Newsletter Article – SPECIAL CYBERSECURITY AWARENESS MONTH
THREAT SPOTLIGHT:The Investigation Gap
Snare Insider Newsletter Series Article
Make sure you Subscribe
A growing body of 2026 research points at a second, quieter constraint sitting right behind it: even organisations with good evidence are struggling to integrate it into something an investigation can actually use. Call it the investigation gap — the widening distance between how much security teams collect and how much of it is genuinely askable when it matters.
| Finding | Source |
| The leading barrier practitioners report to SOC effectiveness: too many uncorrelated alerts, too many unintegrated tools, and not enough context to act on either | SANS 2026 SOC Survey, June 2026 (444 practitioners, 69 cyber leaders) |
| 79% of SOCs already use AI or machine learning somewhere in their operations; only 36% have integrated it into a defined SOC workflow | SANS 2026 SOC Survey, June 2026 |
| 24% of cyber leaders name enterprise-wide visibility as the single biggest barrier to SOC effectiveness — the top-ranked answer | SANS 2026 SOC Survey, June 2026 |
| 70% of large SOCs are expected to be piloting AI agents for Tier 1 and Tier 2 operations by 2028 — but only 15% will achieve measurable improvement without structured evaluation first | Gartner, “Validate the Promises of AI SOC Agents With These Key Questions,” Craig Lawson and Andrew Davies, 2026 |
| 59% of security teams report critical or significant skills needs, up from 44% in 2024 — AI/ML and cloud security are the two largest gaps | ISC2 2025 Cybersecurity Workforce Study, December 2025 (16,029 respondents) |
Read the first three rows together and a shape appears. SOC teams aren’t short of alerts or short of tools — if anything they have too many of both, which is SANS’s own description of the top barrier practitioners report.
What’s missing is integration and context: four in five teams already have AI or machine learning somewhere in the stack, but barely a third have built it into how an investigation actually runs, and under a quarter say they have the enterprise-wide visibility to ask a question across the whole environment at once.
Gartner’s caution about AI SOC agents lands in the same place from a different angle. Most large SOCs will be piloting one within two years, and Gartner’s own analysts expect roughly 85% of those pilots to show no measurable improvement because sitting an agent on top of an uncorrelated, fragmented evidence base doesn’t fix the fragmentation. It just automates the fragmentation faster.
ISC2’s numbers explain why that fragmentation persists. The shortage has moved, it’s a skills gap now more than a headcount gap, and the two largest deficits, AI/ML and cloud security, are exactly the skills a modern, integrated investigation increasingly depends on.
Four ordinary investigative questions, and what makes each one slow in a typical environment today — not because the data is missing, but because of what it takes to reach it.
| The question | Why it’s slow today |
| “Has this account done this anywhere else in the last 90 days?” | Means hand-written queries across identity, endpoint and SaaS logs, each in its own query language, then manually reconciling the results |
| “Did we see this indicator anywhere before the alert fired?” | Means knowing which of a dozen possible sources to search, then searching each one separately, because there’s no single place to ask the question once |
| “What changed on this host immediately before and after the event?” | Means correlating timestamps across systems that don’t log time the same way, by hand, under time pressure |
| “Is this pattern happening anywhere else in the environment right now?” | Means rebuilding and re-running the same search across every relevant source and host, because yesterday’s query doesn’t travel to today’s question |
None of those four questions are exotic. They’re the questions any analyst asks in the first ten minutes of a real investigation — and in most environments, each one still has to be hand-translated into platform-specific syntax, source by source, before it can even be asked.
Three things have to be true at once for an investigation to keep pace with what SANS describes as the modern SOC’s actual condition, too many alerts, too many disconnected tools, not enough shared context. The evidence has to be collected and retained — the problem we’ve spent most of this month on. It has to be correlated and queryable in something closer to plain language than six different query syntaxes, so the analyst asking “has this account done this anywhere else” doesn’t need to be a specialist in every source it touches.
And, per Gartner’s own caution, that querying layer has to sit on top of evidence that’s already integrated, not be asked to paper over fragmentation it had no part in fixing.
That third piece is where we’re taking this newsletter later in the month — including a first full look at AskSnare, built on top of an evidence layer that’s already collected, normalised and correlated, specifically to close the distance between asking an investigative question and getting an answer. Not a replacement for analyst judgement, and not the kind of bolted-on AI SOC agent Gartner is cautioning against — a way of turning the four questions above into something askable in the time an analyst actually has.
Source: SANS 2026 SOC Survey, June 2026; Gartner, “Validate the Promises of AI SOC Agents With These Key Questions,” 2026; ISC2 2025 Cybersecurity Workforce Study, December 2025

Snare Insider Issue #15 – Oct 2026