The SANS 2024 SOC Survey: Facing Top Challenges in Security Operations, published by SANS Institute in May 2024, measured the capabilities, budget, staffing, and challenges facing security operations centers (SOCs) worldwide. Written by Christopher Crowley, the survey drew on responses from 403 security professionals, with 334 headquartered in North America (301 in the United States), spanning the technology, government, banking and finance, cybersecurity, and education sectors.
Key findings:
- Lack of automation and orchestration is the single most-cited SOC barrier, named by 71 of 388 respondents, ahead of high staffing requirements and lack of skilled staff combined
- 38% of respondents said their organization's SOC budget is simply "unknown," suggesting a disconnect between SOC staff and organizational budgeting processes
- 67% of respondents provide metrics to senior management to justify SOC resources, down from 74% in 2022
- Cloud-based architecture has overtaken single, central SOC as the most common SOC structure for the first time
- 60% of respondents (242 of 403) run a single, centralized SOC, up from 49% in 2023 and 53% in 2022
- 38% now ingest everything into their SIEM rather than filtering data before collection, up from 29% in 2023
- 46% partially automate threat hunting using vendor-provided tools, up from 38% in 2023
- AI/ML technologies rank at the bottom of SOC technology satisfaction, with "Analysis: AI or machine learning" dropping from a 2.17 to a 1.99 GPA year over year, and generative AI (GPT) debuting at the very bottom with a 1.80 GPA
- EDR/XDR is the highest-rated technology for the first time, crossing into "A" territory with a 3.13 GPA
- Only 20% of SOCs do not operate 24/7, and of those that do, 49% follow a "follow-the-sun" model
- 76% of respondents say SOC staff can work remotely
- 68% of organizations have some operational technology (OT) component to monitor alongside IT
- Pen-testing, red-teaming, purple-teaming, and digital forensics are the most commonly outsourced SOC capabilities, while security administration and roadmap planning stay almost entirely in-house
- The most common SOC size remains 2–10 people, a finding that has held steady since the survey began in 2017
The throughline across this year's results is a widening gap between what SOCs are asked to do and what they're resourced to do: budgets remain opaque to the people running them, staffing shortages persist as the top barrier, and the newest wave of AI/ML tooling has yet to earn the trust of the analysts using it. At the same time, structural shifts — the move to cloud-based architecture, more centralized SOCs, and heavier automation of routine threat hunting — suggest SOCs are consolidating and streamlining even as staffing and budget visibility lag behind.
Respondents were drawn from 403 security professionals, primarily security administrators/analysts, SOC analysts, security managers/directors, and SOC managers/directors, working at organizations ranging from fewer than 1,000 to more than 50,000 employees, concentrated in technology, government, banking and finance, cybersecurity, and education.