Optiv
Reports
All Statistics
45% of IT and IT security professionals identify poor data quality as a key barrier to automation.
41% of IT and IT security professionals identify a lack of standardized processes as a key barrier to automation.
28% of IT and IT security professionals believe identity-related issues involved in SOC security incidents are investigated continuously or hourly, with 18% believing they are investigated continuously and 10% believing they are investigated hourly.
74% of respondents identify a lack of understanding of every potential source of vulnerability as their biggest challenge to effective vulnerability management.
The effectiveness of CSIRPs in minimizing the consequences of cybersecurity incidents increased from 50% of respondents in 2024 to 57% of respondents in 2025
46% of respondents say their organizations use AI/ML to prevent cyberattacks.
23% of IT and IT security professionals say their SOC is managed based on metrics and key performance indicators (KPIs).
63% of organizations cite reducing tool sprawl and the complexity of managing dozens to hundreds of security tools as a primary driver for cybersecurity platform consolidation.
36% of alerts and incidents are investigated through manual processes rather than automated workflows.
46% of organizations have pursued cybersecurity platform consolidation within the past two years.
55% of organizations cite improving visibility and reducing security gaps as a primary driver for cybersecurity platform consolidation.
40% of IT and IT security professionals characterize their SOC as very mature.
49% of IT and IT security professionals identify insufficient explainability as a key barrier to automation.
39% of IT and IT security professionals report that their SOC currently uses AI and/or machine learning to support detection, investigation and response.
38% of SOCs using AI have it fully integrated into existing SOC workflows and tooling.
39% of IT and IT security professionals identify limited visibility into the systems SOC teams oversee as a critical gap undermining SOC effectiveness.
37% of IT and IT security professionals identify lack of in-house expertise, including threat hunters and intelligence analysts, as a critical gap undermining SOC effectiveness.
Security Operations Centers (SOCs) manage an average of 2,566 alerts and incidents each day.
17% of IT and IT security professionals say their SOC is optimized for continuous improvement.
64% of IT and IT security professionals say identity visibility is very or extremely important to improving overall SOC effectiveness.
32% of IT and IT security professionals say identity events and privileged access events are centrally visible to their SOC.
51% of IT and IT security professionals at organizations with a SOC rate their SOC's ability to keep pace with the speed and sophistication of modern threats as effective or very effective.
46% of IT and IT security professionals identify insufficient staffing as a critical gap undermining SOC effectiveness.
52% of IT and IT security professionals report that alert and incident volumes have increased, with 23% reporting volumes have significantly increased and 29% reporting they have increased.
The average security budget is $24 million.
79% of respondents say their organization is making changes to its cybersecurity budget.
Of organizations using AI/ML, 88% are incorporating generative AI at some level.
Outsourcing to managed security service providers (MSSPs) jumped from 47% in 2024 to 58% in 2025.
Of organizations making budget changes, 71% say security budgets are increasing.
66% of respondents report cybersecurity incidents have increased significantly or increased in the past year. This is up from 61% in 2024.
51% of respondents say their organizations have a Cybersecurity Incident Response Plan (CSIRP) applied consistently across the entire enterprise. This is up from 46% in 2024.
The primary drivers for AI/ML adoption are improving operational efficiency (41%) and maintaining competitive advantage (40%).
66% of respondents say their organizations have fully or partially implemented Secure Access Service Edge (SASE).
72% of respondents continue to significantly or moderately use Security Orchestration, Automation, and Response (SOAR) to reduce cyber threats.
67% of organizations are now using risk and threat assessments to inform budget decisions. This is up from 53% in 2024.
57% of respondents report automation has reduced the time to respond to vulnerabilities.
34% of respondents report seeing significant improvements in vulnerability response time due to automation.