STOCK TITAN

Global State of Security Report Reveals Critical Need for Connected Security Operations

Rhea-AI Impact
(Low)
Rhea-AI Sentiment
(Neutral)
Tags
Splunk's State of Security 2025 report reveals significant challenges in cybersecurity operations. Only 11% of organizations fully trust AI for critical tasks, while 46% spend more time on tool maintenance than defense. Key findings show 66% experienced data breaches in the past year. The report highlights operational inefficiencies with 78% reporting dispersed security tools and 69% facing challenges from disconnected systems. SOC teams are struggling with 52% reporting overwork and considering leaving the field. Despite challenges, 59% report improved efficiency with AI adoption, with top applications in threat intelligence analysis (33%), security data querying (31%), and policy writing (29%). Organizations implementing unified security approaches report faster incident detection (78%) and quicker remediation (66%).
Il rapporto State of Security 2025 di Splunk evidenzia sfide significative nelle operazioni di cybersecurity. Solo l'11% delle organizzazioni si fida completamente dell'IA per compiti critici, mentre il 46% dedica più tempo alla manutenzione degli strumenti che alla difesa. I dati mostrano che il 66% ha subito violazioni dei dati nell'ultimo anno. Il report sottolinea inefficienze operative, con il 78% che segnala strumenti di sicurezza dispersi e il 69% che affronta difficoltà dovute a sistemi disconnessi. I team SOC sono sotto pressione: il 52% dichiara sovraccarico di lavoro e sta valutando di lasciare il settore. Nonostante ciò, il 59% riporta un miglioramento dell'efficienza grazie all'adozione dell'IA, con le applicazioni principali nell'analisi delle informazioni sulle minacce (33%), interrogazioni sui dati di sicurezza (31%) e scrittura delle policy (29%). Le organizzazioni che adottano approcci di sicurezza unificati segnalano una rilevazione degli incidenti più rapida (78%) e una risoluzione più veloce (66%).
El informe State of Security 2025 de Splunk revela desafíos importantes en las operaciones de ciberseguridad. Solo el 11% de las organizaciones confía plenamente en la IA para tareas críticas, mientras que el 46% dedica más tiempo al mantenimiento de herramientas que a la defensa. Los hallazgos clave muestran que el 66% experimentó brechas de datos en el último año. El informe destaca ineficiencias operativas, con un 78% que reporta herramientas de seguridad dispersas y un 69% que enfrenta desafíos por sistemas desconectados. Los equipos SOC están en dificultades: el 52% reporta sobrecarga de trabajo y considera dejar el campo. A pesar de los desafíos, el 59% informa una mejora en la eficiencia con la adopción de IA, con aplicaciones principales en análisis de inteligencia de amenazas (33%), consultas de datos de seguridad (31%) y redacción de políticas (29%). Las organizaciones que implementan enfoques de seguridad unificados reportan detección de incidentes más rápida (78%) y remediación más ágil (66%).
Splunk의 State of Security 2025 보고서는 사이버 보안 운영에서 중요한 도전 과제를 드러냅니다. 단지 11%의 조직만이 중요한 업무에 AI를 완전히 신뢰하며, 46%는 방어보다 도구 유지 관리에 더 많은 시간을 할애하고 있습니다. 주요 결과에 따르면 66%가 지난 해 데이터 유출을 경험했습니다. 보고서는 78%가 분산된 보안 도구를 사용하고 있으며, 69%는 연결되지 않은 시스템으로 인한 문제를 겪고 있다고 지적합니다. SOC 팀은 과로 상태에 있으며 52%가 과중한 업무로 인해 업계를 떠날 것을 고려하고 있습니다. 어려움에도 불구하고 59%는 AI 도입으로 효율성이 향상되었다고 보고하며, 주요 활용 분야는 위협 인텔리전스 분석(33%), 보안 데이터 쿼리(31%), 정책 작성(29%)입니다. 통합 보안 접근 방식을 도입한 조직은 더 빠른 사고 탐지(78%)와 신속한 대응(66%)을 보고하고 있습니다.
Le rapport State of Security 2025 de Splunk révèle des défis majeurs dans les opérations de cybersécurité. Seules 11% des organisations font entièrement confiance à l'IA pour des tâches critiques, tandis que 46% passent plus de temps à la maintenance des outils qu'à la défense. Les principales conclusions montrent que 66% ont subi des violations de données au cours de l'année écoulée. Le rapport souligne des inefficacités opérationnelles, avec 78% signalant des outils de sécurité dispersés et 69% rencontrant des difficultés dues à des systèmes déconnectés. Les équipes SOC sont en difficulté : 52% déclarent être surchargées de travail et envisagent de quitter le domaine. Malgré ces défis, 59% rapportent une amélioration de l'efficacité grâce à l'adoption de l'IA, avec des applications principales dans l'analyse du renseignement sur les menaces (33%), les requêtes de données de sécurité (31%) et la rédaction de politiques (29%). Les organisations qui mettent en œuvre des approches de sécurité unifiées signalent une détection plus rapide des incidents (78%) et une résolution plus rapide (66%).
Der Bericht State of Security 2025 von Splunk zeigt erhebliche Herausforderungen im Bereich der Cybersicherheitsoperationen auf. Nur 11% der Organisationen vertrauen KI vollständig für kritische Aufgaben, während 46% mehr Zeit für die Wartung von Tools als für die Verteidigung aufwenden. Wichtige Erkenntnisse zeigen, dass 66% im vergangenen Jahr Datenverletzungen erlitten haben. Der Bericht hebt betriebliche Ineffizienzen hervor, wobei 78% über verstreute Sicherheitstools berichten und 69% Herausforderungen durch nicht verbundene Systeme haben. SOC-Teams kämpfen: 52% berichten von Überlastung und denken darüber nach, den Bereich zu verlassen. Trotz der Herausforderungen berichten 59% von verbesserten Effizienzen durch KI-Einsatz, mit den wichtigsten Anwendungen in der Bedrohungsanalyse (33%), Sicherheitsdatenabfragen (31%) und Richtlinienerstellung (29%). Organisationen, die einheitliche Sicherheitsansätze umsetzen, berichten von schnellerer Vorfallserkennung (78%) und schnellerer Behebung (66%).
Positive
  • None.
Negative
  • 66% experienced data breaches in the past year
  • 46% spend more time maintaining tools than defending systems
  • 52% of security teams are overworked and considering leaving the field
  • 78% report dispersed and disconnected security tools
  • 59% lose valuable investigation time to data management gaps
  • Only 11% fully trust AI for mission-critical tasks

Insights

Splunk's security report reveals critical industry pain points, reinforcing Cisco's strategic acquisition value, though challenges in AI adoption persist.

Splunk's State of Security 2025 report provides valuable insights into the current cybersecurity landscape and validates Cisco's $28 billion acquisition of the company last year. The findings highlight three critical market opportunities that directly align with Cisco's integration strategy.

First, the report reveals significant operational inefficiencies plaguing security teams - 46% of respondents spend more time maintaining tools than defending organizations, while 78% report dispersed and disconnected security tools. This creates a compelling case for Cisco's integrated security architecture approach that combines Splunk's data analytics with Cisco's network security portfolio.

Second, the cautious AI adoption (only 11% fully trust AI for mission-critical tasks) presents both a challenge and opportunity. While organizations recognize AI's potential with 59% reporting efficiency gains, the hesitancy suggests Cisco must carefully position its AI security offerings with strong validation frameworks. The most common AI applications currently focus on threat intelligence analysis (33%) and data querying (31%), aligning perfectly with Splunk's core capabilities.

Finally, the human resource challenges illustrated by 52% of teams feeling overworked creates a market demand for solutions that reduce analyst burnout. Cisco's combined portfolio now has the potential to address this through automation while maintaining human oversight.

The data connecting security and observability teams is particularly noteworthy - 78% of organizations report faster incident detection when these teams share information. This validates Cisco's strategic vision of unifying network operations, security operations, and observability through the Splunk acquisition. The 66% data breach rate among respondents also underscores the urgency and market demand for improved security solutions.

  • Security remains a key focus as organizations cautiously approach AI, with only 11% fully trusting it for mission-critical tasks
  • Nearly half (46%) spend more time maintaining tools than defending the organization
  • 78% say sharing data with observability teams resolves incidents faster

SAN FRANCISCO, May 20, 2025 /PRNewswire/ -- Splunk, the cybersecurity and observability leader, today released its "State of Security 2025" global research report, highlighting the mounting challenges faced by Security Operations Centers (SOCs). The report uncovers the pain points that mire down organizations and open their doors to threats 46% of respondents said they spend more time maintaining tools than defending the organization, while only 11% trust AI completely for mission-critical tasks. Furthermore, 66% experienced a data breach in the past year, making it the most common security incident.

With new threats such as AI-powered attacks, organizations must be fully prepared and confident in protecting themselves and their customers. The common thread in addressing these concerns is to build a unified SOC that combines human expertise with AI advancements.

"Organizations are increasingly leaning on AI for threat hunting and detection, and other mission-critical tasks, but we don't see AI taking complete oversight of the SOC – for good reason," says Michael Fanning, CISO at Splunk. "Human oversight remains central to effective cybersecurity, and AI is used to enhance human capabilities to help where it truly matters: defending the organization."

"As cyber threats grow in volume and sophistication, security teams are under constant pressure," said Nate Lesser, CISO at Children's National Hospital. "According to Splunk's State of Security report, the industry is struggling with escalating workloads, alert fatigue, and a shortage of skilled talent. Integrating AI and automation helps us address these risks and empowers our teams with smarter tools to ensure our organization remains resilient."

Security teams plagued by technological inefficiencies while external threats increase
When SOC workflows aren't operating at their peak, it creates major barriers to effective threat detection and response. The report highlights areas of inefficiencies that create risk for organizations:

  • 59% say tool maintenance is the main source of inefficiency
  • 78% say their security tools are dispersed and disconnected
  • 69% say disconnected and dispersed tools creates moderate to significant challenges

Tool maintenance, data silos, and alert fatigue bog down SOC teams. These day-to-day burdens drain valuable time and impact an analyst's ability to respond quickly and decisively. The report revealed:

  • 57% report losing valuable investigation time to data management gaps
  • 59% have too many alerts
  • 55% have to address too many false positives

SOC analysts are overworked and understaffed
Beyond operational hurdles, the report sheds light on the immense pressure for SOC analysts. High stress levels, chronic understaffing, and burnout are taking a toll and put talent retention and long-term team stability at risk. Findings show that:

  • 52% say their team is overworked
  • 52% say stress on the job has prompted them to think about leaving cybersecurity altogether
  • 43% face unrealistic expectations by leadership

GenAI in the SOC is paying long-term dividends for organizations
Organizations see how AI can alleviate operational and staff shortage problems, as 59% have moderately or significantly boosted their efficiency with AI. Over half (56%) have prioritized the application of AI to security workflows this year, while 1 in 3 (33%) plan to fill skills gaps with AI and automation.

Compared to publicly available tools, 63% agree that domain-specific AI significantly or extremely enhances security operations. However, AI is not running solo as organizations keep humans in the loop to deliver trustworthy AI outcomes. The top three tasks that GenAI is helping across SOCs included:

  • Threat intelligence analysis (33%)  
  • Querying security data (31%)
  • Writing/editing security policies (29%)

A unified approach accelerates operations
Minimizing tool maintenance is just the starting point for the benefits of a unified security platform. Adopting a unified approach for threat detection and response leads to tighter collaboration, bringing more context and speed to investigations. Sharing information across security and observability isn't fully embraced yet, but those who have made the leap report noteworthy advantages. Specifically, 78% of respondents cited faster incident detection, and 66% noted quicker remediation as moderate to transformative benefits.

To learn more and see the full findings, download the 2025 State of Security Report here.

Methodology
In collaboration with Oxford Economics, researchers surveyed 2,058 security leaders (including directors of security, vice presidents of cybersecurity, directors of security operations, and security analysts) October 2024 through December 2024. Respondents were in Australia, France, Germany, India, Japan, New Zealand, Singapore, United Kingdom and United States. They also represented 16 industries: Business services, construction and engineering, consumer packaged goods, education, financial services, government (federal/national, state, and local), healthcare, life sciences, manufacturing, technology, media, oil/gas, retail/wholesale, telecom, transportation/logistics, and utilities.

About Splunk LLC
Splunk, a Cisco company, helps build a safer and more resilient digital world. Organizations trust Splunk to prevent security, infrastructure and application issues from becoming major incidents, absorb shocks from digital disruptions, and accelerate digital transformation.

Splunk and the Splunk> logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. A listing of Cisco's trademarks can be found at http://www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word "'partner"' does not imply a partnership relationship between Cisco or its affiliates and any other company.

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/global-state-of-security-report-reveals-critical-need-for-connected-security-operations-302460307.html

SOURCE Cisco Systems, Inc.

FAQ

What are the key findings from Splunk's 2025 State of Security Report?

The report reveals that 66% experienced data breaches, 46% spend more time on tool maintenance than defense, and only 11% fully trust AI for critical tasks. Additionally, 78% report dispersed security tools and 52% of teams are overworked.

How are organizations using AI in their security operations according to the report?

Organizations are primarily using AI for threat intelligence analysis (33%), querying security data (31%), and writing/editing security policies (29%). 59% report improved efficiency through AI implementation.

What are the main challenges facing Security Operations Centers (SOCs) in 2025?

Main challenges include tool maintenance inefficiencies (46%), dispersed and disconnected tools (78%), data management gaps (59%), alert fatigue (55%), and staff burnout with 52% considering leaving the field.

What benefits are organizations seeing from unified security approaches?

Organizations implementing unified security approaches report 78% faster incident detection and 66% quicker remediation through improved information sharing and collaboration.

How widespread is AI adoption in cybersecurity operations?

56% of organizations have prioritized AI application in security workflows, with 33% planning to fill skills gaps using AI and automation. However, only 11% fully trust AI for mission-critical tasks.
Cisco Sys Inc

NASDAQ:CSCO

CSCO Rankings

CSCO Latest News

CSCO Latest SEC Filings

CSCO Stock Data

271.51B
3.95B
0.07%
80.82%
1.2%
Communication Equipment
Computer Communications Equipment
Link
United States
SAN JOSE