SIEMs only cover 19% of MITRE ATT&CK tactics.

Published:

spot_img

CardinalOps Report: State of SIEM Detection Risk Highlights Mismatched Capabilities

CardinalOps recently released its State of SIEM Detection Risk report, shedding light on the current state of Security Information and Event Management (SIEM) systems. The report, which analyzed 3,000 detection rules and 1.2 million log sources, revealed that SIEMs only cover 19% of MITRE ATT&CK tactics, leaving a significant gap in security coverage.

Despite this finding, the report also highlighted that organizations have the potential to cover 87% of the techniques if utilized correctly. Key findings from the report include the increasing trend of multiple SIEM environments, with 43% of organizations now utilizing two or more SIEM systems. Additionally, 18% of SIEM rules were found to be broken, often due to missing fields and misconfigured data sources.

Security leaders in the industry weighed in on these findings, offering their insights and concerns. Adam Neel, Senior Threat Detection Engineer at Critical Start, expressed concerns over the complexity that multiple SIEM tools can bring, potentially leading to slower response times and misconfigured rules. Tamir Passi, Senior Product Director at DoControl, emphasized the gap between SIEM capabilities and actual detection coverage, advocating for purpose-built systems for improved detection. John Bambenek, President at Bambenek Consulting, highlighted the need for organizations to focus on foundational behaviors in detection rules rather than specific indicators.

Overall, the CardinalOps report serves as a wake-up call for organizations to reassess their SIEM strategies and ensure proper coverage of detection techniques to enhance their cybersecurity posture.

spot_img

Related articles

Recent articles

Webinar: Uncovering Suspicious APK Files in Wedding Card and Loan App Scams

The surge of malicious APK files in cyber fraud schemes, such as fake wedding invitations and instant loan applications, has become a growing concern....

Skylon Partners with COBNB to Launch COBNB+ Featuring L’Occitane en Provence Hotel Amenities

Skylon Partners with COBNB for a Luxurious Hospitality Experience in Kuala Lumpur Introduction to the New Partnership In an exciting development for the hospitality scene in...

Understanding CISA KEV: Key Insights and Tools for Security Teams

Understanding the CISA Known Exploited Vulnerability (KEV) Catalog The Cybersecurity and Infrastructure Security Agency (CISA) maintains the Known Exploited Vulnerability (KEV) catalog, a resource designed...

Dark Web Leak Sparks WFH Job Scams; Prayagraj Police Freeze ₹2 Crore in Fraudulent Funds

Rising Cybercrime in Prayagraj: A New Target Shifting Tactics of Cybercriminals In Prayagraj, the landscape of cybercrime is evolving. Previously, scammers predominantly targeted victims through enticing...