Group Purchasing
Group Purchasing

10th Annual SANS SOC Report

AI has entered the SOC faster than any technology before it, but most organizations are using it without governance, validation, or a defined workflow. Staffing and funding gaps remain the biggest barriers to closing that gap, and SOCs that plan their data strategy before buying tools consistently report the highest technology satisfaction.

Top Takeaways

79%

of SOCs use AI or ML tools for security operations

36%

have built AI tools into a defined SOC workflow

32%

of practitioners say management prioritizes SOC staffing

70%

still cite incident count as their top SOC metric

Survey Methodology and Respondent Profile

The 2026 SANS SOC Survey received 444 qualified responses from IT and security professionals working in monitoring or security operations roles, with about 150 completing an extended section on technology deployment, satisfaction, metrics, and threat intelligence.

Leadership Lens

A parallel instrument drew 69 CISOs and senior security executives for the Cyber Leaders module. Respondents span cybersecurity, banking and finance, technology, and government, across the United States, Europe, Asia, and Canada.

Vendor Neutrality

SANS Institute conducted and authored the analysis independently of the survey's sponsors.

More Key Findings from the SANS 2026 SOC Report 

  • 79% of SOCs use AI or ML tools, but only 36% have built them into a defined workflow.
  • Skilled staff shortages remain the top challenge, yet only 32% say management prioritizes SOC hiring and retention. 
  • SOCs that feed all data into the SIEM score a technology satisfaction GPA of 2.76, versus 2.14 for low-capability peers. 
  • Meaningful work and career progression have outranked pay as top retention drivers for three straight years. 
  • SIEM is the most requested hiring skill, even though EDR earns the highest satisfaction rating of any tool. 
  • 24% of cyber leaders name lack of enterprise-wide visibility as the top barrier to SOC capability, ahead of staffing gaps. 
  • 74% of cyber leaders apply threat intelligence to operations, but only 26% use it to inform budget decisions.

Watch the 2026 SOC Survey Insights Webcast

Christopher Crowley walks through the data behind the 10th annual SANS SOC Survey, including the widening gap between AI adoption and integration, the persistent management alignment gap, and what separates the highest-satisfaction SOCs from the rest. Bring questions for the live Q&A.

Stylized Microphone Blue Background

Meet the Author

Christopher Crowley
Christopher Crowley

Christopher Crowley

Independent Consultant at Montance, LLC

Chris Crowley, SANS Senior Instructor and SOC consultant, combines 25 years of cyber operations leadership and AI expertise to train defenders to detect, analyze, and respond to modern threats with clarity, confidence, and hands-on precision.

Read more about Christopher Crowley

FAQs

79% of SOCs use AI or machine learning tools, according to the 2026 SANS SOC Survey, but only 36% have integrated them into a defined workflow. Most analysts use AI individually, without organizational structure or systematic validation.

Meaningful work and career progression have outranked compensation as the top SOC retention drivers for three years running. Only 32% of practitioners say management pays close attention to hiring and retention, a gap that compounds every staffing decision.

24% of cyber leaders name lack of enterprise-wide visibility as the single biggest barrier to leveraging SOC capabilities, ranking it above staffing and automation gaps. Practitioners describe the same problem as too many uncorrelated alerts and unintegrated tools.

74% of cyber leaders apply threat intelligence to security operations and threat hunting, but only 26% use it to inform budget and spending decisions, according to the 2026 SANS SOC Survey.

Only 16% of SOCs fully support all at-risk smart systems, and another 29% offer partial coverage. More than half of organizations lack full visibility into operational technology and IoT assets.

Number of incidents handled has been the top reported SOC metric for 10 consecutive years, cited by 70% of respondents. It measures volume of activity, not whether the right threats were caught or caught early.

Thank You to Our Sponsors

Explore Previous SOC Report Insights

The 2026 edition marks the 10th year SANS has tracked security operations practice at scale. Explore the past few years to see how AI adoption, staffing, and technology satisfaction have evolved.

SANS 2026 SOC Report: A Decade of Evolution in Cyber Defense | SANS Institute