Skip to main content
Cybersecurity

Data Quality Overtakes Skills as Top Threat Hunting Barrier

Cybersecurity practitioner surrounded by cluttered workstation and tangled data cables.

“You can be the most capable hunter in the room and still come up empty if the telemetry you're working with is incomplete, inconsistent, or scattered across a dozen tools that are difficult to access or difficult to process,” SANS principal instructor and report author Josh Lemon warned.

Data volume and quality now the top barrier

For the first time in five years of SANS Institute polling, data — not skills — sits atop the list of obstacles for threat hunting. In a survey of 500 cybersecurity practitioners and leaders across North America, Europe, Latin America and Asia, 50% of respondents named data quality or quantity as their single biggest hurdle, up from 41% a year earlier and 34% in 2023. “The direction of that trend suggests that the volume of data flowing into hunting programs is now creating as many problems as it solves, with normalization and standards lagging behind collection,” the report noted. The same survey also recorded lack of data standards as a separate concern for 39% of respondents.

Skills shortages have eased but still reshape who hunts

Skilled staff remained a major constraint but declined in prominence: 45% of respondents cited skills shortages this year, down from 61% last year. SANS framed that improvement as progress while cautioning about the operational consequences: skills shortages mean fewer hunts get run, and those that do “lean more heavily on whoever happens to be available rather than whoever is best placed to construct the hypothesis.” The programs themselves are not green—over 80% of respondents said they have been hunting for at least two years—yet experience is being bluntly limited by people availability.

Methodologies and measurement are slipping

Formal hunting frameworks appear to be receding. Programs reporting formally defined threat hunting methodologies fell from 51% in 2024 to 37% in 2026, while ad hoc approaches increased to 39%. SANS argued that a formalized approach is “what makes a hunting program repeatable and defensible.” Measurement is also weak: only 40% of programs formally measure whether their hunting actually works, leaving many organizations unable to quantify what their hunts discover or prevent. Other barriers identified by respondents include budget constraints (42%), tool limitations (37%), and lack of defined processes (36%).

Ransomware dominates, living-off-the-land techniques are most common

Respondents reported what they encounter most: ransomware was the top concern at 55%, followed by business email compromise at 43%. Nation-state activity and insider threats each appeared for 26% of respondents. Across these threat categories, living-off-the-land techniques were the most common tactic encountered. The report underscored a tactical shift in attackers’ behavior: “If you are still writing hunts around known bad hashes or IP addresses, you are hunting for threat actors who stopped behaving that way years ago,” the report argued.

AI/ML intent falls; agentic hunting seen as an early signal

Interest in adopting AI and machine learning as a planned improvement is waning in the near term: only 39% of respondents ranked AI/ML incorporation among their top planned improvements, down from 48% last year. SANS interpreted the decline as a transition “from aspiration to the harder work of actual implementation,” noting that intent to use these tools has fallen for two consecutive years. Still, free-text responses contained early indicators of more autonomous approaches: “The teams describing agentic hunting frameworks in their free-text responses are the early signals of where this goes next,” the report concluded.

What this means for technologists, procurement leaders, and policymakers

  • Technologists and security teams: expect the day-to-day hunt to be shaped more by data plumbing than by pure detection logic. With telemetry described as “incomplete, inconsistent, or scattered,” teams will need to prioritize normalization, access, and cross-tool processing if hunts are to produce reliable results.
  • Procurement and budget holders: budget constraints (42%) and tool limitations (37%) are prominent. The measurement gap—only 40% formally track whether hunting works—makes it harder to justify investments; procurement decisions will increasingly hinge on measurable outcomes rather than feature checklists.
  • Policymakers and standards bodies: the survey flags a concrete gap in data standards (39%). As collections grow, normalization and shared formats will matter for repeatability and for any cross-organization collaboration the report signals as necessary.

For now, the clearest next step the report identifies is not a new algorithm but better measurement and better data. Without consistent telemetry and a way to quantify what hunting prevents, the SANS research warns, organizations will struggle to build a defensible case for the people, processes and tools they say they need. That measurement gap is the practical choke point the report singles out as “most worth closing.”

Original story