The SANS 2026 Detection Engineering Survey, conducted in partnership with Anvilogic, paints a sobering picture of the state of defensive security operations. Surveying 307 practitioners across more than 10 industries, the report finds that only 18% of detection engineers report staying ahead of emerging threats — despite the explosion of AI tooling and automation in the SOC.

The headline finding is a stark trust gap: while 83% of practitioners now use AI tools in their detection workflows, only 42% trust those tools for critical tasks like tuning detections. The survey also identifies cloud-native environments as the number one detection coverage gap, cited by 43% of organizations — more than 2.5 times any other environment category.

Beyond AI trust and cloud gaps, the survey explores how organizations are adopting Detection-as-Code approaches, automating workflows, and staffing their detection engineering programs. It highlights persistent challenges around skills shortages, tooling fragmentation, and the difficulty of keeping detection content current against a rapidly evolving threat landscape.

Sources

Commentary

The trust gap between AI adoption and AI confidence is the real story here. Security teams are using AI because they have to — the volume and velocity of threats demand it — but they don’t trust it where it matters most. When only 42% trust AI for tuning detections, it means the majority are still manually reviewing and validating AI-generated output, which undermines the efficiency gains that drove adoption in the first place.

The cloud detection gap is equally concerning but less surprising. Cloud-native environments are dynamic, ephemeral, and architecturally different from traditional infrastructure, yet many detection programs were built for on-prem paradigms. The 43% figure is a clear signal that the industry’s detection capabilities haven’t kept pace with its cloud migration. For security leaders, this survey is a useful benchmark — and a wake-up call that throwing AI at the problem isn’t enough without the trust, training, and cloud-native detection content to back it up.

By Allan