the SANS Detection and Response Report Archive

Review prior year’s data to see how organizations across industries are evolving their cybersecurity operations in the face of mounting complexity, resource constraints, and an increasingly sophisticated threat landscape.

Frequently Asked Questions

According to the SANS 2025 Detection and Response Survey, false positives are the leading detection challenge, cited by 73% of respondents, up sharply from 64% in 2024.

90% of organizations rely on automated tools for threat detection, up from 87% in 2024, while 45% now use AI and ML technologies as part of their detection stack.

Yes. 76% of organizations plan to expand their use of AI and ML for detection and response, up from 67% in 2024, with automated threat hunting adoption plans rising to 73%.

Not fully. 28% of organizations describe their detection and response budget as insufficient, up from 22% in 2024, while only 3% report more-than-sufficient funding.