Cybersecurity 03 June 2026 Matas Bliudzius

Only 10% of Security Operations Centres Say They’re Getting Full Value — Here’s Why

Back to Blog

New research reveals that only 1 in 10 Security Operations Centres consider themselves to be getting full value from their security tooling and threat intelligence — a damning finding that points to a widespread crisis in how organisations defend themselves against cyber threats.

The State of the Modern SOC

Security Operations Centres are the frontline of enterprise cyber defence — the teams and systems responsible for monitoring, detecting, and responding to security incidents around the clock. In theory, a well-functioning SOC provides continuous visibility into an organisation’s threat landscape, enabling rapid detection and containment of attacks before they cause serious damage.

In practice, the research paints a starkly different picture. The overwhelming majority of SOC teams report that they are not operating at the effectiveness level they need to be — hampered by alert fatigue, tool sprawl, talent shortages, and threat intelligence that doesn’t translate into actionable insight.

Why SOCs Are Struggling

Alert Fatigue: Volume Without Value

The most consistently cited problem in SOC effectiveness research is alert volume. Modern security tooling — SIEM platforms, EDR solutions, network monitoring, cloud security posture management — generates enormous quantities of alerts. The majority of these are false positives or low-priority notifications that require manual review to dismiss.

When analysts spend the bulk of their time triaging noise, genuinely critical alerts get buried. Studies have consistently shown that SOC analysts miss or delay response to significant incidents not because they lacked the tools to detect them, but because the signal was lost in the noise. Burnout rates among SOC analysts are among the highest in the IT profession, driving high staff turnover and compounding the skills shortage.

Tool Sprawl and Integration Gaps

The average enterprise SOC now operates dozens of security tools — many of which were procured separately, integrate poorly with each other, and present data in incompatible formats. Analysts must pivot between multiple consoles to investigate a single incident, manually correlating data that ideally should be automatically linked.

This fragmentation means that the full context of an attack — which might span endpoint activity, network traffic, cloud API calls, and identity provider logs — is rarely visible in a single view. Attackers who understand this exploit the gaps between tools deliberately.

Threat Intelligence That Doesn’t Translate

Many organisations subscribe to threat intelligence feeds — data about known malicious IPs, domains, file hashes, and attack techniques. The challenge is operationalising this intelligence: translating it into detection rules, response playbooks, and prioritised alerts that actually reflect the threats most relevant to that specific organisation.

Generic threat intelligence feeds produce generic detections. The organisations getting the most value from threat intelligence are those that enrich it with context specific to their industry, geography, and technology stack — a capability that requires dedicated expertise most organisations don’t have in-house.

The Skills Shortage

The global cybersecurity skills shortage is acutely felt in SOC operations. Experienced SOC analysts — particularly those at Tier 2 and Tier 3 level who can investigate complex incidents and develop detection logic — are in short supply and high demand. Entry-level analysts can handle routine alerts but lack the expertise to identify sophisticated, multi-stage attacks that don’t trigger simple rule-based detections.

What the 10% Are Doing Differently

The minority of SOCs reporting high effectiveness share several common characteristics:

  • Automation-first alert triage: Using SOAR (Security Orchestration, Automation, and Response) platforms to automatically handle and close low-fidelity alerts, freeing analysts for genuinely suspicious activity
  • Threat-led detection engineering: Building detection logic based on specific threat actor techniques relevant to their industry (using frameworks like MITRE ATT&CK) rather than relying on vendor default rules
  • Integrated tooling: Investing in platforms that consolidate endpoint, network, identity, and cloud telemetry into a single investigation surface — reducing the context-switching burden on analysts
  • Regular purple team exercises: Proactively testing detection capabilities by simulating attacks and identifying gaps before real attackers do
  • Clear escalation and response playbooks: Reducing decision fatigue by giving analysts structured, pre-approved response actions for common incident types

What This Means for Smaller Organisations

For small and medium-sized businesses, the SOC effectiveness problem manifests differently — most don’t have a dedicated SOC at all. Security monitoring is often handled reactively, by generalist IT staff who lack the time or specialised skills to analyse security events proactively.

The practical implication is that many SMBs have limited visibility into attacks that are actively in progress on their networks. Threat actors targeting SMBs know this and exploit the detection gap — dwelling within compromised networks for weeks or months before triggering a ransomware event or data exfiltration.

Managed Detection and Response (MDR) services — where a specialist provider monitors your environment on your behalf — offer a practical alternative to building an in-house SOC. MDR providers bring pre-built detection logic, threat intelligence, and experienced analysts at a fraction of the cost of maintaining those capabilities internally.

How BIT Tech Approaches Security Monitoring

At BIT Tech IT Solutions, we help businesses implement practical security monitoring appropriate to their size and risk profile — from configuring endpoint detection and response tools correctly, to advising on managed security services that provide round-the-clock monitoring without the overhead of building an in-house capability.

If you’d like to discuss how to improve your organisation’s security visibility and detection capability, contact our team.