TL;DR: A survey of nearly 300 CISOs, SOC leaders, and SecOps practitioners found large enterprises generate 3,181 alerts a day, 40% of alerts go uninvestigated, and average alert dwell time is 56 minutes, according to Prophet Security. The operational problem is not just volume, but whether SOC workflows can preserve triage quality as AI absorbs more of the workload.
At a glance
What this is: This survey says large SOCs are drowning in alerts, with investigation gaps and dwell times that leave threats sitting idle for nearly an hour.
Why it matters: It matters because SOC automation, AI-assisted triage, and identity-adjacent detections all depend on reducing noise fast enough for analysts and systems to act before risk compounds.
By the numbers:
- Approximately 40% of alerts are ignored or left uninvestigated due to resource constraints.
- Alert dwell time, the interval between an alert firing and initial triage, averages about 56 minutes.
- Within three years, respondents anticipate AI will manage approximately 60% of SOC workloads.
👉 Read Prophet's full report on AI in the SOC survey findings
Context
Security operations are under pressure from two directions at once. Alert volume keeps rising, while the time available for triage keeps shrinking. In that environment, AI in the SOC is less about novelty and more about whether teams can preserve detection quality, investigation speed, and response discipline.
The identity angle is indirect but real. SOC tooling increasingly touches human identities, service accounts, and machine identities through authentication events, access anomalies, and privileged behaviour. When alert fatigue rises, those identity signals are exactly the ones most likely to be missed, misrouted, or triaged too late.
Key questions
Q: How should financial institutions use AI SOC agents without losing investigation quality?
A: Use AI SOC agents to gather evidence, correlate telemetry, and draft case narratives, but keep human review on the final decision path. The goal is not to remove analysts. It is to standardise the evidence trail, reduce repetitive correlation work, and ensure every case can survive audit, incident review, and regulatory scrutiny.
Q: Why do large alert volumes create security risk even when tools are working?
A: High alert volume creates risk because analysts cannot investigate everything at the same speed, so important signals wait in queue or get ignored. When dwell time rises, attackers have more time to move, exfiltrate data, or blend into normal activity before the SOC responds.
Q: What do security teams get wrong about GenAI in the SOC?
A: They often assume the model reduces the need for analyst judgment. In practice, GenAI reduces reading and writing time, but the analyst still owns interpretation, prioritisation, and escalation. If the team uses the model to replace verification, it will amplify mistakes instead of reducing workload.
Q: How should organisations govern access to data used by AI systems?
A: Treat AI data access as an identity governance problem, not just a data storage problem. Define who or what can use each dataset, what purpose is allowed, and what runtime restrictions apply. Then review humans, service accounts, and AI agents separately so entitlement scope matches actual behaviour rather than a generic AI policy.
Technical breakdown
Why alert overload breaks SOC triage
SOC triage depends on a queue that can be prioritized faster than threats evolve. When teams face thousands of alerts per day, analysts start rationing attention, which lowers the quality of first-line investigation and increases dwell time. This is not just a staffing problem. It is a signal-routing problem caused by too many tools producing too many weakly differentiated alerts. In practice, the SOC loses the ability to separate high-confidence activity from noisy detections, especially when identities, endpoints, and cloud systems all emit overlapping events.
Practical implication: teams should reduce duplicate detections and define escalation logic around confidence, context, and blast radius.
How AI changes SOC workload distribution
AI in security operations works best when it automates repetitive enrichment, clustering, and summary work while leaving final judgement to humans. The survey suggests leaders expect AI to absorb a large share of SOC workload, but that only works if models are integrated into existing case management, ticketing, and investigation paths. AI does not remove the need for control ownership. It shifts the human role from first-pass sorting to exception handling, quality assurance, and response authorization.
Practical implication: implement AI where it compresses triage time, not where it obscures the evidence chain.
Data privacy constraints in AI-enabled SOCs
The biggest barrier in the report is not fear that AI will replace analysts. It is privacy and regulatory risk around the data used to train, tune, or operate SOC AI. That is a governance issue, not a tooling issue. Security telemetry often contains personal data, sensitive access patterns, and incident details that may be subject to retention, jurisdiction, or purpose-limitation controls. If those constraints are not built into the workflow, AI adoption becomes a compliance risk instead of an operations improvement.
Practical implication: classify telemetry, restrict model inputs, and define retention rules before expanding AI-assisted investigation.
NHI Mgmt Group analysis
Alert fatigue has become a governance failure, not just an operations inconvenience. When 40% of alerts are left uninvestigated, the problem is no longer whether a team is busy. It is whether the SOC can still claim effective control over its detection pipeline. In mature programmes, triage capacity is part of security governance, not an afterthought. The practitioner takeaway is that alert quality, routing, and ownership must be managed as core control design.
AI in the SOC will reward organisations that treat automation as workflow redesign. Adding AI to a broken queue only speeds up the wrong process. The survey points to a future where AI handles a large share of repetitive workload, but the decisive question is whether the organisation has redefined escalation, validation, and handoff rules. The practitioner implication is to redesign the operating model before scaling model-driven triage.
Identity telemetry is one of the first places alert overload creates blind spots. Authentication anomalies, privileged access spikes, and service account misuse are easy to bury when analysts are overwhelmed. That makes SOC AI relevant to IAM and NHI governance even when the article is not explicitly about identity. The field should treat identity events as high-value signals that deserve priority routing, not just another alert class. Practitioners should preserve identity-specific context in SOC workflows.
Data privacy will shape AI adoption in security operations more than model accuracy will. The survey suggests leaders are already willing to trust AI if it can be integrated safely, but the blockers are regulatory and operational. That means the next phase of SOC AI is likely to be governed by data handling rules, not just detection performance. Practitioners should align AI-enabled SOC designs with privacy controls, retention policies, and auditability requirements.
What this signals
Alert volume is now a programme-design issue, not a tooling issue. SOC teams that keep stacking products without simplifying triage will keep paying the same tax in analyst time and missed detections. The operational signal to watch is whether automation is reducing queue length and dwell time, not just generating more dashboards.
AI-assisted SOC workflows should be measured against control outcomes, not adoption counts. If analysts still need to re-check everything the model touches, the programme has only added a new layer of work. The better metric is whether alerts reach the right decision point faster with less noise and better evidence.
Identity and access events will need priority handling inside AI-enabled SOC pipelines. Authentication anomalies, privileged access spikes, and machine identity misuse often carry more value than generic telemetry, especially when analyst capacity is stretched. Teams should preserve those signals as high-priority detection paths rather than burying them inside broad alert queues.
For practitioners
- Rationalise alert sources and deduplicate detections Inventory the 28 or more alert-producing tools that typically feed large SOCs, then remove overlapping detections, redundant enrichments, and low-value noise before adding more automation. Focus on queues where duplicate alerts are masking identity, endpoint, or cloud incidents.
- Build AI triage into the case-management path Use AI to summarize, cluster, and enrich alerts inside existing SOC workflows so analysts can validate evidence without switching tools or losing context. Keep human approval in the escalation path for high-impact investigations and privileged-access events.
- Prioritise identity and privilege signals for fast triage Route authentication anomalies, service account misuse, and unusual privileged activity above generic noise so identity-related incidents do not sit behind lower-value alerts. This is especially important where human and machine identities share monitoring pipelines.
- Define telemetry privacy and retention rules before scaling AI Classify security telemetry that may contain personal data or sensitive access patterns, then set approved inputs, retention periods, and audit requirements for AI-assisted analysis. That prevents compliance gaps from becoming the hidden cost of SOC automation.
Key takeaways
- The survey shows that alert fatigue is already creating missed investigations, longer dwell times, and weaker SOC triage discipline.
- AI is moving into the SOC as a workload-shaping capability, but privacy and integration constraints will determine how far it can be used.
- Security teams should treat identity and privilege signals as high-value telemetry and redesign workflows before scaling automation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST AI RMF, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-1 | Alert monitoring and triage are central to the survey's SOC workload findings. |
| NIST AI RMF | GOVERN | AI use in the SOC raises governance, accountability, and privacy questions. |
| NIST SP 800-53 Rev 5 | AU-6 | Alert review and analysis depend on audit review processes that can sustain triage quality. |
| CIS Controls v8 | CIS-8 , Audit Log Management | The article centers on analysing and prioritising large alert volumes from security tooling. |
Use DE.CM-1 to assess whether detection coverage is producing actionable, not excessive, alert volume.
Key terms
- Alert Dwell Time: The time between an alert being generated and a human analyst beginning triage. In practice, it measures how long a signal sits in the queue before the organisation starts making containment decisions, which makes it a direct indicator of operational responsiveness.
- Alert Fatigue: Alert fatigue is the condition where a security team receives so many low-value alerts that important events become harder to notice. In monitoring programs, it usually signals poor rule tuning, weak prioritisation, or a mismatch between detection logic and operational reality.
- SOC automation: The use of automated workflows to triage, enrich, route, or suppress security alerts. It improves analyst efficiency when boundaries are clear, but it becomes a governance issue when automation can make final decisions that affect evidence, containment, or incident status.
- AI-Assisted Triage: The use of machine-driven prioritisation to sort, rank or route suspicious cases for human review. It can improve speed and consistency, but only if analysts can understand, challenge and override the recommendation. Without governance, it becomes a hidden decision layer inside the investigation process.
What's in the full report
Prophet's full report covers the operational detail this post intentionally leaves for the source:
- Survey breakdowns by practitioner role, including CISOs, SOC leaders, and SecOps respondents
- Reported AI use cases for alert triage, investigation, and workload reduction
- ROI measurement approaches for AI in the SOC
- The full distribution of investigation times and tool counts behind the headline findings
Deepen your knowledge
NHI Mgmt Group covers identity security, NHI governance, and agentic AI through independent research, practitioner guides, and the NHI Foundation Level course, the industry's only accredited NHI security programme. It helps security and identity practitioners connect workload, privilege, and lifecycle controls to real-world governance decisions.
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org