The Detection Engineering Best Practices for Implementing a Threat-Informed Defense survey, published by SANS Institute in November 2023, measured the state of practice in detection engineering across cybersecurity organizations. The survey drew on responses from 267 cybersecurity professionals, covering SIEM adoption, staffing, framework use, detection validation, and quality assurance.
Key findings:
- 91.4% of organizations are using a SIEM, but many still focus on log management over event detection
- Microsoft Sentinel is now the most-used SIEM product at 45.8%, despite not being a market factor before 2021
- 85.6% of organizations use the MITRE ATT&CK framework to structure and assess their detections
- Only 42.4% use the Cyber Kill Chain framework, making ATT&CK the dominant approach by a wide margin
- 29.6% of organizations run a SOC with 26 to 100 full-time equivalents, the most common staffing tier
- 31.3% validate detections through penetration testing, more than any other single method
- 22% rely on automated validation test scripts to confirm detections are working after deployment
- Purple team and red team exercises are most often run quarterly, cited by 40.4% of respondents
- 62.2% uncover detection gaps primarily through third-party security assessments
- Staying responsive to a changing threat landscape is the most significant cause of detection gaps, ahead of alert fatigue and toolset complexity
- 54.5% measure detection quality using the true positive to false positive alert ratio
- Detection engineering responsibility is spread across SOC analysts, security engineers, threat hunters, and red teamers, indicating "detection engineer" is not yet a widely recognized standalone role
The findings show an industry still treating detection engineering as a shared responsibility rather than a dedicated discipline, even as MITRE ATT&CK adoption signals a maturing, framework-driven approach to gap assessment. Organizations lean heavily on third-party assessments and periodic red team exercises to validate detections, but the emphasis on responsiveness to new threats over structured, continuous testing suggests most teams remain reactive rather than proactive in closing coverage gaps.
Respondents were drawn primarily from the cybersecurity, banking and finance, manufacturing, and technology sectors, spanning organizations from fewer than 1,000 employees to more than 50,000, with roles concentrated among security administrators and analysts, business managers, and IT managers or directors.