{"id":818,"date":"2017-03-02T12:48:39","date_gmt":"2017-03-02T16:48:39","guid":{"rendered":"https:\/\/solutionsreview.com\/security-information-event-management\/?p=818"},"modified":"2017-03-09T12:57:15","modified_gmt":"2017-03-09T16:57:15","slug":"half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/","title":{"rendered":"Half of SIEM Users Find Threat Intelligence Unsatisfactory, Ponemon Reports"},"content":{"rendered":"<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-819\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg\" alt=\"ponemon-institute-header\" width=\"800\" height=\"350\" srcset=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg 800w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header-300x131.jpg 300w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header-768x336.jpg 768w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header-600x263.jpg 600w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header-180x79.jpg 180w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header-400x175.jpg 400w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>Nearly half of all users of Security Information and Event Management (SIEM) solutions are unsatisfied with the threat intelligence provided by their tools, according to <a href=\"https:\/\/go.cyphort.com\/Ponemon-SIEM-Report-2017-Page.html\" target=\"_blank\">new research<\/a> conducted by the Ponemon Institute and Cyphort. The report, <em>Challenges to Achieving SIEM Optimization<\/em>, examines issues and attitudes from SIEM users in 559 large organizations across the United States. According to the study, 76 percent of respondents value their SIEM as a strategically important security tool, yet just 48 percent were satisfied with the actionable intelligence they get from their SIEMs.<\/p>\n<p style=\"text-align: justify\">\u201cThe root of their dissatisfaction seems to be related to the complexity of the SIEM itself,\u201d says Dr. Larry Ponemon, chairman and founder of the Ponemon Institute. \u201cIn fact, 75 percent of respondents said there is significant, or very significant, effort involved in configuring their SIEM for their organization. Obviously, this complexity can make it very difficult to extract the value they want and need.\u201d The issue of complexity was also evident in the total cost of ownership for SIEM solutions.<\/p>\n<p style=\"text-align: justify\">Just 25 percent of total SIEM cost is related to the initial purchase of the software, according to the Ponemon Institute&#8217;s research. The other 75 percent of the cost is for installation, maintenance, and staffing. Surprisingly, 78 percent of the organizations surveyed have one or less full-time staff assigned to SIEM administration, and yet 64 percent or organizations pay more than $1 million annually for external consultants and contractors to assist with SIEM configuration and management. \u201cThis data also indicates that the demand for trained security analysts exceeds the supply of skilled talent available to fill these positions,\u201d added Dr. Ponemon.<\/p>\n<p style=\"text-align: justify\">User dissatisfaction and general frustrations were evident in the report&#8217;s other key findings as well:<\/p>\n<ul>\n<li style=\"text-align: justify\">The SIEM is too \u201cnoisy\u201d \u2013 54 percent of users agree that their SIEM generates too much low-level data and too many alerts, making it difficult to focus on what matters most.<\/li>\n<li style=\"text-align: justify\">Better identity context is desired \u2013 61 percent want to understand the specific users and devices associated with security events reported by the SIEM.<\/li>\n<li style=\"text-align: justify\">More trained staff is needed \u2013 68 percent say their SIEM is useful\u00a0but would need additional staff to maximize its value.<\/li>\n<li style=\"text-align: justify\">Improvements in alerts \u2013 70 percent want their SIEM to generate fewer alerts that are more accurate, prioritized and meaningful.<\/li>\n<li style=\"text-align: justify\">SIEM users want more automation \u2013 71 percent want to automate certain SIEM-generated tasks, so that response teams can focus on priorities.<\/li>\n<\/ul>\n<p style=\"text-align: justify\"><strong>SIEM Still Essential<\/strong><\/p>\n<p style=\"text-align: justify\">Despite issues of complexity and staffing challenges, 84 percent of respondents said their SIEM is important, very important or essential to their incident respondent process. This reinforces the fact that the SIEM is strategically important to their businesses. Unfortunately, the performance of the SIEM as a security tool falls short of user expectations \u2013 specifically in terms of minimizing the dwell time of advanced threats that have penetrated the network. The research revealed that for 65 percent of organizations, the SIEM\u2019s discovery of a compromise can take hours, days, weeks or even months.<\/p>\n<p style=\"text-align: justify\">\u201cThe research data from the Ponemon Institute is consistent with the feedback we\u2019ve been hearing from many organizations across the US in terms of the problem with SIEMs,\u201d said Franklyn Jones, Cyphort chief marketing officer. \u201cThe quantity of data is too high, while the quality of the data is too low. And there is inadequate staff to minimize that noise and maximize the underlying value.\u201d<\/p>\n<p style=\"text-align: justify\">\n","protected":false},"excerpt":{"rendered":"<p>Nearly half of all users of Security Information and Event Management (SIEM) solutions are unsatisfied with the threat intelligence provided by their tools, according to new research conducted by the Ponemon Institute and Cyphort. The report, Challenges to Achieving SIEM Optimization, examines issues and attitudes from SIEM users in 559 large organizations across the United [&hellip;]<\/p>\n","protected":false},"author":24,"featured_media":819,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[3],"tags":[128,386,385,22,373],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Half of SIEM Users Find Threat Intelligence Unsatisfactory, Ponemon Reports<\/title>\n<meta name=\"description\" content=\"Nearly half of all users of Security Information and Event Management (SIEM) solutions are unsatisfied with the threat intelligence provided by their\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Half of SIEM Users Find Threat Intelligence Unsatisfactory, Ponemon Reports\" \/>\n<meta property=\"og:description\" content=\"Nearly half of all users of Security Information and Event Management (SIEM) solutions are unsatisfied with the threat intelligence provided by their\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/\" \/>\n<meta property=\"og:site_name\" content=\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\" \/>\n<meta property=\"article:published_time\" content=\"2017-03-02T16:48:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-03-09T16:57:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jeff Edwards\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Edwards\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/\",\"name\":\"Half of SIEM Users Find Threat Intelligence Unsatisfactory, Ponemon Reports\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg\",\"datePublished\":\"2017-03-02T16:48:39+00:00\",\"dateModified\":\"2017-03-09T16:57:15+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\"},\"description\":\"Nearly half of all users of Security Information and Event Management (SIEM) solutions are unsatisfied with the threat intelligence provided by their\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg\",\"width\":800,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Half of SIEM Users Find Threat Intelligence Unsatisfactory, Ponemon Reports\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\",\"name\":\"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors\",\"description\":\"Buyer&#039;s Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\",\"name\":\"Jeff Edwards\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"caption\":\"Jeff Edwards\"},\"description\":\"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.\",\"sameAs\":[\"https:\/\/solutionsreview.com\",\"https:\/\/x.com\/InfoSec_Review\"],\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/author\/jedwards\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Half of SIEM Users Find Threat Intelligence Unsatisfactory, Ponemon Reports","description":"Nearly half of all users of Security Information and Event Management (SIEM) solutions are unsatisfied with the threat intelligence provided by their","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/","og_locale":"en_US","og_type":"article","og_title":"Half of SIEM Users Find Threat Intelligence Unsatisfactory, Ponemon Reports","og_description":"Nearly half of all users of Security Information and Event Management (SIEM) solutions are unsatisfied with the threat intelligence provided by their","og_url":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/","og_site_name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","article_published_time":"2017-03-02T16:48:39+00:00","article_modified_time":"2017-03-09T16:57:15+00:00","og_image":[{"width":800,"height":350,"url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg","type":"image\/jpeg"}],"author":"Jeff Edwards","twitter_misc":{"Written by":"Jeff Edwards","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/","name":"Half of SIEM Users Find Threat Intelligence Unsatisfactory, Ponemon Reports","isPartOf":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg","datePublished":"2017-03-02T16:48:39+00:00","dateModified":"2017-03-09T16:57:15+00:00","author":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6"},"description":"Nearly half of all users of Security Information and Event Management (SIEM) solutions are unsatisfied with the threat intelligence provided by their","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#primaryimage","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2017\/03\/ponemon-institute-header.jpg","width":800,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/half-of-siem-users-find-threat-intelligence-unsatisfactory-ponemon-reports\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/security-information-event-management\/"},{"@type":"ListItem","position":2,"name":"Half of SIEM Users Find Threat Intelligence Unsatisfactory, Ponemon Reports"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website","url":"https:\/\/solutionsreview.com\/security-information-event-management\/","name":"Best Information Security SIEM Tools, Software, Solutions &amp; Vendors","description":"Buyer&#039;s Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6","name":"Jeff Edwards","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","caption":"Jeff Edwards"},"description":"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.","sameAs":["https:\/\/solutionsreview.com","https:\/\/x.com\/InfoSec_Review"],"url":"https:\/\/solutionsreview.com\/security-information-event-management\/author\/jedwards\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/818"}],"collection":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/comments?post=818"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/818\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media\/819"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media?parent=818"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/categories?post=818"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/tags?post=818"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}