Nearly Half of Organizations Say Their SOCs Can't Keep Pace with Modern Threats
New research from Optiv and Palo Alto Networks reveals mounting pressure on security operations as rising threat volume and complexity drive adoption of AI, automation and platform consolidation
LEAWOOD, Kan., Sept. 22, 2026 /PRNewswire/ -- Optiv, the world's largest pure-play cybersecurity company, today published its 2026 Creating a Modern and Mature Security Operations Center (SOC) Report in partnership with Palo Alto Networks. The report examines why traditional SOC models struggle to keep up with increasingly sophisticated and stealthy cyber threats and identifies the strategies organizations are using to modernize security operations.
Based on independent research conducted by Ponemon Institute, the report finds that only 51% of respondents rate their SOC's ability to keep pace with the speed and sophistication of modern threats as effective or very effective.
The findings point to several critical gaps undermining SOC effectiveness, including:
Download the 2026 Creating a Modern and Mature Security Operations Center (SOC) Report from Optiv and Palo Alto Networks: https://www.optiv.com/insights/discover/downloads/creating-modern-and-mature-security-operations-center-soc
At the same time, SOC teams are contending with a growing volume of security alerts and incidents. More than half (52%) of respondents report that alert and incident volumes have either significantly increased (23%) or increased (29%), with SOCs managing an average of 2,566 alerts and incidents each day. Despite this mounting workload, organizations continue to investigate more than one-third (36%) of alerts and incidents through manual processes rather than automated workflows.
"The findings make clear that legacy approaches to security operations are no longer sufficient and can actually put organizations at greater risk," said Kathryn Hall, Optiv's senior vice president of services. "As threats become more sophisticated and alert volumes continue to rise, organizations need to modernize their SOCs with greater automation, intelligence and visibility. Doing so can help security teams move beyond simply managing alerts to proactively identifying and addressing the threats that matter most."
Additional key findings from the report include:
"Modernizing the SOC is no longer about adding more tools or asking analysts to work faster," said Kasey Cross, director of product marketing, Cortex XSIAM at Palo Alto Networks. "It requires a fundamentally different operating model, one built around agentic AI, automation, consolidated data and measurable outcomes. The organizations moving fastest in this direction are creating more proactive and resilient security operations, but the findings show there is still a long way to go."
The report findings are based on responses from 574 IT and IT security professionals at organizations with a SOC and who are knowledgeable about its operations.
For the latest news and updates from Optiv, visit https://www.optiv.com/newsroom.
About Optiv Security: Secure greatness. ®
Optiv is the world's largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.
More Ways to Engage:
Follow Optiv on LinkedIn
Subscribe to the Cyber Landscape Newsletter
Explore Insights and Blogs
View our Newsroom
SOURCE Optiv Security Inc.