The State of Threat Detection, Investigation, and Response

Despite significant cybersecurity investments, many organizations still struggle with threat detection, investigation, and response (TDIR). A global IDC survey found over 90% believe they have good detection capabilities, yet 57% faced major security incidents needing extra resources last year.
Key findings:
• TDIR performance metrics improve year-over-year
• Nearly half automate over 50% of TDIR workflows
• Limited visibility (66% of IT environments) is a top concern
• Investigations remain time-consuming with insufficient automation
• Understanding user behavior is challenging
Progress is evident, but teams must invest in automation, training, and visibility to counter evolving threats.