Enhancing Cybersecurity: Insights From Splunk’s State of Security Report with Michael Fanning
Michael Fanning, CISO at Splunk, shares insights on cybersecurity challenges highlighted in the Splunk State of Security report. Key issues include analyst burnout and alert fatigue, which persist over time. Fanning discusses how AI can improve efficiency and support analysts, emphasizing the need for better prioritization and event correlation in security operations to enhance effectiveness and create a healthier work environment.
Transcript
Hey everyone, it's Alan Shimel. We're back here at Textron Gang. Great to have you with us.
Let me introduce you to our next guest. He's been with us before. Always a pleasure.
Meet, say hello to Michael Fanning Michael of, of course, is the CSO at Splunk, a Cisco company. Michael, great to have you back. I, I know you're suffering a little from allergies, so we're gonna go easy on you today.
Uh, Hey, Alan. Great, thanks. Uh, thanks for having me back and yeah, it's, it's allergy season here in the Seattle area, so bear, bear with me please.
A little congested today. Yeah, I know it. It's, no one likes to feel like that.
I, I feel for you. Um, Michael, I mentioned you're the CSO and you, you've been CSO at Splunk. Now, I'm going to guess it, has it been two years?
I've been in a deputy role for about three years, and then back in the September timeframe, uh, officially became CSO for the Splunk, be within Cisco. So about almost a year. I, I think we had you on right after that.
You did. You did. Yeah.
It's a good talk. Mm-hmm. Absolutely.
Michael, just to give people a kind of sense of your journey, you, um, as you mentioned, you were deputy CSO for a couple of years, but you've got a kinda long distinguished career in security. Yeah, you know, it, it began about 20 years ago. I actually at, at Symantec, and I won't drain, you know, my resume, but I kind of moved out west sight unseen into, into Oregon.
I, I, I was offered a role at Symantec and just kind of thought at the time, like the security thing might actually be something so moved out. And, and that's where I really started to kind of cut my teeth. I really, from that was, that was really the beginning of cybersecurity and, and really incident response that my, primarily, my background has been on the incident response side and digital forensics, um, working within security operations centers, leading security operations centers, and having them been reported to me.
And I've done that, you know, now in multiple companies. Um, you know, since my time at Symantec leading into where we're at today within Splunk. So, very cool.
Uh, you know, a lot of experience there. A lot of good times and a lot of scars. I know how that is.
Here we go. Unfortunately not how it is. Yeah.
com is, is, uh, covering the Splunk State of security report. It's that time of year again. Um, why don't you, well, let me just say, you know, we, the whole world gets a, a flood of, of security reports, state of security, cyber, what have you, usually right before the RSA net, uh, conference and then right before Black hat or around black hat.
This one, we, this report today is perfect timing because the RSA stuff's kind of in the rear view mirror. Black hat's still a little ways out ways. What can you tell us, you know, so it's a good time to discuss the Splunk State of Security report.
Tell us about the 2025 report, maybe how it relates to what has become a rich history of Splunk State of Security reports. Yeah, thanks, Alan. So, you know, what we've done with the state of security report is taken a close look at Security operations centers and I have understanding what's it like to, to work in a soc.
Uh, what are the problems that we have? What are some of the bigger opportunities? And, you know, what's really standing out to me is just a lot of the problems that you, that you hear about today are the same problems that we had, you know, 10 years ago, which is there's a lot of burnout from a so analyst.
The reason for that, what we, you know, really kind of think about is just that alert fatigue and just, you know, the, the, the churn of what the day-to-day looks like. Uh, in a, in a soc I think over greater than 50% of those pulled, have, have effectively said they're just experiencing burnout, fatigue. And it's even causing them to think about looking for, for jobs, even outside of cybersecurity.
That's how much, that's how much of a frustration pain point it is for them. You know, unfortunately, burnout in, in the cyber or, you know, security world has been something we've been dealing with for, I'm in cyber 30 years. It is, I mean, 'cause it's a, it many ways, it's a thankless job, right?
Because if nothing happens, that means you did your job. But when something happens, you know, the finger pointing starts immediately and before even the triage and, and, you know, recovery part is done and, and then it's a constant battle because it's, you know, it's the Tom and Jerry cartoon and you're, you're, I always forget if Jerry's the mouse or Tom's the mouse, but we're the cat. Right?
We're always the guy running into the frying pan or something, you know what I mean? And, um, it, it's hard. It, it's, it's hard and it gets burnt out.
And though you, you know, no, no one works for free, don't get me wrong, but it's long hours, long hours and a lot of thankless It is. Task going on Can be, you know, what I think is is super interesting, if you really think about it, what it would indicate if somebody was, was experiencing this churn as a SOC analyst, it would mean there are intrusions in their environment all the time. You know, they're constantly, they're constantly under attack and they actually have actual intrusions.
And I don't think that that's necessarily the case, right? Like, if you're dealing with an, a legitimate intrusion every hour of the day, every day, then that's a, then that's a major problem. I think that what this is indicative is, is really the quality of the way that we configure alerting our detection pipelines.
How we, how we investigate alerts is ultimately what has that downstream impact on, on a SOC analyst. And we, so we really placed this emphasis on detection as code, really treating the way that you think about engineering your detections, similar to how a software engineer thinks about the software development life cycle. Really thinking about false positive, true positive, benign, positive detection, uh, detection metrics is something that can help you derive towards improving the quality of your detections.
And ultimately, you know, the quality of, of the experience For a SOC analyst, I think part of the, the burnout is I'm expecting all, I'm, I'm investigating all of these benign, um, events that, that actually don't have security value. And I think it's one thing to say, yeah, I'm actually dealing with an intrusion and that's kind of fun, but I'm just, you know, if I'm looking at trash every day, that's, that's not a good time, especially if it's not getting any better. Yeah.
You know, Michael, years ago, uh, when I started still secure, we had an intrusion prevention product, vulnerability management network access control, and we were bidding, involved in replacing, it was actually a semantic IDS IPS system. Oh, great. I about remember that one at a large, a large US military network, probably one of the largest private networks in the world.
Yeah. And this network got on average about 400 thou, and I kid you not 400,000 intrusion attempts a day. Yeah.
A day, you know, mostly foreign state actors, nation state, foreign, and I imagine being a, you know, the screen watcher there, the screen scraper guy there, the, the SOC analyst, desensitize desensitizing doesn't even begin Yeah. To describe it. Yep.
Yeah. Right. And, and the, the, the, the really crappy part of it mm-hmm.
Is it takes one, it only takes one successful intrusion to just ruin everyone's day. Yes. Right?
Yep. And often it's a tough, tough world because of these problems, you know, do you just, do you just become a little desensitized to the alerts and you don't, you don't spend the diligence, the due diligence investigating the, you know, the ones that matter because it's like a, you know, these other hundred that I looked at this past week were nothing but it, to your pointed, this one could be the one. So again, like that prioritization and truly understanding your environment, do you really need to have for ex to your, to your network IDS, do you really need to fire on every single alert that's internet facing?
Because I mean, someone's always gonna be knocking at the door. Right? But, but it's what's, what's gotten through the door that you know, that you really need to understand.
Yep. Sometimes the knock at the door is just the false Yep. Alarm.
Right. And they're low and slow behind you. Yep.
But let's turn to this 2025 report though, Michael, give us sort of our key findings. What are the top three things you think in here? Yeah.
Um, you know, some of the things that I, that, you know, that I had mentioned earlier, just teams just feeling overwork and, and, and in some, in a lot of socks, it's not even just that they're, they're running the investigations. Some of them are running the tooling, they're running the detection pipeline. They have these hybrid roles.
There's, there is no specialization. Right? And so feeling overworked, one, the, the tooling sprawl, um, things that we've, that we've kind of chatted about in the past and understood in the past is think on average the security organization's gonna have 20, 25 distinct tools that, that they need to operate to, to protect an infrastructure that, that feels very bloated, you know, to me.
And, you know, where do you have opportunities to kind of consolidate and rationalize the tooling that you use to protect your infrastructure? And then, you know, the last piece being again, um, those that are actually looking to thinking about leaving their cybersecurity career, career behind all of this exacerbated by, I think the downward pressure by leadership of like, Hey, I'm investing resources, money, time, you know, into your organization. And, you know, when they see some of these kind of metrics come out with the false positives and, you know, where are the intrusions?
You say you're overworked, but like, where are the intrusions? Like this is all just creating just this pressure cooker of an environment for a SOC analyst to work in that super unhealthy. And, you know, I think we have an opportunity to, to help improve.
Fair. Fair. What about ai?
AI has a, has a great opportunity to, to help support and, and I think alleviate, you know, the overall workload. And we, we love to stress, um, AI is going to help create efficiencies for a SOC analyst, but it's not necessarily that replacement. If we think about it as an augmentation, the SOC analyst is still that human in the root, in the loop that validates, uh, some of these findings, you know, but a few examples that we've been working on, you know, within Splunk and the Splunk products are things like an AI assistant to help you engineer your own detection so that you don't necessarily have to be an expert in the Splunk processing language.
It's just a great way to kind of maybe get you 80% of the way there, but then that expert helps you tie that together. Another great feature that we've chatted about recently at, uh, Cisco Live last week was, um, this ability to create an incident report based on your case notes that you've, that you've created within, within Splunk. So the ability to, you know, distill all of these findings in your investigation notes and then create an, an executive, you know, incident summary that we can then pass on.
If you think about the incident response and the SOC role, it's not just that investigation. It's, it's about conveying what happened to your leadership chain in a way that they can digest and understand what the impact is, what the risk is. And, you know, some AI just has that ability to just really kind of, not just uplevel someone from a technical perspective, but thinking about those soft skills and that ability to write a quality report.
This are just, you know, a really simple great opportunity for us. Agreed, agreed, agreed. Um, Michael, I always, every report I've always been involved in, there's always some finding that I shake my head and say, well, I'm surprised.
I'm not surprised, but I'm surprised or I didn't see that coming. Or, Jesus, this a blip. You know, what, what, what in this report kind of struck you like that.
I'm surprised that we still have the same problems today that we, we had 10 years ago. Yeah, that's, that's what I'm surprised at. We're we, we still haven't solved it.
Um, the, the standard, the, the detection, you know, the, the, the churn, the false positives, the quality of the detections, all, it's, it's all still there. It's, it's exactly the same that it, it, it was 10, 10, 15 years ago. So, you know, I think we need to, we need to find ways that enable, and I think to your point about ai, that's, that's a great opportunity to really, I think, enable and, and offset, you know, some of this churn and help understand what do we, what should we truly care about when we think about creating visibility into an infrastructure, uh, engineering our detections and that investigative workflow, right?
Like, I think there's a lot of efficiencies to be gained along the way that, that are gonna, you know, help to really kinda take the stress off of an analyst. You know, maybe I'm old and cynical, but I, I've come to expect that, right? You look at things like the f**k 10 and stuff like that.
It doesn't really change very much year to year to year to year the same problems. We're still battling the same problems. And it's not that there's not new security threats and new security vectors and attack surfaces that we need to, you know, there's all, all of that.
But we in, in some ways, and it's frustrating and it, and it contributes to the burnout you're talking about. We can't get out of our own way dealing with the stuff we've been dealing with for 15 years. How the heck are we going to get to the new stuff?
Completely, completely agree. Um, you know, what we really think about has been super helpful for us internally that we're happy to pass on to, to anyone listening is, is really that event correlation, right? So I think a lot of, a lot of the way that socks are structured and detections are structured are, are one event equals a detection that warrants an investigation.
But when you can tie these events together with correlation and in Splunk products, that's gonna be risk-based alerting. When you, when you're able to say, these seven events are something that should be investigated as one investigation, it's one event that fires, that's your entire investigation of these seven events versus individually these seven events. So a fish, a malware detection, a network connection, not just necessarily investigating each one, uh, individually, but when you're able to really kind of tune your detections in a way that does that event correlation for you, you are really gonna kinda get some great efficiencies right out of the gates.
Agreed. Agreed. Excuse me, Michael, we're about outta time, but for people who want to download the report Yeah.
And kinda read it for themselves and digest it, what, what's their best bet to get It? Yeah, thanks for asking. Really the simplest way.
Go to Google type in 2025, Splunk data security. It's gonna be one of your top links. I think you'll also see last year's report there as well.
com will get you there as well, but the simplest path, just Google for the report then should pop right up for you. I love it. Hey Michael, good luck with your allergies.
This too shall pass. Enjoy. Appreciate it.
Keep up the great work at Splunk, man. We appreciate you and all you do. Yep, Likewise.
And thank you Alan, for having me on. It's always great to be here. My pleasure.
Michael Fanning be so at Splunk here on Tech Trunk tv. Go check out the report. Google it.
That's the Splunk state of security report 2025. We're gonna take a break. We'll be back on Tech Trunk tv.