Newsletter Article – SPECIAL CYBERSECURITY AWARENESS MONTH

THREAT SPOTLIGHT:The Investigation Gap

Snare Insider Newsletter Series Article

Make sure you Subscribe

This month we keep coming back to evidence: what gets collected, what gets retained, what’s still there when an investigation starts. That’s the right starting point. It’s not the whole problem.

A growing body of 2026 research points at a second, quieter constraint sitting right behind it: even organisations with good evidence are struggling to integrate it into something an investigation can actually use. Call it the investigation gap — the widening distance between how much security teams collect and how much of it is genuinely askable when it matters.

What the research says

Finding Source
The leading barrier practitioners report to SOC effectiveness: too many uncorrelated alerts, too many unintegrated tools, and not enough context to act on either SANS 2026 SOC Survey, June 2026 (444 practitioners, 69 cyber leaders)
79% of SOCs already use AI or machine learning somewhere in their operations; only 36% have integrated it into a defined SOC workflow SANS 2026 SOC Survey, June 2026
24% of cyber leaders name enterprise-wide visibility as the single biggest barrier to SOC effectiveness — the top-ranked answer SANS 2026 SOC Survey, June 2026
70% of large SOCs are expected to be piloting AI agents for Tier 1 and Tier 2 operations by 2028 — but only 15% will achieve measurable improvement without structured evaluation first Gartner, “Validate the Promises of AI SOC Agents With These Key Questions,” Craig Lawson and Andrew Davies, 2026
59% of security teams report critical or significant skills needs, up from 44% in 2024 — AI/ML and cloud security are the two largest gaps ISC2 2025 Cybersecurity Workforce Study, December 2025 (16,029 respondents)

Read the first three rows together and a shape appears. SOC teams aren’t short of alerts or short of tools — if anything they have too many of both, which is SANS’s own description of the top barrier practitioners report.

What’s missing is integration and context: four in five teams already have AI or machine learning somewhere in the stack, but barely a third have built it into how an investigation actually runs, and under a quarter say they have the enterprise-wide visibility to ask a question across the whole environment at once.

Gartner’s caution about AI SOC agents lands in the same place from a different angle. Most large SOCs will be piloting one within two years, and Gartner’s own analysts expect roughly 85% of those pilots to show no measurable improvement because sitting an agent on top of an uncorrelated, fragmented evidence base doesn’t fix the fragmentation. It just automates the fragmentation faster.

ISC2’s numbers explain why that fragmentation persists. The shortage has moved, it’s a skills gap now more than a headcount gap, and the two largest deficits, AI/ML and cloud security, are exactly the skills a modern, integrated investigation increasingly depends on.

Why this is a different problem to “do you have the logs”

Every incident in this week’s Global Cyber Threat Pulse was, in principle, answerable from evidence that existed somewhere — a vendor’s access log, a VPN session record, an email-authorisation trail, an API’s request history. None of those investigations failed because the evidence didn’t exist. Where they were slow, they were slow because finding, correlating and interpreting that evidence took time — across sources that, per SANS, most teams still haven’t integrated and in most cases can’t see across all at once.

Retention solves “does the evidence still exist.” It doesn’t solve “can someone find and use it, correlated, in the time an investigation actually has.” Those are two different engineering problems, and most logging strategies are built to solve only the first one.

Where the investigation gap actually bites

Four ordinary investigative questions, and what makes each one slow in a typical environment today — not because the data is missing, but because of what it takes to reach it.

The question Why it’s slow today
“Has this account done this anywhere else in the last 90 days?” Means hand-written queries across identity, endpoint and SaaS logs, each in its own query language, then manually reconciling the results
“Did we see this indicator anywhere before the alert fired?” Means knowing which of a dozen possible sources to search, then searching each one separately, because there’s no single place to ask the question once
“What changed on this host immediately before and after the event?” Means correlating timestamps across systems that don’t log time the same way, by hand, under time pressure
“Is this pattern happening anywhere else in the environment right now?” Means rebuilding and re-running the same search across every relevant source and host, because yesterday’s query doesn’t travel to today’s question

None of those four questions are exotic. They’re the questions any analyst asks in the first ten minutes of a real investigation — and in most environments, each one still has to be hand-translated into platform-specific syntax, source by source, before it can even be asked.

Closing the gap takes more than retention

Three things have to be true at once for an investigation to keep pace with what SANS describes as the modern SOC’s actual condition, too many alerts, too many disconnected tools, not enough shared context. The evidence has to be collected and retained — the problem we’ve spent most of this month on. It has to be correlated and queryable in something closer to plain language than six different query syntaxes, so the analyst asking “has this account done this anywhere else” doesn’t need to be a specialist in every source it touches.

And, per Gartner’s own caution, that querying layer has to sit on top of evidence that’s already integrated, not be asked to paper over fragmentation it had no part in fixing.

That third piece is where we’re taking this newsletter later in the month — including a first full look at AskSnare, built on top of an evidence layer that’s already collected, normalised and correlated, specifically to close the distance between asking an investigative question and getting an answer. Not a replacement for analyst judgement, and not the kind of bolted-on AI SOC agent Gartner is cautioning against — a way of turning the four questions above into something askable in the time an analyst actually has.

Source: SANS 2026 SOC Survey, June 2026; Gartner, “Validate the Promises of AI SOC Agents With These Key Questions,” 2026; ISC2 2025 Cybersecurity Workforce Study, December 2025

Snare Solutions
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.