Home » Emerging Technologies » Cyber Security » Threat Hunting Data Emerges as Biggest Barrier
News Desk -

Share

Threat hunting is facing a growing data challenge, according to the latest SANS survey, which finds that data quality or quantity has overtaken skilled staff as the biggest barrier to effective threat hunting.

SANS Institute has released the SANS 2026 Threat Hunting Survey: The Evolution of Threat Hunting, authored by Josh Lemon, SANS Principal Instructor. The survey shows that staffing is no longer the primary concern for threat hunting programs.

Instead, the findings point to persistent challenges around the data that security teams rely on to identify potential threats.

The survey collected responses from 500 cybersecurity practitioners and security leaders across North America, Europe, Latin America, and Asia. It has tracked how organisations approach proactive threat detection since 2021.

This year, 82% of respondents said they have been involved in threat hunting for at least two years. However, 50% identified data quality or quantity as their primary barrier to effective hunting.

That marks the first time in the survey’s history that data has ranked above skilled staff, which was cited by 45% of respondents.

Cloud infrastructure is also creating challenges for security teams. Some 32% of respondents identified it as the toughest environment to hunt in, more than any other area. This comes as organisations continue to move more of their infrastructure to the cloud.

“Data quality has overtaken skilled staff as the top barrier for the first time in this survey’s history,” said Josh Lemon, SANS Principal Instructor.

“You can be the most capable hunter in the room and still come up empty if the telemetry you’re working with is incomplete, inconsistent, or scattered across a dozen tools that are difficult to access or difficult to process,” Lemon added.

He also pointed to a measurement gap across many programmes. Only 40% of programmes formally measure whether their hunting is effective, making it difficult for organisations to determine the impact of data gaps.

The survey also highlights the continued importance of techniques that can operate without traditional malware. Some 73% of respondents identified living-off-the-land techniques as the top method used by nation-state actors, while 63% said the same for organised crime.

At the same time, formally defined threat hunting methodologies are becoming less common. Only 37% of organisations now have a formally defined methodology, compared with 46% in 2025 and 51% in 2024.

Ad hoc approaches have increased to 39%.

Measurement is also declining. Formal measurement of hunt outcomes has fallen to 40%, down from 64% in 2024. This could make it harder for organisations to demonstrate the value of their hunting programmes and support their budgets.

Plans around AI and machine learning have also become more measured. Some 39% of respondents ranked AI and ML incorporation among their top planned improvements, down from 48% in 2025.

The findings indicate that organisations are assessing AI against their existing workflows rather than relying on it to address underlying data challenges.

Meanwhile, outsourcing continues to decline. The share of organisations outsourcing threat hunting fell to 18%, compared with 30% in 2025. Organisations keeping hunting in-house remained at 58% for the second consecutive year.

The full SANS 2026 Threat Hunting Survey: The Evolution of Threat Hunting is available to download from SANS Institute.

Josh Lemon was scheduled to present an accompanying webcast on September 23 at 10:30 a.m. ET, with a recording available afterward. The webcast information is available through SANS webcast page.

The survey findings show that as threat hunting programmes gain experience, access to usable and measurable security data remains a significant challenge for organisations.