A Huntress survey of 1,050 IT and security professionals reveals that most security programs are built for outdated threat models focused on malware, while modern attackers exploit identity-based vectors like business email compromise, account takeover, and session hijacking. Key findings: most teams are small (6–15 people), budgets are generally adequate, but 64% of teams report over 25% of alerts are noise. The post argues resilience comes from auditing alert quality, treating identity as a primary attack surface, clarifying incident ownership, and using AI to reduce analyst burnout — not from buying more tools. A real-world SOC case study illustrates how human-led, AI-assisted identity threat detection stopped a multi-account compromise with no malware involved.

7m read timeFrom huntress.com
Post cover image
Table of contents
Key takeawaysThe teams behind the dataThe real problem is that security programs are built for yesterday's threatsReal-world incident: Identity threats in actionAI amplifies what lean teams can doWhat can you do right now to build a resilient team?