SANS 2025 SOC Survey Exposes Critical Gaps and What Top Teams Are Doing Right

Press release
Published September 9th, 2025 - 06:35 GMT

SANS 2025 SOC Survey Exposes Critical Gaps and What Top Teams Are Doing Right

The 2025 Global SOC Survey from SANS Institute reveals a stark disconnect between alert response and data strategy in Security Operations Centers (SOCs). While 85% of SOC analysts cite endpoint security alerts as their primary response trigger, 42% of SOCs admit to dumping all incoming data into a SIEM without a plan for retrieval or analysis. Recently released, the report highlights this and other critical insights drawn from thousands of practitioners worldwide and offers the industry’s most comprehensive, vendor-neutral benchmark of SOC maturity, tooling, and staffing.

"SOCs are the backbone of modern cyber defense, but many remain overwhelmed and under-resourced," said Christopher Crowley, Certified Instructor at SANS Institute and lead author of the survey. "This year’s data offers a clear look at how SOCs are adapting to the demands of 24/7 operations, AI integration, and remote work - while also surfacing common missteps and areas for growth."

Key findings from the 2025 report include:

•    82% of SOCs report operating 24/7.
•    85% of SOC analysts cite endpoint alerts as their primary response trigger.
•    73% allow some degree of remote work for SOC personnel.
•    42% send all incoming data to a SIEM without a defined strategy for management or retrieval.
•    42% use AI/ML tools in an out-of-the-box capacity without customization.

"If company leadership isn’t prepared to fully commit the resources to make a tool effective, it would be better not to deploy it at all," said Crowley. "A shiny new technology that seems like a great solution requires budget, training, time and integration into workflow."

"We define a SOC by its capabilities, architecture, staffing, and whether those functions are internal or outsourced," added Crowley. "This report helps security leaders understand how others are building and evolving their SOCs, and where they stand in comparison."

Background Information

SANS Institute

The SANS Institute was established in 1989 as a cooperative research and education organization. Its programs now reach more than 165,000 security professionals around the world. A range of individuals from auditors and network administrators, to chief information security officers are sharing the lessons they learn and are jointly finding solutions to the challenges they face. At the heart of SANS are the many security practitioners in varied global organizations from corporations to universities working together to help the entire information security community.

Check out our PR service


Signal PressWire is the world’s largest independent Middle East PR distribution service.

Subscribe

Sign up to our newsletter for exclusive updates and enhanced content