Group Purchasing
Group Purchasing

SANS 2023 SOC Survey

SANS 2023 SOC Survey (PDF, 1.96MB)Published: 13 Jun, 2023
Created by:
Christopher CrowleyBarbara FilkinsJohn Pescatore
Christopher Crowley, Barbara Filkins & John Pescatore

The SANS 2023 SOC Survey, published by SANS Institute in June 2023, examined how security operations centers are staffed, architected, and funded in its seventh year running. The survey drew on responses from 641 SOC managers, analysts, and security administrators across industries including cybersecurity, technology, banking and finance, and government, covering threat hunting, threat intelligence, SIEM data ingestion, SOAR adoption, and staff hiring and retention.

Key findings:

  • More than 75% of respondents detected incidents before external notification, with only 9% via proactive threat hunting
  • The most common SOC size is between 11 and 25 staff
  • 73% of SOCs allow staff analysts to work remotely, including 58% of those with a single, centralized SOC
  • 84% of SOCs collect and expose performance metrics, yet 22% don't know their own annual SOC budget
  • Career progression, not money, is the top-cited method for retaining SOC staff, named by 30% of respondents
  • 68% of respondents said monitoring and alerting was the most frequent source of incident detection, ahead of threat hunting or user reports
  • "Lack of context related to what we are seeing" was the top-cited barrier to full SOC utilization, jumping from near the bottom of the list the prior year
  • No security technology category scored above a C average on a satisfaction basis; AI/machine learning and network packet analysis tied for the lowest scores
  • 56% of SOCs are not attempting to calculate the monetary value the SOC provides
  • Only 31% of respondents have calculated a "cost per record" figure from an actual incident
  • SOCs most commonly outsource forensics, penetration testing, and threat intelligence, while keeping security architecture, engineering, and administration in-house
  • 49% of SOCs currently use cloud-based services in their architecture, with respondents projecting growth to 62% within 12 months

The findings point to a widening gap between SOC operational maturity and the business context needed to prove its value: teams collect metrics and detect threats effectively, but most cannot connect that work to cost, budget, or risk in language executives use. Staffing pressure compounds the problem, with SOCs still small relative to the volume of alerts and context-gathering required, and skilled analysts remaining the scarcest resource even as remote work removes geographic constraints on hiring.

Respondents represented organizations of all sizes, from fewer than 1,000 employees to more than 50,000, with the largest concentrations of operations located in North America, government, cybersecurity, technology, and banking and finance sectors, and the survey spanning SOC analysts, managers, security administrators, and security directors.

FAQ

Meet the experts