Report by Splunk

State of Security 2025: The Stronger, Smarter SOC of the Future

22 FINDINGSPublished May 20, 2025
View Original Report →

Key Findings

52% of respondents say their team is overworked.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Security team

43% of respondents face unrealistic expectations by leadership.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Talent

57% of respondents report losing valuable investigation time to data management gaps.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Data management

Nearly half (46%) of respondents spend more time maintaining tools than defending the organization.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Security tools

59% of organizations have moderately or significantly boosted their efficiency with AI.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AI

78% of respondents say sharing data with observability teams resolves incidents faster.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Data

Over half (56%) of respondents have prioritized the application of AI to security workflows this year.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AI

31% of SOCs are using GenAI for Querying security data.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AIGen AI

52% of respondents say stress on the job has prompted them to think about leaving cybersecurity altogether.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
StressTalent

66% of organizations experienced a data breach in the past year, making it the most common security incident.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Data breach

29% of SOCs are using GenAI for Writing/editing security policies.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AIGen AISOC

78% of respondents say their security tools are dispersed and disconnected.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Security tools

Only 11% of organizations fully trust AI for mission-critical tasks.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AI

78% of respondents cited faster incident detection as a moderate to transformative benefit of a unified approach for threat detection and response.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Incident detectionThreat detection and responseUnified approach

66% of respondents noted quicker remediation as a moderate to transformative benefit of a unified approach for threat detection and response

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
RemediationThreat detection and responseUnified approach

59% of respondents report having too many alerts.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AlertsAlert fatigue

33% of SOCs are using GenAI for Threat intelligence analysis.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AIGen AIThreat intelligence

1 in 3 (33%) of respondents plan to fill skills gaps with AI and automation.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AIAutomationSkills gap

Compared to publicly available tools, 63% agree that domain-specific AI significantly or extremely enhances security operations.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AI

59% of respondents say tool maintenance is the main source of inefficiency.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Security tools

69% say disconnected and dispersed tools creates moderate to significant challenges.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
Security tools

55% of respondents report having to address too many false positives.

SplunkState of Security 2025: The Stronger, Smarter SOC of the Future ·May 20, 2025
AlertsFalse positives