Report by Optiv
2026 Creating a Modern and Mature Security Operations Center (SOC) Report
Key Findings
45% of IT and IT security professionals identify poor data quality as a key barrier to automation.
41% of IT and IT security professionals identify a lack of standardized processes as a key barrier to automation.
28% of IT and IT security professionals believe identity-related issues involved in SOC security incidents are investigated continuously or hourly, with 18% believing they are investigated continuously and 10% believing they are investigated hourly.
23% of IT and IT security professionals say their SOC is managed based on metrics and key performance indicators (KPIs).
63% of organizations cite reducing tool sprawl and the complexity of managing dozens to hundreds of security tools as a primary driver for cybersecurity platform consolidation.
36% of alerts and incidents are investigated through manual processes rather than automated workflows.
46% of organizations have pursued cybersecurity platform consolidation within the past two years.
55% of organizations cite improving visibility and reducing security gaps as a primary driver for cybersecurity platform consolidation.
40% of IT and IT security professionals characterize their SOC as very mature.
49% of IT and IT security professionals identify insufficient explainability as a key barrier to automation.
39% of IT and IT security professionals report that their SOC currently uses AI and/or machine learning to support detection, investigation and response.
38% of SOCs using AI have it fully integrated into existing SOC workflows and tooling.
39% of IT and IT security professionals identify limited visibility into the systems SOC teams oversee as a critical gap undermining SOC effectiveness.
37% of IT and IT security professionals identify lack of in-house expertise, including threat hunters and intelligence analysts, as a critical gap undermining SOC effectiveness.
Security Operations Centers (SOCs) manage an average of 2,566 alerts and incidents each day.
17% of IT and IT security professionals say their SOC is optimized for continuous improvement.
64% of IT and IT security professionals say identity visibility is very or extremely important to improving overall SOC effectiveness.
32% of IT and IT security professionals say identity events and privileged access events are centrally visible to their SOC.
51% of IT and IT security professionals at organizations with a SOC rate their SOC's ability to keep pace with the speed and sophistication of modern threats as effective or very effective.
46% of IT and IT security professionals identify insufficient staffing as a critical gap undermining SOC effectiveness.
52% of IT and IT security professionals report that alert and incident volumes have increased, with 23% reporting volumes have significantly increased and 29% reporting they have increased.