The 2026 SANS SOC Survey Insights: A Decade of Evolution in Cyber Defense, published by SANS Institute in June 2026, marks the 10th year SANS has tracked security operations practice at scale. The survey drew on 444 qualified responses from SOC analysts, security administrators, and security managers across the United States, Europe, Asia, and Canada, with a parallel module capturing perspectives from 69 CISOs and senior security executives.
Key findings:
- 79% of SOCs use AI or ML tools, but only 36% have integrated them into a defined SOC workflow
- Only 32% of practitioners say management pays close attention to SOC hiring and retention needs, compared to 59% of cyber leaders who believe management is engaged
- Meaningful work is the top SOC retention driver for the third consecutive year; compensation has fallen to fourth place
- SOCs with skilled practitioners score a technology satisfaction GPA of 2.76, compared to 2.14 for low-capability peers
- Only 45% of SOCs fully or partially monitor nontraditional computing assets such as OT, ICS, and IoT devices
The full report also examines how these gaps play out across SOC architecture and cloud migration trends, outsourcing patterns for functions like threat hunting and digital forensics, the hiring paradox between SIEM and EDR skills, and a dedicated Cyber Leaders module comparing executive and practitioner perspectives on visibility, staffing, and threat intelligence investment. Log in to sans.org to download the complete survey report.
Respondents were drawn primarily from cybersecurity (81), banking and finance (71), technology (61), and government (43) sectors, with the largest single role represented being SOC analyst (86). The primary survey instrument was completed by all 444 respondents, with roughly 150 completing a deeper second section on technology satisfaction, metrics, and threat intelligence; a separate parallel survey captured responses from 69 CISOs and senior security executives.