The 2025 SANS Detection Engineering Survey: Evolving Practices in Modern Security Operations, published by SANS Institute in February 2025 in partnership with Anvilogic, examined how organizations are building, staffing, and scaling detection engineering as a distinct security discipline. The survey drew on responses from 264 cybersecurity professionals across industries including cybersecurity, technology, banking and finance, and healthcare, covering team maturity, workforce skills, compensation, technology adoption, and the role of automation and AI.
Key findings:
- Investment has outpaced maturity: nearly 80% of organizations fund detection engineering, but only 60% have established dedicated detection engineering teams
- Behavior-based detection is the most effective methodology, cited by 67% of respondents, ahead of threat intelligence-driven and correlation-based approaches, which tied at 43% each
- 71% of organizations cite resource and time constraints as their primary obstacle, despite 67% reporting strong executive buy-in
- 47% of respondents report inadequate access to the data feeds needed for effective detection
- Only 45% of organizations currently use AI for detection, yet 88% believe it will significantly impact their operations within three years
- 41% of respondents report difficulty finding skilled detection engineering personnel
- Custom-developed detection content is the leading detection source at 42%, ahead of vendor-provided detections at 37% and open source at 17%
- Vendor-provided detection tools carry high false positive rates (64%) and accuracy issues (61%), the most commonly cited technology challenges
- The most common detection engineer salary range is $101,000–$150,000 annually, with U.S. tech-hub states like Massachusetts and California averaging $167,782 and $153,151
- 63% of organizations currently use automation in detection workflows, and another 30% plan to implement it within 12 months
- Integration between detection engineering and incident response teams is highest at 58%, while integration with infrastructure (31%) and application teams (35%) remains comparatively low
- Only 45% of organizations have a way to reliably measure the effectiveness of their detection engineering efforts, and 49% report difficulty evaluating that effectiveness at all
The findings describe a discipline caught between strong strategic backing and thin operational follow-through: organizations recognize detection engineering as critical enough to fund, but haven't yet built the staffing, data pipelines, or measurement frameworks needed to make that investment pay off consistently. The shift toward behavior-based and custom-developed detections signals growing distrust of static, vendor-supplied signatures in the face of adaptive threats, while the gap between AI's low current adoption and near-universal expectation of future impact suggests most teams are still in the early stages of figuring out how generative AI and security copilots fit into their workflows rather than already relying on them.
Respondents were drawn primarily from cybersecurity, technology, banking and finance, and healthcare organizations of varying sizes, from fewer than 1,000 employees to more than 50,000, with the largest concentration of both operations and headquarters located in North America.