Organisations Are Identifying Cyber Threats More Effectively

The SANS Institute Threat Hunting Survey report concludes that organisations are beginning to find cyber threats more effectively.

However, whilst techniques, tools and the scope of threat hunting is expanding, the practice is still relatively poorly defined amongst IT professionals. Most organisations are still reacting to alerts and incidents, instead of proactively seeking out intruders.

Moving from reactive to proactive

The survey of 600 IT professionals globally reveals a change in mindset from the respondents of the 2017 survey — where many respondents indicated that their threat hunting methods centered completely on reactive indicators, instead of proactively seeking out threats, and identifying and counteracting adversaries who may already be in their environment.

The 2018 survey found that 43% of respondents now perform continuous and more accurate threat hunting operations, compared to just 35% in 2017.

According to SANS authors Rob M Lee and Rob T. Lee, this is a strong indicator that threat hunting is growing in scope and need. However, the survey also reveals that most organisations that are hunting, tend to be larger enterprises or those that have been heavily targeted in the past. At the same time, 37% of respondents are still only performing threat hunting if triggered by an event or an alarm.

“Threat hunting is part of nonstandard security operations. It’s a good combination of threat intelligence and hypothesis generation based on likely and probable locations of intrusions into a network. Once an organisation begins consuming threat intelligence, natural hunting begins to take place,” said Robert M. Lee, SANS certified instructor and co-author of the report.

Rob T. Lee, co-author and curriculum lead for digital forensic and incident response training, SANS Institute added: “One of the most notable highlights of the 2018 survey is that it demonstrates a more accurate use of threat hunting in many organisations. This change in threat hunting practices has increased since the last survey in 2017, which showed many organisations typically were hunting incorrectly through traditional intrusion detection. In this year’s survey, many more organisations were using proper threat intelligence to help identify the best locations inside an organisation’s network to look for anomalistic behaviours that are direct indicators of threats.”

The change in mindset regarding security is cause for hope.

As more organisations perform threat hunting, dwell time will shorten even more in the coming years. The survey indicates that dwell time currently averages above 90 days, but “as recently as 2013, the average dwell time was over six months. The decline since then shows that the adoption of threat hunting and stronger analytical techniques have had a significant impact on reducing the overall dwell time of adversaries across most networks.”

Other findings include:

• Tech versus people: Organisations are prioritising buying tools over developing a well-versed staff with the analytical skills to run effective threat hunting programs. 41% of respondents said technology was the most important area for threat hunting spend; just 30% said staff. This is interesting, as the majority of breaches are caused by human error. And, one of the main points to come out of Information Age’s Cyber Security Month, has related to the importance of security awareness training for all employees.

Automated threat hunting doesn’t exist, so while technology can help identify mistakes and achieve speed, it’s the skills of the human that will be able to minimise disruption and damage to the network.

• Weapon of choice: The top three skills valued in threat hunting team members included log analysis (83%), threat analysis and the use of threat intelligence (73%), and a knowledge of baseline network activity (72%). Threat intelligence and hunting must go hand in hand to work effectively. Intelligence is key to effective threat hunting and focusing on people and training are paramount for that effectiveness.

• Looking to the future: When asked what improvements would be required to improve threat hunting tools and capabilities, the most frequent responses were better investigative functions (59%), and more staff with investigative skills (also 59%). Both of the top options relate to the effectiveness and efficiency of staff, as well as an increasing need for skilled personnel.

Information Age:

You Might Also Read:

How to Measure Cybersecurity Success

« Reputational Damage & The Human Factor In Social Media
A Self-Flying AI-Powered Drone That Can Track You »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

IABG

IABG

IABG offer independent, product-neutral consulting as well as technical and scientific services for the use of safety-relevant systems and technologies.

4N6

4N6

4N6 is a privately-owned firm founded with the goal of providing expert knowledge of computer forensics.

The Security Awareness Company (SAC)

The Security Awareness Company (SAC)

The Security Awareness Company provides cyber security awareness training programs for companies of all sizes.

Sungard Availability Services (Sungard AS)

Sungard Availability Services (Sungard AS)

Sungard AS partners with customers around the globe to understand their unique business needs and provide production and recovery services tailored to their requirements.

Egyptian Supreme Cybersecurity Council (ESCC)

Egyptian Supreme Cybersecurity Council (ESCC)

ESCC is responsible for developing a national strategy to face and respond to the cyber threats and attacks and to oversee its implementation and update.

XLAB

XLAB

XLAB is an R&D company with a strong research background in the fields of distributed systems, cloud computing, security and dependability of systems.

National Cyber Security Agency (NACSA) - Malaysia

National Cyber Security Agency (NACSA) - Malaysia

NACSA is the leading government agency in Malaysia responsible for the development and implementation of national cyber security management policie and strategies.

Agility Networks

Agility Networks

Agility Networks is a technology company providing integrated services and solutions for Digital Transformation and Cyber Security.

CyberDegrees.org

CyberDegrees.org

CyberDegrees.org aims to provide top-notch information for students seeking Cyber Security education and career guidance.

Sevatec

Sevatec

Sevatec’s Active Cyber Defense (ACD) methodology proactively defends against adversarial kills chain, addressing active and emerging threats while reducing program vulnerabilities and risks.

Cyber Range Solutions (CRS)

Cyber Range Solutions (CRS)

CRS provides cyber security training and improve security team performance by providing a hyper realistic, virtual training environment.

Hyperion Gray

Hyperion Gray

Hyperion Gray are a small research and development team focused on innovative work in a variety of areas including Software & Security Research, Penetration Testing, Incident Response, and Red Teaming

North East Business Resilience Centre (NEBRC)

North East Business Resilience Centre (NEBRC)

The North East Business Resilience Centre is a non-profit organisation here to support businesses in the North East of England in protecting themselves from cyber crimes and fraud.

Difenda

Difenda

Difenda Shield is a fully integrated and modular cybersecurity suite that gives your organization the agility it needs to implement a world-class cybersecurity system.

Diverto

Diverto

Diverto is a company that provides a high level of information security to companies, institutions and other organisations in an information-centric world.

Pango

Pango

Pango is a leading provider of digital consumer security solutions.