Traditional SOC models have faced persistent challenges for several years now, including:
-
Alert fatigue due to high volumes and high false-positive rates. When analysts review high volumes of alerts that repeatedly need to be designated as false-positives, it becomes increasingly hard for them to spot the real incidents between the noise.
-
Difficulties to attract and retain SOC staff, especially analysts. The job requires specific and advanced skills, continuous concentration and eagerness to learn, as well as the willingness to be on-call.
-
Increasing attack sophistication, volume and speed. Attackers no longer need to search for days to find weaknesses and exploit them, but can automate these reconnaissance and exploitation attempts at scale.
-
Inability to achieve SLAs (Service Level Agreements) due to alert volumes/spikes. When a lot of alerts pile up in a short time frame, it becomes difficult to respond to all of them within the SLA.
As a result, even mature environments struggle to filter signal from noise. Detection engineering pipelines are unable to keep pace with the explosive growth of threat intelligence and the various forms of telemetry, while analysts spend a disproportionate amount of time on alert triage. This is exactly where AI thrives. Not as a substitute, but as an accelerator.
The most impactful use of AI in SOC practices is not in “thinking like an analyst” but in amplifying analyst effectiveness through automation, pattern recognition and contextualization. In this capacity, AI can excel at routine and procedural tasks such as:
-
Alert triage and basic investigations. Triage agents already perform at a quality level comparable to that of human analysts, but deliver results in a fraction of the time.
-
Context enrichment through threat intelligence. When an analyst receives an alert, AI can collect and structure contextual information to streamline, facilitate, and accelerate the investigative process.
-
Alert aggregation, correlation, and outlier detection across different sources. Aggregating alerts from different sources linked to the same event and correlating events that are part of the same incident can be very time-consuming, while anomalies in large amounts of “normal data” are easily missed. AI can efficiently and effectively perform these tasks on behalf of the analyst.
-
Ticket life cycle management (including internal and customer communications). AI tools are useful for deciding when to create a ticket, who to assign it to and sending out consistent communications in line with a pre-defined communication plan (often part of the Incident Response Plan).
However, these workflows must remain observable, auditable, and controllable to avoid introducing additional risks and/or decreasing service quality. The effectiveness and completeness of the tasks executed by AI are directly correlated to the quality and comprehensiveness of their training data. When threat actors leverage novel TTPs (Tactics, Techniques & Procedures), unknown vulnerabilities or weaknesses (“zero-days”), human intelligence and the analyst’s mindset will remain the differentiators between over-automated and well-balanced modern SOCs.
As always, the cat-and-mouse game between attackers and defenders extends into the AI field. Attackers are not only leveraging AI to increase the efficiency and complexity of their offensive operations. They are also actively exploring ways to attack AI as a defensive tool itself, for example by generating benign-looking patterns or poisoning training data to evade AI-based detections.
Conclusion
In an AI-enabled SOC, the roles and responsibilities of analysts will not disappear. Instead, they will become even more critical as the first-line supervisors of AI. From automating repetitive tasks to validating AI-delivered verdicts, analysts will be able to dedicate more time to in-depth investigations, contributions to detection engineering improvements and even proactive threat-hunting. AI will undoubtedly redefine SOC practices, but it will not replace the human element. Instead, it will elevate it.
In the eternal battle between threat actors and cyber defenders, intelligently combining machine efficiency with human expertise will become a key factor in safeguarding modern society.