New Study Reveals Nearly 40% of Security Threats Are Unmonitored for Effective Cyber Defense

New Research Highlights Critical Gaps in Cybersecurity Threat Detection



In a world increasingly dominated by digital threats, a recent report by Conifers, the creators of the CognitiveSOC™ agentic AI SOC platform, unveils stark insights into the cybersecurity landscape. Titled The Detection Blind Spot, the report analyzes over 14,000 detection incidents in enterprise environments, revealing that close to 40% of recognized cybersecurity threats remain inadequately monitored.

As the report suggests, traditional security measures are proving insufficient. Historically, the industry has equated the number of deployed detection tools and rules with effectiveness in combating cyber threats. However, Conifers points out that this assumption is misleading and conceals a more profound issue within threat detection systems.

The study found that while organizations have identified relevant threats, a staggering 37% remain without active defenses. Even when detection mechanisms are operational, only 63% of flagged threats had adequate monitoring in place. This discrepancy is alarming, particularly as adversaries become more sophisticated and capable of exploiting weaknesses at unprecedented speeds.

For many organizations, the reliance on outdated detection strategies—often involving manual adjustments and periodic reviews—has led to operational coverage that does not meet the evolving landscape of cyber threats. Notably, the report uncovered five primary issues affecting the functionality of detections:

1. Logic Flaws: Many detections are improperly coded, preventing effective alerts.
2. Missing Telemetry: Data streams that are crucial for detection either stop flowing or were never integrated into the system.
3. Incorrect Queries: Some queries are directed at the wrong data repositories, leading to missed alerts.
4. Duplicate Detections: Redundant alerts create confusion without enhancing coverage.
5. Noisy Detections: Many alerts are too frequent or imprecise, causing analysts to disregard them entirely.

According to Rutger de Boer, CTO at DTX, the challenge lies not just in the quality of detection rules but the underlying telemetry that often changes without notice, leaving outdated detections hanging without anyone realizing their ineffectiveness. This situation creates critical blind spots in security operations.

Conifers’ findings emphasize that the industry's method of counting detection rules can be misleading. CEO Tom Findling remarks, “Deployed does not mean protected,” indicating the need for a more comprehensive understanding of what effective threat coverage entails.

To combat these security gaps, the report outlines six key actions for security leaders:
  • - Measure threat coverage through active, verified detections tailored to their specific threats and techniques.
  • - Go beyond SIEM-focused health checks to encompass all vendor-managed detections.
  • - Develop a control system to optimize, deduplicate, and manage alerts before they reach analysts.
  • - Track the time taken between threat identification and the deployment of effective detections.
  • - Base threat hunting on exposure data, focusing on critical assets within organizations.
  • - Integrate verified findings from threat hunts into the overall detection architecture.

As organizations face the ever-evolving landscape of cyber warfare and agentic adversaries, the need for continuous, validated threat detection is crucial. The report suggests that to ensure effective protection, there needs to be a consolidation of threat intelligence, hunting, detection engineering, and operational response within a singular cohesive function.

For more insights, the full report, The Detection Blind Spot, is accessible through Conifers' website. As the digital threat landscape continues to transform, adopting these principles and improving detection mechanisms may be instrumental in fortifying defenses against future cyber threats.

Topics Other)

【About Using Articles】

You can freely use the title and article content by linking to the page where the article is posted.
※ Images cannot be used.

【About Links】

Links are free to use.