Data has overtaken skilled staffing as the biggest barrier to effective threat hunting for the first time in the SANS Institute’s annual survey.
The SANS 2026 Threat Hunting Survey: The Evolution of Threat Hunting, authored by SANS Principal Instructor Josh Lemon, draws on responses from 500 cybersecurity practitioners and security leaders across North America, Europe, Latin America and Asia.
Although 82% of respondents have been hunting threats for at least two years, half now identify data quality or quantity as their primary obstacle, ahead of skilled staff at 45%. Cloud infrastructure is the toughest environment for 32% of respondents.
“You can be the most capable hunter in the room and still come up empty if the telemetry you're working with is incomplete, inconsistent, or scattered across a dozen tools that are difficult to access or difficult to process,” said Lemon.
“And with only 40% of programmes formally measuring whether their hunting actually works, most organisations have no real way of knowing whether that gap is costing them.”
Methodology and measurement under pressure
The proportion of organisations with a formally defined threat-hunting methodology fell to 37%, from 46% in 2025 and 51% in 2024. Ad hoc approaches rose to 39%.
Formal measurement of outcomes also declined, reaching 40% compared with 64% in 2024. SANS warns that this makes it harder for teams to demonstrate their value and defend budgets.
Living-off-the-land techniques, which use legitimate system tools to blend into normal activity, were identified as the leading approach used by nation-state actors by 73% of respondents, and by organised crime by 63%.
A more measured approach to AI
AI and machine-learning integration remained a planned improvement for 39% of respondents, down from 48% in 2025. SANS interprets this as a more grounded approach to testing the technology against existing workflows.
Outsourcing fell to 18%, from 30% in 2025, while the share keeping threat hunting in-house remained at 58% for a second year.













