Evidence Annex · August 2026

What security analysts and SOC engineers actually fight — and how the curriculum answers it.

Method: cross-referenced practitioner surveys (SANS SOC Survey 2025, SANS Detection & Response Survey 2025, Tines Voice of the SOC, Splunk State of Security 2025, ISC2 Workforce Study 2025) against incident-response telemetry (CrowdStrike Global Threat Report 2026, Mandiant M-Trends 2026, Verizon DBIR 2026). Surveys tell us what hurts; IR telemetry tells us what attackers actually do. The curriculum is weighted where both agree.

The ranking

Nine challenges, ranked by evidence weight.

01

Alert overload and false positives

73% of organisations rank false positives as their number-one threat-detection challenge — a dramatic rise year over year. More than 60% encounter them frequently or very frequently, and "very frequent" jumped from 13% to 20% in one year (SANS Detection & Response Survey 2025). Splunk corroborates: 59% report excessive alerts, 55% too many false positives.

Trained in: B1 AI-Assisted Triage (measured on time-to-verdict and triage error rate) · B2 Detection Engineering (measured on false-positive rate) · SEC5xx Day 1
02

Manual toil, with reporting as the single worst offender

64% of analysts spend more than half their time on tedious manual work; 23% spend three-quarters or more. Reporting is the most time-consuming task (50.4%), ahead of monitoring (46.6%) — and among the most disliked (Tines, Voice of the SOC). 69% of SOCs still compile operational metrics manually, and nearly half say it is excessively time-consuming (SANS SOC Survey 2025). 66% of analysts believe half or more of their tasks could be automated today.

Trained in: B5 SOC Automation with AI Agents (measured on reporting hours and case cycle time)
03

Identity-first, malware-free intrusions

82% of detections are now malware-free — valid credentials, trusted identity flows, approved SaaS integrations (CrowdStrike GTR 2026). Credential abuse appears somewhere in 39% of all breaches (DBIR 2026). 50% of ransomware victims had a credential or infostealer exposure event in the 95 days before the attack. Valid-account abuse drives 35% of cloud incidents; cloud-conscious intrusions grew 37%.

Trained in: SEC5xx Day 2 (rebuilt) — identity kill chain, session hijack, precursor hunting · B2 identity detections
04

Machine-speed attacks against human-speed operations

Average eCrime breakout time is down to 29 minutes, the fastest observed 27 seconds (CrowdStrike GTR 2026). The hand-off from initial-access brokers to secondary operators collapsed from 8+ hours in 2022 to 22 seconds in 2025 (M-Trends 2026). Mandiant's explicit recommendation: treat "low-impact" alerts as critical, because by the time a human requeues them, the second crew is already inside.

Trained in: B3 AI in IR & Forensics (measured on MTTR) · B5 guarded auto-containment · SEC5xx Day 5 capstone
05

Voice social engineering of help desks — the surprise riser

Voice phishing is now the #2 initial infection vector at 11% of intrusions (M-Trends 2026) and the leading entry into cloud environments — interactive calls that talk help desks into MFA resets. Contact-center deepfake attempts went from roughly one a month to seven a day in a single year (Pindrop 2025); the FBI's IC3 logged $893M in AI-enabled fraud losses in its first year tracking it. This is an identity-workflow problem, not a media-forensics problem — which is exactly how the curriculum treats it.

Trained in: SEC5xx Day 2, module 2.2 — one module, anchored to help-desk verification workflows, not a full day
06

Tool sprawl and the SOC data layer

78% of teams run dispersed, disconnected security tools; 46% spend more time maintaining tools than defending the organisation; 57% lose investigation time to data-management gaps (Splunk State of Security 2025). 42% of SOCs load data into the SIEM with no documented plan to retrieve or analyse it (SANS SOC Survey 2025). Mandiant adds the visibility angle: 90-day log retention is insufficient against intrusions that persist for 400+ days, and edge devices remain blind spots.

Trained in: B6 Engineering the SOC Data Layer (new module — measured on maintenance hours and coverage per € ingested)
07

Vulnerability exploitation and exposure overload

Vulnerability exploitation overtook credentials as the #1 breach vector at 31%, up from 20% (DBIR 2026). Zero-days exploited before public disclosure rose 42% year over year; mean time-to-exploit is now negative — exploitation before patch release (M-Trends / CrowdStrike 2026). 40% of China-nexus exploitation targeted edge devices that carry no EDR telemetry.

Trained in: B2 coverage-driven detection for unpatchable windows · B4 AI-assisted exposure prioritisation in hunting
08

Staffing, burnout and retention

71% of analysts report burnout and 64% are likely to switch jobs within a year (Tines). 62% say their organisation isn't doing enough to retain top personnel (SANS SOC 2025). 52% have considered leaving the profession entirely (Splunk 2025). One third of organisations cannot adequately staff their security teams (ISC2 2025). Analysts' own #1 retention ask: automation for tedious tasks. A curriculum that removes toil is a retention tool, not just a training product.

Addressed by: the whole program's force-multiplication design — and directly by B5
09

The AI skills gap itself — and low trust in AI tooling

AI security skills are the #1 rising skill demand for the second consecutive year (41%, ISC2 2025); 88% of professionals tie significant incidents to skills deficiencies. Yet only 11% fully trust AI for mission-critical tasks (Splunk), GenAI tools score the lowest satisfaction of any SOC technology, and 42% of AI/ML deployments run out-of-the-box with zero customisation (SANS SOC 2025). Shadow AI compounds it: of the 45% of employees using AI at work, 67% do so through personal accounts (DBIR 2026).

Trained in: C1 AI Literacy (calibrated trust, evaluation-first) · S1 Defending Enterprise AI (shadow-AI discovery, copilot monitoring)
The calibration question

What about deepfakes?

The claim tested: "Deepfakes are not a real problem for security personnel."

What the data supports: as a video-detection problem deserving a full training day — no. Video deepfake BEC is a rare, high-impact event (Arup, ~$25.6M, Feb 2024) that no practitioner survey ranks among daily SOC challenges, and the defence is a verification workflow, not a detection technology. The v1 curriculum over-weighted it. That day is gone.

What the data refutes: dismissing the voice channel. Vishing is the #2 initial infection vector (11%, M-Trends 2026), the top entry into cloud environments, and contact-centre synthetic-voice attempts grew 1,300% in a year (Pindrop). The FBI logged $893M in AI-enabled fraud losses in 2025. Scattered-Spider-style help-desk impersonation is a daily reality for exposed organisations.

Curriculum consequence: deepfake video detection shrinks from a full day to case-study material; voice-channel social engineering survives as one module (2.2) inside the rebuilt identity-attacks day, anchored to help-desk verification and MFA-reset workflows — the place where SOC personnel actually meet this threat.

Changes applied

What changed in the curriculum because of this research.

Before (v2.0)After (v2.1)Driven by
SEC5xx Day 2: full day on deepfake BEC and synthetic media detectionDay 2 rebuilt: identity-first attacks, session hijack, precursor hunting; synthetic voice = one module in the help-desk contextChallenges 03 and 05
Threat classes presented unrankedThreat classes ranked by observed frequency (daily → rare); course hours follow the rankingDBIR / M-Trends / CrowdStrike vector data
No module for the SOC data layerNew B6: Engineering the SOC Data Layer — pipelines, normalisation, log economics, coverageChallenge 06
Reporting toil implicit in B5B5 explicitly measured on reporting hours (the #1 time sink)Challenge 02
Program stats cited without mappingEvery module now maps to a sourced challenge on the landing pageAll

Version note: v1 Day 2 (deepfake-focused) remains archived here for comparison.

Sources

Primary sources read for this annex.

Compiled August 2026 · Ed Dulharu · back to the program →