HomeCyber BalkansData Quality Surpasses Skills as the Primary Challenge in Threat Hunting

Data Quality Surpasses Skills as the Primary Challenge in Threat Hunting

Published on

spot_img

Data Quality Emerges as Primary Challenge for Threat Hunting Teams, Surpassing Skills Shortages

Data quality has recently been identified as the foremost obstacle confronting threat hunting teams, marking a notable shift in the cybersecurity landscape. For the first time in five years, data quality has overtaken skills shortages as the predominant concern among cybersecurity practitioners, according to the SANS Institute’s latest survey. This revelation stems from a comprehensive study of 500 professionals in the field, where a striking 50% acknowledged data quality or quantity as their biggest challenge. This figure has steadily increased from 41% in 2024 and 34% in 2023, indicating that the flood of security data is creating complications faster than organizations can implement appropriate normalization and standards.

While shortages of skilled personnel continue to pose significant challenges, their prevalence has diminished, dropping from 61% last year to 45% in the current landscape. The decline in resources often leads organizations to conduct fewer threat hunts. As experts become limited, companies tend to rely on general staff rather than those best equipped to develop sophisticated hunting hypotheses, ultimately impairing the effectiveness of their security measures.

The survey findings further reveal a drop in the use of formally defined threat hunting methodologies—from 51% last year to 37% this year. In contrast, ad hoc approaches, which lack structure, have seen an increase, now comprising 39% of the practices undertaken by organizations. Other identified barriers to effective threat hunting include budget constraints, cited by 42% of respondents, lack of data standards at 39%, limitations within existing tools at 37%, and undefined processes, which affected 36% of those surveyed.

Josh Lemon, a principal instructor at SANS and the report’s author, articulated a critical perspective on the challenges faced by hunting teams. He emphasized that even the most skilled threat hunters cannot thrive amidst incomplete or inconsistent data, which is frequently scattered across multiple tools. This situation is further complicated by a glaring measurement gap: only 40% of threat hunting programs undergo formal assessments to evaluate whether their activities yield meaningful results. The absence of this validation leaves organizations in a precarious position, as they are unable to ascertain whether issues related to data quality are causing them to overlook potential threats.

Despite these mounting challenges, the maturity of threat hunting programs has notably improved, with more than 80% of survey respondents indicating that their programs have been operational for at least two years. Ransomware remains the most pursued threat, with 55% of teams targeting it, closely followed by business email compromise at 43%. Other threats include nation-state actors and insider threats, each representing 26% of the hunting priorities. Additionally, the report highlights a concerning trend in attacker behavior, noting that "living-off-the-land" techniques dominate. This signifies a shift in tactics that could potentially outpace traditional hunting strategies, especially those that rely on known malicious indicators like IP addresses or file hashes, which are increasingly becoming outdated.

The study also noted a declining interest in artificial intelligence and machine learning tools, with only 39% of respondents ranking AI incorporation among their top priorities, a drop from 48% last year. SANS attributes this decline to teams transitioning from aspirational goals to confronting practical challenges associated with implementation. The report culminates with a pressing recommendation for organizations to prioritize measuring the effectiveness of their threat hunting programs before diving into advanced technological investments. Demonstrating tangible results will be critical to justifying ongoing expenditures in threat hunting operations, ensuring that resources are directed effectively to mitigate emerging security challenges.

As the cybersecurity landscape evolves, understanding these dynamics will be pivotal for organizations seeking to enhance their defensive capabilities and fortify their resilience against increasingly sophisticated cyber threats. The necessity for prioritizing data quality, understanding measured results, and adapting to the evolving tactics of adversaries will be essential for organizations striving to stay ahead in the digital threat environment.

Source: Infosecurity Magazine

Source link

Latest articles

CISA Offers OT Recovery Guidance via CI-Fortify

Business Continuity...

UK Government Transitions to Service-Led Cyber Governance Following Audit

The UK government's approach to cybersecurity within the civil service is undergoing a significant...

SCOUTz Unveils Prospect Intelligence Platform for MSPs with 30-Day Beta Launch

Phoenix, Arizona, September 24th, 2026, CyberNewswire — The landscape of cybersecurity sales for managed...

Thousands of AI Relays Conceal Chinese Users

Cybersecurity Weekly Roundup: Major Incidents and Developments In the ever-evolving landscape of cybercrime and cybersecurity,...

More like this

CISA Offers OT Recovery Guidance via CI-Fortify

Business Continuity...

UK Government Transitions to Service-Led Cyber Governance Following Audit

The UK government's approach to cybersecurity within the civil service is undergoing a significant...

SCOUTz Unveils Prospect Intelligence Platform for MSPs with 30-Day Beta Launch

Phoenix, Arizona, September 24th, 2026, CyberNewswire — The landscape of cybersecurity sales for managed...