informa
Quick Hits

SOC Teams Burdened by Alert Fatigue Explore XDR

ESG research finds a complex attack surface and threat landscape make alerts too overwhelming to monitor accurately

Cybersecurity analytics and operations is more difficult today than it was 2 years ago, according to a recent survey of security professionals conducted by Enterprise Strategy Group (ESG).

The research finds some of the top reasons why security teams struggle more now include:

  • The threat landscape is evolving and changing rapidly: 41%
  • We collect and process more security data than we did two years ago: 35%
  • The volume of security alerts has increased over the past two years: 34%
  • The attack surface has grown over the past two years: 30%

As the attack surface and threat landscape grow more complex, security teams say alerts in the security operations center (SOC), generated from many disparate security controls, have also become complicated and difficult to monitor.

Survey respondents listed their top three challenges with alerts as:

  • Filtering the nose out of alerts so we can focus on the right signals: 38%
  • Scaling to collect, process, and analyze the growing volume of security data: 37%
  • Collecting, processing, and contextualizing threat intelligence data: 36%

Many organizations are exploring extended detection and response (XDR) to help detect complex attacks. XDR is an integrated suite of security products spanning hybrid IT architectures designed to coordinate on threat prevention, detection, and response. The tech is meant to unify control points, security telemetry, analytics, and operations into one enterprise system.

ESG reports those who are interested in XDR find the following capabilities most appealing:

  • Simplified visualization of complex attacks and understanding how they progress across a kill chain: 42%
  • Advanced analytics that can detect and identify modern, sophisticated attacks: 38%

Dave Gruber, senior analyst with ESG, examines the XDR market and the technology's potential in SOCs in a recent Dark Reading webinar Making XDR Work in Your Enterprise.

The webinar's discussion centers on how XDR applies to real-life environments and scenarios, and how it works with, and independently from, other tools. It also touches on common challenges with deployment of XDR solutions.

The webinar can be accessed here.

Recommended Reading: