State of Security Research Zeroes in on Data Strategies

The past year was monumental for security leaders, with both the COVID-19 pandemic and the SolarWinds attacks challenging our traditional approaches to security. Overnight, the pandemic forced the rapid shift to remote work — and the exponentially faster shift to cloud technology that it helped drive. This came with less visibility into the technology ecosystem, less control of access points, and a larger, more varied attack surface for hackers to target.

In the midst of this massive shift came the largest supply chain attacks we have ever seen. The impact of these two events will be felt for years and be a defining moment for the careers of many of us in the security industry.

Unfortunately the attacks have continued, with the DarkSide ransomware attack and the CodeCove supply chain attack hitting this month — before many could implement the security strategies necessary to stay ahead of emboldened adversaries.

New research, sponsored by Splunk and released today in The State of Security 2021, provides the first look into the post-SolarWinds landscape. We still have a lot of work to do, but there are reasons for cybersecurity experts to be optimistic.

Researchers at the Enterprise Strategy Group, working with Splunk, surveyed more than 500 security and IT leaders worldwide only two months after the SolarWinds attacks were first discovered. The data suggests that organizations had not yet gotten their heads around the risk of one of the most dramatic supply chain attacks seen to date. Specifically, our research found that:

The State of Security report points out that supply chain attacks are not the only challenge facing CISOs. We also need to evolve our security strategies to address the increasing complexity of hybrid, multicloud infrastructures. The rush to more remote work and to expand cloud and digital technologies as a rapid response to the pandemic exacerbated these challenges.

The research does offer encouraging signs that change is already happening. One bright spot is the relationship between security and IT teams: 83% of respondents agreed that collaboration had improved during the pandemic. For security, almost 90% of organizations also said that they are increasing IT spending, and 35% said they are “increasing significantly.”

Here are more findings from the research:

Now that we have this data, where do we start? We start by contemplating what Splunk CEO Doug Merrit discussed at the annual RSA security conference last week: Data is essential to an effective cybersecurity program. Data is central to identifying and responding to any security threat. Security is indeed a data problem.

We’re living in the Data Age, in which the backbone of any effective security strategy, especially after COVID and SolarWinds, must center on data. Data is not only what we’re protecting, it’s what lets us optimize our investments and effectively communicate risk and mitigations. It’s what tells us when threat actors are knocking at the door or have already snuck in.

To effectively use data, we need to start by adopting a zero trust strategy, which is built on limiting the access to data and resources until a connection is proven secure. We are continually evaluating existing and emerging threats and the techniques, tactics and procedures (TTPs) these threat actors leverage, so that we can remediate any weaknesses. In addition, we need to deploy a modern security operations center (SOC) built on an intelligent and scalable data platform with full automation capabilities to catch threats, identify anomalies and shorten response cycles.

Lastly, we must also use data to improve communications, threat intelligence sharing and vendor trust. Take supply chain attacks: Software providers, like Splunk, have a duty to conduct a regular refresh of our vendors and ask them how they mitigate the risk of emerging threats. We then need to communicate that to our customers, as we did after the SolarWinds attacks. A robust and flexible platform is required to audit and share this data at scale with our customers and the community as a whole.

The past year presented challenges for security professionals, but it also opened opportunities, unlocked budgets and galvanized support at all organizational levels to build stronger security practices. I’m highly optimistic that security leaders are leveraging the current momentum to accelerate improvements and stay ahead of intensifying security challenges.

For more, including recommendations for improving your security posture, get The State of Security 2021.

----------------------------------------------------
Thanks!
Yassir Abousselham

Related Articles

Security Predictions 2026: What Agentic AI Means for the People Running the SOC
Leadership
10 Minute Read

Security Predictions 2026: What Agentic AI Means for the People Running the SOC

Splunk's Hao Yang shares our security predictions for 2026 and how agentic AI is reshaping how we see the SOC.
The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility
Leadership
4 Minute Read

The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility

Systems show symptoms. Business context shows impact. Discover why the future of observability is understanding what matters most to your customers.
MachineGPT, Agentic AI, and the New Foundation for Digital Resilience
Leadership
4 Minute Read

MachineGPT, Agentic AI, and the New Foundation for Digital Resilience

MachineGPT is foundational to the rise of Agentic AI in the enterprise, which is poised to fundamentally reshape digital operations – and it's advancing faster than we expected.
MachineGPT: Speaking the Language of Machines to Shape the Future of AI
Leadership
4 Minute Read

MachineGPT: Speaking the Language of Machines to Shape the Future of AI

MachineGPT brings the power of generative AI to one of the most overlooked resources: machine data. Splunk SVP & GM Kamal Hathi explains why mastering data as the heartbeat of the digital world is a game changer.
Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25
Leadership
3 Minute Read

Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25

Splunk's Kamal Hathi recaps our innovation highlights from .conf25, marking a pivotal moment for Splunk and Cisco as we deliver significant new value to our customers that make the use of AI a practical reality in their organizations.
Machine Data: Fighting Fire With Fire for Digital Resilience
Leadership
2 Minute Read

Machine Data: Fighting Fire With Fire for Digital Resilience

Kamal Hathi shares how Cisco and Splunk are helping organizations manage the explosion of machine data and AI-driven complexity, delivering real-time digital resilience to counter threats at machine speed and scale.
.conf25: Reinventing Digital Resilience for the Agentic Era
Leadership
3 Minute Read

.conf25: Reinventing Digital Resilience for the Agentic Era

Kamal Hathi shares how Cisco and Splunk deliver the data foundation, agentic intelligence, and cross-domain insights needed to build a more secure, resilient, and always-on digital enterprise.
UK Needn’t Fear The Data Deluge
Leadership
4 Minute Read

UK Needn’t Fear The Data Deluge

UK businesses face a data explosion—fueling growth but also raising risks in security, compliance, and operations. With smart data management strategies, organisations can regain control, boost resilience, and turn data into a true competitive edge.
Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco
Leadership
7 Minute Read

Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco

Cisco and Splunk deliver Digital Resilience by Design with seamless troubleshooting across security, observability, and networking domains, powered by AI innovations to manage complexity and stay ahead of risk.