In a significant shift within the cybersecurity landscape, data has overtaken skills as the primary barrier for threat hunters, marking a notable change for the first time in five years, according to findings from the SANS Institute. This revelation emerged from the comprehensive “SANS 2026 Threat Hunting Survey: The Evolution of Threat Hunting,” which gathered insights from 500 cybersecurity practitioners and leaders across North America, Europe, Latin America, and Asia.
A striking 50% of the respondents indicated that data quality or quantity poses their most substantial challenge in threat hunting. This figure reflects a marked increase from previous years, where it was 41% last year and 34% in 2023. The trend underscores the ongoing difficulties threat hunters face as the volume of data increases, potentially leading to overwhelming complexities rather than solutions. The report noted that the influx of data is accompanied by inadequate normalization and outdated standards, further complicating threat-hunting endeavors.
In comparison, skilled staff emerged as the second biggest hurdle, cited by 45% of participants. This figure has notably decreased from 61% last year, a sign of progress in tackling staffing issues within the field. However, the persistent skills shortage means that when hunts are conducted, they often rely more on the availability of personnel rather than the expertise that would ideally inform the most effective hypothesis crafting.
Interestingly, the formalization of threat-hunting methodologies has dropped from 51% in 2024 to 37% this year, with 39% of respondents opting for ad hoc approaches. This decline is concerning as a structured methodology is vital for ensuring that threat-hunting programs are repeatable and defensible in an era where robust cybersecurity strategies are essential.
Budget constraints, cited by 42% of respondents, along with the lack of data standards (39%), tool limitations (37%), and undefined processes (36%), highlight the multifaceted challenges that organizations face in enhancing their threat-hunting capabilities. Josh Lemon, a principal instructor with SANS and the report’s author, emphasized that high-quality data is the bedrock of effective threat-hunting operations. He underscored a critical reality: “You can be the most capable hunter in the room and still come up empty if the telemetry you’re working with is incomplete, inconsistent, or scattered across a dozen tools that are difficult to access or difficult to process.”
Moreover, the survey revealed a concerning statistic: only 40% of programs have any formal measurements to evaluate the effectiveness of their hunting efforts. As a result, many organizations operate without a clear understanding of whether their existing practices are truly effective or if they are inadvertently missing critical opportunities for improvement.
The survey also highlighted that ransomware remains the predominant threat for threat-hunting teams, with 55% of respondents identifying it as their primary concern. Other significant threats included business email compromise at 43%, nation-state attacks at 26%, and insider threats, which also rated at 26%. However, the report criticized the approach of relying on known threats, stating, “If you are still writing hunts around known bad hashes or IP addresses, you are hunting for threat actors who stopped behaving that way years ago.”
Despite the multitude of challenges presented, it is noteworthy that the uptake of artificial intelligence (AI) and machine learning (ML) among threat hunters has not surged as anticipated. Only 39% of respondents ranked the incorporation of AI and ML among their top planned improvements, a decrease from 48% last year. This decline indicates a broader trend where teams are shifting from aspirations toward the more demanding reality of effective implementation.
The report suggests that early signals of progressive change within the field are presented by teams describing agentic hunting frameworks in their free-text responses. This represents a cognitive shift toward more proactive and independent approaches in threat hunting.
In conclusion, as the landscape of threat hunting continues to evolve, the most pressing issue identified is the measurement of effectiveness. The report strongly advises organizations to focus on demonstrating the tangible findings of their hunting efforts and how these findings contribute to preventing attacks. This shift toward measurable outcomes is crucial for justifying investments in tools, training, and strategies cited throughout the report, ultimately shaping a more resilient approach to cybersecurity in the future.
