Method: cross-referenced practitioner surveys (SANS SOC Survey 2025, SANS Detection & Response Survey 2025, Tines Voice of the SOC, Splunk State of Security 2025, ISC2 Workforce Study 2025) against incident-response telemetry (CrowdStrike Global Threat Report 2026, Mandiant M-Trends 2026, Verizon DBIR 2026). Surveys tell us what hurts; IR telemetry tells us what attackers actually do. The curriculum is weighted where both agree.
73% of organisations rank false positives as their number-one threat-detection challenge — a dramatic rise year over year. More than 60% encounter them frequently or very frequently, and "very frequent" jumped from 13% to 20% in one year (SANS Detection & Response Survey 2025). Splunk corroborates: 59% report excessive alerts, 55% too many false positives.
64% of analysts spend more than half their time on tedious manual work; 23% spend three-quarters or more. Reporting is the most time-consuming task (50.4%), ahead of monitoring (46.6%) — and among the most disliked (Tines, Voice of the SOC). 69% of SOCs still compile operational metrics manually, and nearly half say it is excessively time-consuming (SANS SOC Survey 2025). 66% of analysts believe half or more of their tasks could be automated today.
82% of detections are now malware-free — valid credentials, trusted identity flows, approved SaaS integrations (CrowdStrike GTR 2026). Credential abuse appears somewhere in 39% of all breaches (DBIR 2026). 50% of ransomware victims had a credential or infostealer exposure event in the 95 days before the attack. Valid-account abuse drives 35% of cloud incidents; cloud-conscious intrusions grew 37%.
Average eCrime breakout time is down to 29 minutes, the fastest observed 27 seconds (CrowdStrike GTR 2026). The hand-off from initial-access brokers to secondary operators collapsed from 8+ hours in 2022 to 22 seconds in 2025 (M-Trends 2026). Mandiant's explicit recommendation: treat "low-impact" alerts as critical, because by the time a human requeues them, the second crew is already inside.
Voice phishing is now the #2 initial infection vector at 11% of intrusions (M-Trends 2026) and the leading entry into cloud environments — interactive calls that talk help desks into MFA resets. Contact-center deepfake attempts went from roughly one a month to seven a day in a single year (Pindrop 2025); the FBI's IC3 logged $893M in AI-enabled fraud losses in its first year tracking it. This is an identity-workflow problem, not a media-forensics problem — which is exactly how the curriculum treats it.
78% of teams run dispersed, disconnected security tools; 46% spend more time maintaining tools than defending the organisation; 57% lose investigation time to data-management gaps (Splunk State of Security 2025). 42% of SOCs load data into the SIEM with no documented plan to retrieve or analyse it (SANS SOC Survey 2025). Mandiant adds the visibility angle: 90-day log retention is insufficient against intrusions that persist for 400+ days, and edge devices remain blind spots.
Vulnerability exploitation overtook credentials as the #1 breach vector at 31%, up from 20% (DBIR 2026). Zero-days exploited before public disclosure rose 42% year over year; mean time-to-exploit is now negative — exploitation before patch release (M-Trends / CrowdStrike 2026). 40% of China-nexus exploitation targeted edge devices that carry no EDR telemetry.
71% of analysts report burnout and 64% are likely to switch jobs within a year (Tines). 62% say their organisation isn't doing enough to retain top personnel (SANS SOC 2025). 52% have considered leaving the profession entirely (Splunk 2025). One third of organisations cannot adequately staff their security teams (ISC2 2025). Analysts' own #1 retention ask: automation for tedious tasks. A curriculum that removes toil is a retention tool, not just a training product.
AI security skills are the #1 rising skill demand for the second consecutive year (41%, ISC2 2025); 88% of professionals tie significant incidents to skills deficiencies. Yet only 11% fully trust AI for mission-critical tasks (Splunk), GenAI tools score the lowest satisfaction of any SOC technology, and 42% of AI/ML deployments run out-of-the-box with zero customisation (SANS SOC 2025). Shadow AI compounds it: of the 45% of employees using AI at work, 67% do so through personal accounts (DBIR 2026).
The claim tested: "Deepfakes are not a real problem for security personnel."
What the data supports: as a video-detection problem deserving a full training day — no. Video deepfake BEC is a rare, high-impact event (Arup, ~$25.6M, Feb 2024) that no practitioner survey ranks among daily SOC challenges, and the defence is a verification workflow, not a detection technology. The v1 curriculum over-weighted it. That day is gone.
What the data refutes: dismissing the voice channel. Vishing is the #2 initial infection vector (11%, M-Trends 2026), the top entry into cloud environments, and contact-centre synthetic-voice attempts grew 1,300% in a year (Pindrop). The FBI logged $893M in AI-enabled fraud losses in 2025. Scattered-Spider-style help-desk impersonation is a daily reality for exposed organisations.
Curriculum consequence: deepfake video detection shrinks from a full day to case-study material; voice-channel social engineering survives as one module (2.2) inside the rebuilt identity-attacks day, anchored to help-desk verification and MFA-reset workflows — the place where SOC personnel actually meet this threat.
| Before (v2.0) | After (v2.1) | Driven by |
|---|---|---|
| SEC5xx Day 2: full day on deepfake BEC and synthetic media detection | Day 2 rebuilt: identity-first attacks, session hijack, precursor hunting; synthetic voice = one module in the help-desk context | Challenges 03 and 05 |
| Threat classes presented unranked | Threat classes ranked by observed frequency (daily → rare); course hours follow the ranking | DBIR / M-Trends / CrowdStrike vector data |
| No module for the SOC data layer | New B6: Engineering the SOC Data Layer — pipelines, normalisation, log economics, coverage | Challenge 06 |
| Reporting toil implicit in B5 | B5 explicitly measured on reporting hours (the #1 time sink) | Challenge 02 |
| Program stats cited without mapping | Every module now maps to a sourced challenge on the landing page | All |
Version note: v1 Day 2 (deepfake-focused) remains archived here for comparison.
Compiled August 2026 · Ed Dulharu · back to the program →