A Huntress survey of 1,050 IT and security professionals reveals that most security programs are built for outdated threat models focused on malware, while modern attackers exploit identity-based vectors like business email compromise, account takeover, and session hijacking. Key findings: most teams are small (6–15 people), budgets are generally adequate, but 64% of teams report over 25% of alerts are noise. The post argues resilience comes from auditing alert quality, treating identity as a primary attack surface, clarifying incident ownership, and using AI to reduce analyst burnout — not from buying more tools. A real-world SOC case study illustrates how human-led, AI-assisted identity threat detection stopped a multi-account compromise with no malware involved.