Are security teams wasting their time?

by Black Hat Middle East and Africa
on
Are security teams wasting their time?

Visibility isn’t cybersecurity’s biggest problem anymore. Security operations centres are alive with alerts, dashboards and threat feeds – but turning all that information into meaningful action before attackers do is a real challenge.

We’ve been reading new research from Filigran which shows us the scale of the issue, finding that security analysts spend an average of 42% of their working week investigating risks that later prove to be low priority or not exploitable – around 17 hours every week per analyst.

That's more than two working days spent answering questions that ultimately don't change an organisation's risk profile.

The cost of chasing the wrong risks

If you’re part of an SOC team, the findings will ring true. Analysts move between vulnerability scanners, threat intelligence feeds, cloud security tools and ticketing systems, piecing together context before they can decide whether a vulnerability deserves immediate attention.

That process takes time. And time is one of cybersecurity's scarcest resources.

Filigran found that:

  • 84% say the attacks they face often exploit risks they already knew about but hadn't prioritised.
  • 97% struggle to determine whether an exposure is actually exploitable. 
  • Only 41% report having a fully consolidated view of their cyber risk exposure.

The result is a growing operational backlog. Teams understand where weaknesses exist but spend valuable hours validating their significance before remediation can begin.

Research from Verizon reinforces why this matters. The firm’s 2025 data breach report found that vulnerability exploitation as an initial access vector increased by 34% year on year, while third party involvement featured in 30% of breaches. Attackers continue to capitalise on known weaknesses, which makes prioritisation every bit as important as detection.

More alerts don't always mean more risk

The volume of security findings continues to rise, but only a small proportion demand immediate action.

Another 2026 report from Check Point found that after exploitability validation, only 7.8% of vulnerability alerts warranted ‘critical’ or ‘high’ attention. That means the overwhelming majority required a different response, additional context or routine remediation rather than emergency action.

But every alert enters the same analyst workflow. Without context, every finding competes for attention, stretching already busy security teams across hundreds or even thousands of potential issues.

Filigran's research shows the operational impact: 89% of respondents believe reducing alert noise would help them identify genuine business risk more effectively, while 82% say manual processes make it harder to determine which risks require immediate attention.

Time to rethink security workflows

In cybersecurity, we’re always talking about tool sprawl – and with good reason. Organisations now manage dozens of security products, each producing valuable information within its own domain. Bringing those insights together into a single picture is something the industry is still very much working to achieve. 

According to Filigran, 93% of organisations experience challenges maintaining an accurate view of their attack surface, while 31% say they simply have too many tools to manage effectively.

So the next stage of cybersecurity maturity centres on reducing operational friction. That means:

  • Connecting threat intelligence with asset context.
  • Validating exploitability before escalating remediation.
  • Automating repetitive analysis wherever possible.

Organisations already know all of this needs to happen. Filigran found that 88% believe greater automation is essential to keep pace with the volume of risks they need to assess, while three-quarters plan to increase investment in cyber risk quantification and exposure assessment over the next two years.

In an environment where attackers increasingly exploit known vulnerabilities, organisations need to have a clearer understanding of which alerts they need to act on fastest.

Share on

Join newsletter

Join the newsletter to receive the latest updates in your inbox.


Follow us


Topics

Sign up for more like this.

Join the newsletter to receive the latest updates in your inbox.

Related articles