back Back

Complex technology makes it increasingly difficult to protect against cyberattacks, study shows

By Puja Sharma

July 19, 2023

  • AI
  • AI in Cybersecurity
  • Cloud Adoption
Share

Cybersecurity, cyber attacksThis is despite 90% of regional SOC analysts saying their current threat detection tools are effective, revealing a disconnect in ability of threat detection tools in preventing cyber attacks

Vectra AI, the AI-driven cyber threat detection and response for hybrid and multi-cloud enterprises, today announced the findings of its 2023 State of Threat Detection Research Report, providing insight into the “spiral of more” that is preventing security operations center (SOC) teams from effectively securing their organizations from cyberattacks.

Today’s security operations (SecOps) teams are tasked with protecting progressively sophisticated, fast-paced cyberattacks. Yet, the complexity of people, processes, and technology at their disposal is making cyber defense increasingly unsustainable. The ever-expanding attack surface combined with evolving attacker methods and increasing SOC analyst workload results in a vicious spiral of more that is preventing security teams from effectively securing their organization. Based on a survey of 2,000 SecOps analysts — including 200 in the UAE and KSA — the report breaks down why the current approach to security operations is not sustainable.

Spiral of More Threatens Regional Security Teams’ Ability to Defend Their Organization

Manual alert triage costs organizations $3.3 billion annually in the US alone, and security analysts are tasked with the massive undertaking of detecting, investigating and responding to threats as quickly and efficiently as possible while being challenged by an expanding attack surface and thousands of daily security alerts.

SOC Analysts across the UAE and KSA Don’t Have the Tools to Do Their Jobs Effectively

Despite a majority of SOC analysts across the UAE and KSA reporting their tools are effective, the combination of blind spots and a high volume of false positive alerts are preventing regional enterprises and their SOC teams from successfully containing cyber risk. Without visibility across the entire IT infrastructure, organizations are not able to identify even the most common signs of an attack, including lateral movement, privilege escalation, and cloud attack hijacking.

UAE and KSA Security Analysts Facing Burnout, Posing Significant Risk to Organizational Security

Despite the increasing adoption of AI and automation tools, the regional security industry still requires a significant number of workers to interpret data, launch investigations, and take remedial action based on the intelligence they are fed. Faced with alert overload and repetitive, mundane tasks, almost three-quarters of security analysts in the UAE and KSA report they are considering or actively leaving their jobs, a statistic that poses a potentially devastating long-term impact to the regional security industry.

“As enterprises shift to hybrid and multi-cloud environments, security teams are continually faced with more — more attack surface, more attacker methods that evade defenses, more noise, more complexity, and more hybrid attacks,” said Kevin Kennedy, senior vice president of products at Vectra AI.

“The current approach to threat detection is broken, and the findings of this report prove that the surplus of disparate, siloed tools has created too much detection noise for SOC analysts to successfully manage and instead fosters a noisy environment that’s ideal for attackers to invade. As an industry, we cannot continue to feed the spiral, and it’s time to hold security vendors accountable for the efficacy of their signal. The more effective the threat signal, the more cyber resilient and effective the SOC becomes.”

Key findings:

  • Around 48% of IT security analysts in the UAE and KSA report the size of their attack surface has increased in the past three years.
  • On average, SOC teams in the UAE and KSA receive 6,736 alerts daily (approx. 2,252 more than the global average) and spend nearly two and a half hours a day manually triaging alerts.
  • Almost 43% claim that security tools are purchased as a box-ticking exercise to meet compliance requirements, and 54% wish IT team members consulted them before investing in new products.
  • Despite 73% of UAE and KSA respondents claiming their job matches expectations, 74% are considering leaving or are actively leaving their job.
  • Of the analysts considering leaving or actively leaving their role, 31% of surveyed security analysts in the UAE and KSA say it is because they spend all their time sifting through poor quality security alerts.
  • 48% of regional analysts claim they’re so busy that they feel like they’re doing the work of multiple people, and 44% believe working in the security sector is not a viable long-term career option.

Previous Article

July 19, 2023

Astra Tech acquires 90% stake in Philippines-based Y Finance

Read More
Next Article

July 19, 2023

ecolytiq & Mambu unite to offer embedded climate engagement to banks

Read More






IBSi FinTech Journal

  • Most trusted FinTech journal since 1991
  • Digital monthly issue
  • 60+ pages of research, analysis, interviews, opinions, and rankings
  • Global coverage
Subscribe Now

Other Related News

Today

Banking malware up 3x, crypto phishing jumps 83% – Are you at risk?

Read More

Today

Will the UK seize its RegTech edge as global competition heats up?

Read More

March 24, 2025

The Monday Roundup: what we are watching this week | Mar 24th

Read More

Related Reports

Sales League Table Report 2024
Know More
Global Digital Banking Vendor & Landscape Report Q4 2024
Know More
NextGen WealthTech: The Trends To Shape The Future Q4 2023
Know More
IBSi Spectrum Report: Supply Chain Finance Platforms Q4 2023
Know More
Treasury & Capital Markets Systems Report Q4 2024
Know More