Threat Detection Dashboards Can Hide Security Coverage Gaps

Summary
Conifers assessed 14,652 detections and found that 47% in the average organization need attention. Organizations averaged 63% coverage of relevant threats and 64% protection for relevant MITRE ATT&CK techniques.
Key points
- Conifers reviewed 14,652 customer detections across SIEM, endpoint, cloud, identity, email and network tools.
- In the average organization, 47% of detections needed attention, despite appearing deployed on coverage dashboards.
- Reported failure causes include logic bugs, missing telemetry, querying the wrong data source, duplicate rules and excessive false alerts.
- Vendor-managed detections can be difficult for security teams to inspect or edit, forcing a choice between tolerating noisy alerts and suppressing them.
- Organizations had detections, hunts or compensating visibility for an average of 63% of threats their own intelligence identified as relevant.
- Average protection covered 64% of relevant MITRE ATT&CK techniques, leaving about one-third without reliable detection. The article advocates automating parts of the threat-intelligence-to-detection process with AI.
Article Details
- Publisher
- Help Net Security
- Scope
- Conifers assessment of customer detections across SIEM, endpoint, cloud, identity, email, and network tools.
- Sample Size
- 14,652 detections in Conifers' customer base; number of organizations not disclosed.
- Key Statistics
- Conifers found that 47% of detections in the average organization needed attention.
- Organizations averaged coverage for 63% of threats their own intelligence identified as relevant.
- Average protection was 64% for MITRE ATT&CK techniques relevant to each organization.
- Recommendations
- Continuously test whether deployed detections work, including whether required telemetry is available.
- Identify threats without matching detections, hunts, or compensating visibility.
- Connect threat intelligence to detection and hunting workflows to reduce the delay between identifying a threat and establishing coverage.