SANS 2026: 80% of detection teams can barely keep pace. Faster rule-writing won't help, a stable data layer will. See how to run Sigma in-stream, before the SIEM

Closing the Data-Detection Gap: What We're Building

It's been a while since we said anything public about where Axoflow's product is heading. Here's what gave us the push to write this now.

SANS polled 307 detection engineers, architects, and security leaders this spring for its 2026 State of Detection Engineering survey. Buried in the executive summary is the number that should worry every security leader who thinks their program is fine: 18%. That's the share of teams who say they're staying ahead of the threat landscape. 56% report barely keeping pace. 24% report falling behind. Four in five practitioners are, at best, treading water.

Automating the Wrong End of the Problem

What's more interesting is what practitioners themselves say would fix it. Asked to name their top improvement priority for the next year, 34% picked automation - more than detection accuracy, more than workflow, more than anything else on the list. Not more headcount. Not more rules. The manual work needs to stop being manual.

Here's where we diverge from how the industry usually reads that number. Automation of what? Automate rule writing on top of a data layer that's still fragmented, brittle, and manually maintained, and you've automated the wrong end of the problem. You'll ship detections faster on top of a foundation that breaks the same way it always did. The 80% treading water aren't losing the race because they write rules too slowly. They're losing it because the ground under the rules keeps moving.

The Coverage Gap Nobody's Closing

Take the coverage gap. 43% of respondents name cloud-native environments - containers, ephemeral workloads, API-driven infrastructure - as their single biggest detection blind spot, more than double any other category, and consistent with last year's finding. My co-founder and CTO, Sándor Guba, built the CNCF Sandbox Logging Operator at Banzai Cloud before Cisco acquired it in 2021. He was solving "how do you even collect from this" in Kubernetes before most SOCs had a Kubernetes footprint to worry about. The lesson carries directly: cloud-native logs don't go dark because nobody wrote the parser. They go dark because the collection layer wasn't built for infrastructure that reshapes itself every few minutes. Fix collection for that reality and the coverage gap closes at the source, not at the SIEM.

The Skills Nobody's Building

The survey's skills data makes the structural point even sharper. Detection engineers say that the disciplines, where the gap is the biggest between where they are today and where they would need to be are: software engineering, data engineering, and - the widest gap in the entire survey - for detection-as-code. Read that in order: the skills the field says it needs most urgently for modern detection maturity are also the ones it has developed least. That's not a training problem you fix with a course. It's a sign the discipline is asking individual detection engineers to grow two adjacent engineering disciplines on top of the one they were hired for.

The skills the field needs most urgently for detection maturity are also the ones it has developed least.

The Ticket You Shouldn't Have to File

Data engineering is the one we'd point at first. It's the discipline behind schema stability, field mapping, and the plumbing that keeps a Sigma rule pointed at the field it expects. 42% of respondents say their detection engineering effort has minimal or no connection to a data engineering team. That's not a staffing failure. It's a sign most organizations still treat data engineering as someone else's department - a ticket away, not a teammate. We don't think detection engineers should have to file that ticket. Axoflow's platform already does the classifying, normalizing, and schema-drift handling before a Sigma rule ever sees the data, so a detection engineer isn't waiting on a separate team for that part today.

Closing the rest of the loop, so being able to fix a coverage gap as soon as it surfaces without a ticket to anyone, is exactly what we're building toward next.

The Testing Discipline the Field Skipped

The same pattern shows up in detection-as-code adoption. Version control and peer review are the two most commonly adopted practices among teams that answered the survey's detection-as-code questions. Automated testing is where it falls apart: only 38% of that same group run their detection logic through any kind of automated validation before it ships.

Nearly one in three respondents skipped the detection-as-code section of the survey entirely, itself a signal of how unfamiliar the practice still is. Teams have adopted the parts of software engineering that are easy to bolt on and skipped the part that actually catches a broken rule before production does. That's the gap we're closing with Axoflow's detection capabilities, and the reason we think it's closable is architectural. In early access now, Axoflow runs Sigma rules in the pipeline itself, in-stream, before the SIEM ever ingests the event, and routes each finding to wherever it needs to go next. Once the rule and the data it runs on live in the same layer, the rest of the discipline - version control, CI/CD testing, validating rules against live ATT&CK vectors - stops being a separate practice every team has to build for itself and becomes something the platform does. That's where we're taking it - public launch of in-stream detection in September, then incrementally shipping the rest of the platform across Q4 and 2027 Q1.

Running Detection In The Pipeline

Go back to that 34% who picked automation as next year's priority. They're right about the diagnosis. The manual work does need to stop being manual. But the manual work worth automating first isn't the last mile, writing the rule. It's the first mile: collecting the right data, classifying it correctly, keeping it stable when a vendor ships a firmware update, and testing that the rule still fires before you find out in production that it doesn't. Automate that layer, and the detection engineer gets back the week the survey shows they're currently losing to schema drift, broken field mappings, and tickets to a team that isn't theirs. That's the layer we built Axoflow to own. Detection is in early access now, and we're working with a small group of design partners ahead of the September launch. If you're one of the 80% treading water and you're done automating the wrong end of the problem, get in touch about joining early access.

Follow Our Progress!

We are excited to be realizing our vision above with a full Axoflow product suite.

Sign Me Up
This button is added to each code block on the live site, then its parent is removed from here.

Fighting data Loss?

Balázs Scheidler

Book a free 30-min consultation with syslog-ng creator Balázs Scheidler

Recent Posts

The Great Corporate Game of "Who Owns This?"
SC4S alternative: a multi-destination log routing without vendor lock-in
Same model, three sets of rules: a 2026 privacy map for Claude, GPT, and Gemini