SIEMs only cover 19% of MITRE ATT&CK tactics.

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

CardinalOps Report: State of SIEM Detection Risk Highlights Mismatched Capabilities

CardinalOps recently released its State of SIEM Detection Risk report, shedding light on the current state of Security Information and Event Management (SIEM) systems. The report, which analyzed 3,000 detection rules and 1.2 million log sources, revealed that SIEMs only cover 19% of MITRE ATT&CK tactics, leaving a significant gap in security coverage.

Despite this finding, the report also highlighted that organizations have the potential to cover 87% of the techniques if utilized correctly. Key findings from the report include the increasing trend of multiple SIEM environments, with 43% of organizations now utilizing two or more SIEM systems. Additionally, 18% of SIEM rules were found to be broken, often due to missing fields and misconfigured data sources.

Security leaders in the industry weighed in on these findings, offering their insights and concerns. Adam Neel, Senior Threat Detection Engineer at Critical Start, expressed concerns over the complexity that multiple SIEM tools can bring, potentially leading to slower response times and misconfigured rules. Tamir Passi, Senior Product Director at DoControl, emphasized the gap between SIEM capabilities and actual detection coverage, advocating for purpose-built systems for improved detection. John Bambenek, President at Bambenek Consulting, highlighted the need for organizations to focus on foundational behaviors in detection rules rather than specific indicators.

Overall, the CardinalOps report serves as a wake-up call for organizations to reassess their SIEM strategies and ensure proper coverage of detection techniques to enhance their cybersecurity posture.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

GnuPG Vulnerability Allows Potential Bypass of Message Integrity Checks

GnuPG Vulnerability Allows Potential Bypass of Message Integrity Checks A recently discovered vulnerability in GnuPG has raised concerns regarding the integrity of messages encrypted with...

Russian National Indicted for Malware Campaign Infecting 80,000 Freelancers, Faces 20 Years in Prison

A Russian national has been indicted on multiple charges related to a malware campaign that infected the devices of over 80,000 individuals. Searzhudin Tamirlanovich...

GISEC Global 2026 to Host Cyber First Summit in Dubai, Addressing AI and Cybersecurity Challenges

The GISEC Global 2026 conference is set to take place from September 16 to 18 at the Dubai Exhibition Centre, Expo City Dubai, under...

Mirage Kitten Unveils NodeRabbit and PollCat, Its First Node.js and JavaScript Malware Families

Recent investigations into the activities of the cyber espionage group known as Mirage Kitten have revealed the emergence of two new malware families: NodeRabbit...