Kaspersky Report Highlights Hidden Detection Gaps in Enterprise Security Operations Centers
A new report from Kaspersky Security Services has identified a significant challenge facing enterprise Security Operations Centers (SOCs): organizations may be measuring response speed without knowing whether they are detecting the threats that matter most.
The report, Anatomy of a Cyber World, found that many SOCs focus on traditional performance metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), while paying less attention to whether their detection systems provide adequate visibility across the organization’s technology environment.
According to Kaspersky’s findings, most SOCs collect substantially more security data than they actively use for threat detection. On average, correlation rule coverage stands at just 43%, meaning that less than half of ingested data sources are monitored through real-time detection logic. While the remaining data can support investigations, threat hunting, and compliance activities, it often remains outside active monitoring processes.
This creates a potentially significant blind spot. Although some organizations intentionally collect data for regulatory or forensic purposes without incorporating it into detection workflows, many security teams struggle with incomplete rule development, unclear ownership of detection content, or limited engineering resources. As a result, important parts of the IT environment may receive little or no real-time security monitoring.
The challenge becomes even more pronounced as organizations grow. Kaspersky found that SOCs handling the largest data volumes typically achieve active detection coverage of only around 30% of available data sources. Detection engineering resources often fail to keep pace with expanding infrastructure, leaving critical systems such as network telemetry, databases, and web servers without sufficient monitoring coverage.
The report also revealed differing approaches to detection strategy. Approximately half of the assessed organizations rely primarily on vendor-provided detection rules, while around 40% develop their own rules internally. Organizations that depend heavily on vendor content may experience higher false-positive rates and coverage limitations if rules are not properly tuned. Meanwhile, organizations relying mainly on Endpoint Detection and Response (EDR) technologies can face visibility gaps when events from multiple sources are not effectively correlated.
Another common issue is that many organizations establish detection requirements when their SOC is first designed but fail to review and update those requirements as infrastructure evolves. Over time, this can lead to growing security blind spots that remain unnoticed until an incident occurs.
Roman Nazarov, Head of SOC Consulting at Kaspersky, noted that evaluating SOC effectiveness from within the organization can be difficult because of internal bias. As a result, many companies are increasingly turning to independent SOC consulting services to assess detection capabilities, analyze event flows, and simulate attacks to determine whether critical threats are being identified.
Nazarov emphasized the importance of building a structured detection engineering process that includes regular development, testing, validation, and review of detection logic to ensure monitoring remains aligned with changing risks and infrastructure.
Kaspersky reports growing demand for SOC consulting services as organizations seek greater visibility into their security operations. In 2025, the most common consulting engagements included SOC Technical Assessments (23.4%), SOC Framework Development (20%), and both SOC Maturity Assessments and SIEM Quality Assurance projects (11.7% each).
The findings are based on data gathered from Kaspersky’s Managed Detection and Response, Incident Response, Compromise Assessment, and SOC Consulting services. The report examines attack techniques, incident trends, and security operations performance across industries and regions worldwide.
Photo credit: Kaspersky.
Source: Kaspersky.
