Optiv

37 stats2 reports

All Statistics

45% of IT and IT security professionals identify poor data quality as a key barrier to automation.

AutomationSecurity Operations

41% of IT and IT security professionals identify a lack of standardized processes as a key barrier to automation.

AutomationSecurity Operations

28% of IT and IT security professionals believe identity-related issues involved in SOC security incidents are investigated continuously or hourly, with 18% believing they are investigated continuously and 10% believing they are investigated hourly.

Identity SecurityIncident ResponseSecurity Operations

74% of respondents identify a lack of understanding of every potential source of vulnerability as their biggest challenge to effective vulnerability management.

VulnerabilitiesVulnerability management

The effectiveness of CSIRPs in minimizing the consequences of cybersecurity incidents increased from 50% of respondents in 2024 to 57% of respondents in 2025

CSIRP

46% of respondents say their organizations use AI/ML to prevent cyberattacks.

AIMachine learning

23% of IT and IT security professionals say their SOC is managed based on metrics and key performance indicators (KPIs).

Security OperationsPerformance Measurement

63% of organizations cite reducing tool sprawl and the complexity of managing dozens to hundreds of security tools as a primary driver for cybersecurity platform consolidation.

Cybersecurity PlatformTool ManagementTool Sprawl

36% of alerts and incidents are investigated through manual processes rather than automated workflows.

AutomationSecurity Operations

46% of organizations have pursued cybersecurity platform consolidation within the past two years.

Cybersecurity PlatformSecurity OperationsConsolidation

55% of organizations cite improving visibility and reducing security gaps as a primary driver for cybersecurity platform consolidation.

Cybersecurity PlatformVisibilityConsolidationTool Sprawl

40% of IT and IT security professionals characterize their SOC as very mature.

Security OperationsMaturity

49% of IT and IT security professionals identify insufficient explainability as a key barrier to automation.

AutomationAI ExplainabilitySecurity Operations

39% of IT and IT security professionals report that their SOC currently uses AI and/or machine learning to support detection, investigation and response.

AISecurity OperationsMachine LearningThreat DetectionThreat Investigation

38% of SOCs using AI have it fully integrated into existing SOC workflows and tooling.

AISecurity Operations

39% of IT and IT security professionals identify limited visibility into the systems SOC teams oversee as a critical gap undermining SOC effectiveness.

Security OperationsVisibility

37% of IT and IT security professionals identify lack of in-house expertise, including threat hunters and intelligence analysts, as a critical gap undermining SOC effectiveness.

Security OperationsWorkforce

Security Operations Centers (SOCs) manage an average of 2,566 alerts and incidents each day.

Security OperationsAlert VolumeAlert Fatigue

17% of IT and IT security professionals say their SOC is optimized for continuous improvement.

Security Operations

64% of IT and IT security professionals say identity visibility is very or extremely important to improving overall SOC effectiveness.

Identity SecuritySecurity OperationsIdentity Visibility

32% of IT and IT security professionals say identity events and privileged access events are centrally visible to their SOC.

Identity SecurityVisibility

51% of IT and IT security professionals at organizations with a SOC rate their SOC's ability to keep pace with the speed and sophistication of modern threats as effective or very effective.

Security OperationsThreat Detection

46% of IT and IT security professionals identify insufficient staffing as a critical gap undermining SOC effectiveness.

Security OperationsWorkforce

52% of IT and IT security professionals report that alert and incident volumes have increased, with 23% reporting volumes have significantly increased and 29% reporting they have increased.

Security OperationsIncident Response

The average security budget is $24 million.

BudgetInvestment

79% of respondents say their organization is making changes to its cybersecurity budget.

BudgetInvestment

Of organizations using AI/ML, 88% are incorporating generative AI at some level.

AIMachine learningGen AI

Outsourcing to managed security service providers (MSSPs) jumped from 47% in 2024 to 58% in 2025.

MSSP

Of organizations making budget changes, 71% say security budgets are increasing.

BudgetInvestment

66% of respondents report cybersecurity incidents have increased significantly or increased in the past year. This is up from 61% in 2024.

Security incident

51% of respondents say their organizations have a Cybersecurity Incident Response Plan (CSIRP) applied consistently across the entire enterprise. This is up from 46% in 2024.

CSIRP

The primary drivers for AI/ML adoption are improving operational efficiency (41%) and maintaining competitive advantage (40%).

AIMachine learning

66% of respondents say their organizations have fully or partially implemented Secure Access Service Edge (SASE).

SASESecurity tool

72% of respondents continue to significantly or moderately use Security Orchestration, Automation, and Response (SOAR) to reduce cyber threats.

SOARSecurity tool

67% of organizations are now using risk and threat assessments to inform budget decisions. This is up from 53% in 2024.

Threat assessmentBudgetInvestment

57% of respondents report automation has reduced the time to respond to vulnerabilities.

AutomationVulnerabilities

34% of respondents report seeing significant improvements in vulnerability response time due to automation.

AutomationVulnerabilitiesVulnerability management