The State of Automation in Security Operations: A SANS Survey, published by SANS Institute in June 2024, examined automation use cases, benefits, priorities, and ongoing challenges in security operations centers (SOCs). The survey explored key drivers of automation adoption, the role automation plays across security functions and team collaboration, and the barriers preventing organizations from realizing its full value.
Key findings:
- Only 29% of respondents cited lack of management support as a reason for not automating, suggesting cost and skills gaps, not leadership buy-in, are the real barriers to adoption
- Approximately 68% of respondents said the engineering effort required to deploy and maintain automation is the most challenging attribute of SOAR, more than any other factor
- About 59% of organizations use more than 10 security tools in their SOC, adding complexity to coordinated analysis and response
- Defending a growing and changing attack surface was cited by approximately 53% of respondents as their most significant security operations challenge, even as industry cybersecurity spending slows
- Nearly 48% of respondents cited software costs as one of the most challenging SOAR attributes, and 42% cited lack of budget as a reason for not automating at all
- Phishing response is the most commonly automated security process, already automated by 52% of organizations, followed by vulnerability management (43%) and data enrichment (42%)
- Matches to indicators of compromise (IOCs) were cited by 37% of respondents as the alert type that takes the longest to triage and investigate
- Approximately 45% of organizations are targeting automation for at least half of their incident response, and another 35% are targeting at least 75%
- Mean time to respond (67%) and mean time to detect (59%) are the top two KPIs organizations use to measure security operations performance
- About 41% of respondents cited a lack of the requisite technical skills as a reason for not deploying automation, nearly matching the 42% who cited lack of budget
- Total cost of ownership was the most common criterion organizations use when selecting an automation platform, ahead of interoperability with existing tools
The findings suggest SOAR has not yet delivered on its promise of democratizing automation for SOC teams. Despite broad recognition of the need for automation, and even management support in most organizations, cost and the engineering effort required to build and maintain automations remain the biggest obstacles to adoption. Organizations have found the most success automating mature, well-understood processes like phishing and vulnerability response, while more complex functions such as breach response and cloud security configuration remain priorities for the future rather than current capabilities.
The survey drew responses primarily from security administrators and analysts, SOC analysts, security managers and directors, and security architects, concentrated in the technology, government, cybersecurity, and banking and finance sectors, with the largest share of respondents working at organizations with fewer than 1,000 employees.