Cybersecurity teams struggle with investigation scope creep, collaboration inefficiencies, and data access limitations, according to new research.
As cyber threats continue to evolve, security operations teams face mounting challenges in defending organizations against increasingly sophisticated attacks. Command Zero has released new research that paints a troubling picture of the current state of cyber investigations. The report, based on interviews with over 350 cybersecurity professionals, reveals critical gaps in incident response and threat-hunting capabilities across industries.
Command Zero’s CEO, Dov Yoran, explained that the research grew out of his personal discussions with chief information security officers (CISOs) after his previous startup—data security posture management (DSPM) provider Polar Security—was acquired by IBM in May 2023. The objective was to gain an understanding of how the security landscape has evolved for cyber investigations and SecOps teams. “There are new adversaries and risks,” Yoran told CISOstack, “but also new technologies.”
This early research eventually grew into a solution unveiled by Command Zero in July when the company announced a $21 million seed funding round led by Andreessen Horowitz.
Cyber Investigations Processes: A Troubling Lack of Consistency
Yoran and his team embarked on a two-year study involving interviews with CISOs and other security professionals to identify the biggest pain points. Among the key findings, the research reveals a universal talent gap in cybersecurity that hinders the ability to run effective investigations.
The study found that 72% of respondents cited investigation scope creep as a significant problem. Keeping the investigation focused is a constant challenge as analysts must continually evaluate the relevance of new information.
Investigation Scope Creep and Data Access Issues
The scope of an investigation may expand rapidly as new data is discovered, complicating the process of building a clear and concise investigation narrative. “Investigators must have well-defined practices when distinguishing between crucial data points and counterproductive rabbit holes,” Yoran said.
The study also identified issues with data access. While 83% of respondents stated that access to SaaS log data is essential for incident response, less than 50% of organizations currently ingest these logs into their incident response platforms. This gap is especially concerning as business applications and core SaaS systems increasingly become high-value targets, hosting intellectual property and other sensitive data. Yoran explained, “Many aspects of incident response are not well-defined, and there are still many gaps” at enterprise companies.
Over-Reliance on Individual Expertise
“We noticed an over-reliance on individual expertise,” Command Zero vice president of product marketing Erdem Menges said. “Many companies rely heavily on a homegrown application or tool, but this approach becomes untenable as the organization scales.” Smaller enterprises can face bottlenecks as a result of an individual leader, but at larger entities, the complexity quickly becomes overwhelming, he noted.
Hidden Cost of Complex Tools
The report also highlights issues with current security operations center (SOC) tools. While solutions like security information and event management (SIEM), security orchestration, automation, and response (SOAR), and endpoint detection and response (EDR) are foundational, they are often difficult to operate, leading to inefficiencies.
Menges stated, “Helping organizations learn from investigations and make more actionable decisions remains a challenge.” Reliance on specialized knowledge creates difficulties for effective collaboration during high-stakes incidents.
Gaps in Current Investigation Tools
A staggering 92% of respondents cited a lack of a standardized collaboration tool as a key challenge during cyber investigations. This reliance on inadequate solutions leads to inefficiencies, miscommunications, and loss of data. Effective project communication is critical for onboarding new team members, handing off investigations between analysts, and collaborating with subject matter experts and asset owners.
While these tools provide valuable data, the report noted that are not equipped to handle the full spectrum of investigative needs. Blind spots in investigations are common due to the narrow focus on security alerts and logs. Only 28% of organizations automate the integration of non-security data sources. “Understanding the big fundamentals like collaboration tools that have more flexibility, helping them walk through the most escalating events—these are areas that still need significant improvement,” Yoran said.
A Call for Better Collaboration and Standardization
The report recommends that security operations teams focus on building standardized processes for cyber investigations, especially for tier-2 and tier-3 analysts, threat hunters, and incident responders. “Helping senior execs get out of manual, repetitive tasks and help get junior employees up to speed is crucial,” Yoran argued.
The research highlights a significant reliance on the expertise of one or a few senior analysts who possess unique knowledge about their company’s environment. This creates a single point of failure that can lead to catastrophic security lapses if these individuals leave.
The key to overcoming these challenges lies in democratizing access to information and tools across the security operations team, Yoran suggested. Standard processes should include how to collaborate and communicate during analyses,” he noted.”
Looking Ahead: A Path to Improvement
“Our goal is to help organizations learn from investigations, make more actionable decisions, and ultimately reduce the manual toil of the process,” Menges said.
Moreover, 80% of CISOs find tracking and complying with regulatory reporting overly complex, especially for organizations operating across multiple jurisdictions. The lack of standardization in investigation processes, outputs, and outcomes exacerbates this complexity, as does the challenge of achieving traceability and auditability of past investigations—a critical intersection of governance, risk, compliance (GRC), security operations, and identity management.
As the cybersecurity landscape continues to evolve, so must the tools and processes used to defend against it. “It’s time to move beyond the status quo and embrace a more collaborative, standardized approach to cyber investigations,” Yoran concluded.
The post How Cyber Investigations Are Falling Short: Report appeared first on CISOstack.