The 2025 SANS Detection & Response Survey offers a comprehensive look at how security teams are adapting to rising operational demands, increasingly complex hybrid environments, and a rapidly evolving threat landscape. With insights from hundreds of practitioners across banking, finance, technology, government, and healthcare, the report reveals where modern SOCs are succeeding and where critical gaps remain.
This year’s findings uncover several pressing challenges, including escalating alert fatigue, cloud visibility issues, persistent skills shortages, and growing pressure to automate detection and response. As SANS notes in the report, “false positives remain the leading operational burden,” reflecting a dramatic rise in noise that hinders analysts’ ability to respond effectively.
Cloud environments continue to strain security programs as well. According to the survey, “cloud complexity outpaces expertise,” and teams struggle to maintain cohesion across multicloud and SaaS ecosystems. The data also highlights widespread resource limitations: “teams are being asked to deliver more capability with less investment,” underscoring the gap between expectations and available funding.
Inside the report, you’ll find data-driven analysis on:
The rising volume and impact of false positives
Cloud detection challenges across CSP, SaaS, and multicloud environments
The growing importance of automation, AI/ML, and proactive threat hunting
Staffing and skill gaps affecting detection and response readiness
The tools and techniques organizations rely on most, and how effective they truly are
How teams benchmark detection coverage, measure performance, and plan future investments
Whether you lead a SOC, manage detection engineering, or are responsible for evaluating detection and response technologies, this report provides timely insight into the obstacles and opportunities shaping cyber defense.
Many of the issues uncovered in this year’s report—false positives, cloud visibility gaps, limited staffing, and increasing response times—are the exact problems Clear NDR® was built to solve.
Explore your next steps:
✅ Request a live demo and see how Clear NDR exposes unseen threats
✅ Review flexible, probe-based pricing for Clear NDR
✅ Dive deeper with our blog series on the SANS findings
Use the links below to learn how to apply the report’s insights within your own security operations.
Cyber Defense Engineering Manager at a major travel technology vendor
Head of Sector at a multi-national government institution
Lead of Information Security Team for a global engineering SaaS company
Lead Security Analyst at large DevOps vendor
Head of Cyber Security and Governance at an international European Bank
CTO at Bulgarian MSSP
Director of Infrastructure Technology at U.S. public school system
Head of Cyber Security and Governance at an international European Bank
Sales Engineer at French MSSP
Head of Cyber Security and Governance at an international European Bank
Lead of Information Security Team for a global software engineering firm
ABOUT STAMUS® NETWORKS
Stamus Networks is the global leader in Suricata-based network security and the creator of the innovative Clear NDR® system. Designed to close visibility gaps and reduce alert fatigue, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Trusted by leading financial institutions, government agencies, and battle-tested over 9 years in NATO’s largest cybersecurity exercises, Stamus Networks delivers proven, high-performance network detection and response solutions. Stamus empowers security teams – delivering clarity amidst complexity – with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.
© 2014-2025 Stamus Networks, Inc. All rights Reserved.