惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - Franky
MyScale Blog
MyScale Blog
A
About on SuperTechFans
博客园_首页
B
Blog RSS Feed
Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Vercel News
Vercel News
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
I
InfoQ
罗磊的独立博客

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
The SOC's visibility gap comes down to staffing - Help Ne...
Mirko Zorz · 2026-06-17 · via Help Net Security

AI has settled into security operations centers faster than any earlier wave of technology. Around four in five practitioners report reaching for AI or machine learning tools in their daily work. The catch shows up one layer down. Roughly a third of those same teams have built these tools into a defined workflow with structure, governance, and consistent validation. The rest pick up AI on their own, case by case, with no shared playbook for how it gets used or checked.

AI in the SOC

That splits the AI story in the latest SANS SOC Survey into two parts. Adoption is widespread. Integration trails behind it. The survey, now in its tenth year, draws on 444 responses from people working in monitoring and security operations roles, with a separate set of questions answered by senior executives.

AI tools can produce confident, well-formatted answers, and an analyst who trusts that output without the skill to question it becomes the weak point. Several SANS instructors land on the same observation. The danger sits with the person who accepts the result, and with a tool that looks authoritative even when it is wrong.

Leaders and their teams describe different organizations

The survey includes a section answered by CISOs and VP-level leaders, and their answers complicate the main findings. Executives and practitioners describe the same organization and reach different conclusions about how well it works.

The sharpest example sits in staffing. A majority of cyber leaders say management pays close attention to SOC hiring and retention needs. About a third of practitioners agree. That 27-point spread has held across every year the question has been asked. Executives describe their intent. Practitioners describe their experience. Both accounts are accurate, and the distance between them is where retention problems begin.

The effect reaches past morale. When the people who run the SOC feel that leadership overlooks their staffing needs, the team loses the ability to build institutional knowledge and grow junior analysts into senior ones. That continuity is what a serious threat environment demands.

What keeps analysts around

The survey has tracked retention drivers for a decade, and the answer stays steady. Meaningful work ranks first for the third year running, followed by career progression and training. Compensation sits in fourth place.

The point lands for organizations that cannot win a bidding war on salary. They can still offer challenging assignments, a visible career path, and investment in development. Teams that lead with raises and skimp on those three are solving for the wrong thing.

Visibility sits underneath every other decision

Cyber leaders point to one barrier above the rest: a shortage of enterprise-wide visibility. Practitioners name a lack of skilled staff first. These describe one problem from two angles. Leadership cannot see the whole environment. The team cannot get the headcount to instrument it.

The two feed each other. Thin staffing leaves parts of the environment uninstrumented, so leaders cannot see the scope of what they are missing, which makes the case for more headcount harder to win. Closing one side alone leaves both open. One SANS instructor traces much of the visibility problem to identity, a part of the environment many teams assume they cover and rarely engineer with the same care they give endpoints.

Intelligence guides the day more than the budget

Threat intelligence has become standard in the SOC. Most teams apply it to incident response, threat hunting, and daily defense. A smaller share lets it inform what the organization funds for the year ahead.

Intelligence tells an organization which threats are active and which assets attackers target. That information belongs in a budget conversation. Most teams keep it on the analyst’s desk and set annual spending from vendor proposals and past patterns. Over time, intelligence that never touches investment loses standing with leadership and slides toward being a cost center that gets tolerated.

The wider message across ten years of this data is steady. The SOC absorbs change at a deliberate speed, on its own terms. AI arrives quicker than that rhythm allows, and the next few years will test whether the structures that govern security operations can keep up with the tools they are asked to manage.

Download: Secure Foundations for AI Workloads on AWS