DEGOOLCYBER SECURITY SOLUTIONS
STUDIES & RESEARCH

What the data actually says

Peer-reviewed studies, longitudinal telemetry analysis and field research from the DeGooL research group. Every published figure is reproducible from the methodology appendix.

FLAGSHIP STUDY · 2026

GCC Threat Landscape Report 2026

Two years of sensor data across 312 estates in nine countries: 4,180 confirmed incidents classified by initial access vector, dwell time, sector and containment outcome — with the full statistical method published alongside.

4,180
CONFIRMED INCIDENTS
312
ESTATES SAMPLED
9
COUNTRIES
24 mo
OBSERVATION WINDOW

Research programmes

Four standing programmes, each with a published output cadence and named lead.

PRG-01

Adversary tracking

Longitudinal tracking of financially motivated and state-aligned clusters operating against GCC targets, with published TTP mappings.

QUARTERLY TEARDOWN

PRG-02

Detection efficacy

Measuring which detection logic actually survives production: precision, recall and decay rates across 1,780 maintained rules.

BIANNUAL STUDY

PRG-03

AI-assisted triage

Controlled comparison of analyst-only, model-only and model-assisted triage on identical incident sets, including error taxonomy.

ANNUAL PAPER + DATASET

PRG-04

OT protocol security

Field research on industrial protocol abuse in energy and water infrastructure, conducted on instrumented test rigs.

CONFERENCE TRACK

Published studies

PEER-REVIEWEDAUG 2026

Model-assisted triage versus analyst-only triage: a controlled comparison on 12,400 incidents

Analysts and a Claude-based reasoning layer were given identical incident sets under blind conditions. We report agreement rates, error taxonomies and the cases where model assistance degraded rather than improved the verdict.

DEGOOL RESEARCH GROUP · 34 PP · METHODOLOGY APPENDIX INCLUDED

94.2%
Analyst agreement with model verdict
3.1%
Cases where assistance degraded the verdict
TELEMETRY STUDYJUN 2026

Dwell time in the GCC: 4,180 incidents by initial access vector

Distribution of attacker dwell time across sectors and initial access vectors, with survival analysis showing where detection coverage changes the curve and where it does not.

DEGOOL RESEARCH GROUP · 52 PP · DATASET AVAILABLE UNDER NDA

62 h
Median dwell time, unmonitored estates
−94%
Reduction under 24/7 monitoring
FIELD RESEARCHAPR 2026

Modbus and DNP3 abuse on instrumented industrial test rigs

Twelve attack primitives executed against a physical test rig, with the passive detection signatures each one produces and the false-positive cost of deploying them in production.

OT PRACTICE · 41 PP · SIGNATURES PUBLISHED

12
Attack primitives characterised
9 / 12
Detectable passively with no production impact
LONGITUDINALFEB 2026

Detection rule decay: why 41% of rules stop working within a year

We tracked 1,780 detection rules over 24 months. Precision decays predictably with estate change; we identify the four drivers and the maintenance cadence that arrests them.

DETECTION ENGINEERING · 28 PP

41%
Rules materially degraded within 12 months
4
Dominant decay drivers identified
SURVEYDEC 2025

Security staffing and alert load across 140 regional organisations

Anonymous survey of security leaders in the GCC on team size, alert volume, triage capacity and the share of the queue that is never reviewed.

DEGOOL RESEARCH GROUP · 22 PP · RAW RESPONSES ANONYMISED

31%
Median share of alert queue never triaged
1 : 4,900
Analysts per monitored asset
PEER-REVIEWEDOCT 2025

Auditability requirements for LLM-assisted security decisions

What a reasoning trace must contain to satisfy an ISO 27001 or SOC 2 auditor, derived from twelve real audit engagements where model-assisted decisions were in scope.

GOVERNANCE PRACTICE · 19 PP

12
Audit engagements analysed
7
Mandatory trace elements identified

Methodology & data sources

ALL FIGURES REPRODUCIBLE FROM THE APPENDIX
Research data sources, scope, volume and method
DATA SOURCESCOPEVOLUMEMETHOD
Client telemetry312 consenting estates, 9 countries41.6 B events/dayAggregated, de-identified at collection
Honeynet sensorsGCC region, 14 sensor sites2.31 M probes/dayFull packet capture, manual classification
Dark web collectionForums, paste sites, broker listings3.4 M credential recordsAutomated collection, human verification
Incident caseworkDFIR engagements 2024–20264,180 confirmed incidentsStructured post-incident coding, dual reviewer
Purple-team exercisesClient estates, quarterly1,780 rules testedAtomic test replay, precision/recall scored
Practitioner survey140 regional organisations140 responsesAnonymous, self-reported, weighted by size

Find out what your telemetry is already telling you.

Two-week assessment: we ingest your existing logs, run the Sentinel detection pack, and hand back a prioritised findings report. No agents, no commitment.