SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey findings:
The findings point to a widening gap between SOC operational maturity and the business context needed to prove its value: teams collect metrics and detect threats effectively, but most cannot connect that work to cost, budget, or risk in language executives use. Staffing pressure compounds the problem, with SOCs still small relative to the volume of alerts and context-gathering required, and skilled analysts remaining the scarcest resource even as remote work removes geographic constraints on hiring.
Respondents represented organizations of all sizes, from fewer than 1,000 employees to more than 50,000, with the largest concentrations of operations located in North America, government, cybersecurity, technology, and banking and finance sectors, and the survey spanning SOC analysts, managers, security administrators, and security directors.
The most common SOC size is 11 to 25 staff, though large organizations with more than 50,000 employees more commonly report 26 to 100 SOC staff.
Yes. 73% of SOCs allow staff analysts to work remotely, including 58% of organizations that operate a single, centralized SOC.
Lack of context related to what analysts are seeing was the top-cited challenge at 16%, followed closely by lack of skilled staff, lack of enterprise-wide visibility, and lack of automation and orchestration.
68% of respondents said monitoring and alerting was their most frequent detection source, far ahead of threat hunting, user reports, or third-party notification.
Not always. 22% of respondents said their annual SOC budget was unknown, the single most common answer to that question.
Career progression was the top-cited retention method at 30%, ahead of meaningful work and money.


Chris Crowley, SANS Senior Instructor and SOC consultant, combines 25 years of cyber operations leadership and AI expertise to train defenders to detect, analyze, and respond to modern threats with clarity, confidence, and hands-on precision.
Learn more

Barbara Filkins, SANS Research Director, holds several SANS certifications, including the GSEC, GCIH, GCPM, GLEG and GICSP, the CISSP, and an MS in information security management from the SANS Technology Institute.
Learn more

John Pescatore has been the Director of Emerging Security Trends at SANS Institute since 2013.
Learn more


















