By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: IntezerPublished March 25, 2026

TL;DR: More than 25 million security alerts were processed across live enterprise SOC environments in 2025, with 126% net revenue retention and adoption across Fortune 500 organisations pointing to a wider shift toward AI SOC models that investigate every alert at machine scale, according to Intezer. The operational question is no longer whether automation helps, but how teams govern machine-led triage without losing decision quality, auditability, or internal control.


At a glance

What this is: This is an analysis of how enterprise security operations are moving toward AI SOC, with Intezer presenting alert-scale and customer-growth signals as evidence of accelerating adoption.

Why it matters: It matters because SOC teams, IAM leaders, and security architects need to understand how machine-scale investigation changes alert governance, escalation thresholds, and identity-linked telemetry across endpoint, cloud, network, and SIEM workflows.

By the numbers:

👉 Read Intezer's analysis of AI SOC momentum and enterprise adoption


Context

AI SOC is a security operations model that uses machine-scale investigation to triage alerts, correlate context, and reserve analysts for the incidents that truly need human judgment. The article argues that traditional SOC and MDR models are constrained by alert overload, which forces teams to sort alerts before they have full context, leaving real risk hidden in the uninvestigated backlog.

The identity angle is material because the article explicitly says AI SOC investigates across endpoint, identity, cloud, network, phishing, and SIEM sources. That makes identity telemetry part of the SOC data plane, not a separate governance lane, and it means access events, authentication anomalies, and privilege signals can be evaluated alongside broader threat indicators. For teams already managing NHI, human identity, and cloud identity controls, that convergence changes how investigation, escalation, and accountability are organised.

The starting position described here is increasingly typical for large enterprises, not an edge case. Alert volume, cross-domain telemetry, and analyst scarcity are now shared constraints, which is why machine-led investigation is moving from an efficiency discussion to an operating-model decision.


Key questions

Q: How should security teams govern AI SOC triage without losing accountability?

A: Security teams should require clear escalation thresholds, logged decision paths, and retained evidence for every automated outcome. The goal is not to let machines replace analysts, but to ensure machine-scale triage stays explainable, reviewable, and aligned to incident handling and audit requirements.

Q: Why do identity events matter in AI SOC workflows?

A: Identity events often provide the earliest signal of compromise, especially when attackers use valid accounts, tokens, or privilege changes instead of noisy malware. If identity telemetry is excluded from SOC correlation, teams lose the context needed to connect access behaviour to endpoint or cloud activity.

Q: What breaks when alert volume is handled only by manual triage?

A: Manual triage forces teams to prioritise before they have full context, which means lower-severity or less obvious alerts can hide genuine incidents. The result is delayed detection, inconsistent escalation, and a backlog that attackers can exploit while analysts focus on the loudest events.

Q: Who is accountable when automated investigation suppresses a real incident?

A: Accountability stays with the organisation, not the automation. Security leaders need ownership for tuning, oversight, and review of automated triage decisions, plus governance that shows how the SOC will detect suppression errors, reconstruct cases, and escalate exceptions quickly.


Technical breakdown

How AI SOC triages alerts at machine scale

AI SOC systems ingest alerts from multiple security sources, normalise the data, and score or cluster events so investigation can happen before an analyst sees the queue. The technical shift is from severity-first routing to context-rich triage, where the system correlates artefacts, historical patterns, and asset or identity context to decide what deserves deeper review. In this model, humans no longer inspect every event. They validate the subset that crosses a confidence or risk threshold, which changes the design of workflows, evidence capture, and escalation logic.

Practical implication: teams need a defined escalation policy that ties machine scoring to human review thresholds and audit evidence.

Why cross-domain telemetry matters for identity and cloud investigations

The value of AI SOC depends on whether it can correlate signals across endpoint, identity, cloud, network, phishing, and SIEM sources. That matters because attackers rarely stay inside one telemetry domain. A suspicious login, token use, cloud permission change, and endpoint execution chain may only look meaningful when combined. For identity programmes, this makes IAM and NHI events part of operational detection rather than compliance records. It also raises the quality bar for entity resolution, because the SOC must reliably connect identities, hosts, and workloads without inflating false positives.

Practical implication: consolidate identity, NHI, and cloud telemetry into investigation workflows that preserve correlation context.

What forensic depth means in an AI SOC workflow

Forensic depth means the system does not stop at alert classification. It preserves artefacts, explains why an alert was escalated or suppressed, and supports review of the chain of evidence. That is different from simple automation, which may close alerts without enough traceability for analysts or auditors. In a SOC environment, auditability is as important as speed because security teams still need to justify decisions, reconstruct incidents, and demonstrate that critical cases were not ignored. A machine-led workflow without evidence retention can reduce noise while increasing governance risk.

Practical implication: require decision logs, evidence retention, and reproducible investigation trails before expanding machine-led triage.


Threat narrative

Attacker objective: The attacker objective is to advance through security environments without early detection by exploiting investigation bottlenecks and alert overload.

  1. Entry occurs as attackers generate, inherit, or trigger alerts across endpoint, identity, cloud, or SIEM sources that need correlation before the real incident is visible.
  2. Escalation happens when fragmented triage or severity-based filtering leaves contextual clues unconnected, allowing threat activity to remain buried in the queue.
  3. Impact follows when real incidents are not investigated early enough and human analysts are forced into reactive response after the attacker has already progressed.

NHI Mgmt Group analysis

AI SOC is becoming an operating model, not a point product category. The article’s core signal is that enterprises are buying relief from investigation overload, not just another detection layer. That matters because security operations now has to govern how machine-led triage changes the relationship between alerts, evidence, and analyst decision-making. For practitioners, the relevant question is whether the SOC can still explain why an alert was escalated or suppressed, not whether it was automatically processed.

Alert-bottleneck risk: when teams sort events before full context is available, they create a governance gap that attackers can exploit indirectly. This is not only a detection problem. It is a workload allocation problem that can hide real incidents inside the uninvestigated tail, especially where identity, cloud, and endpoint signals are separated. For identity programmes, that means NHI and human identity telemetry must be treated as live threat inputs, not retrospective records.

Identity data is now part of security operations throughput. Once AI SOC platforms investigate across identity and NHI events, IAM governance becomes operationally relevant to SOC performance. Access anomalies, privilege escalation, and token misuse are no longer adjacent controls. They are part of the same triage pipeline that determines what gets escalated. Practitioners should therefore treat identity telemetry quality as a SOC control dependency, not a reporting nice-to-have.

Machine-scale investigation only works if the evidence chain survives the automation. Fast triage without reproducible reasoning creates a new kind of risk, where teams cannot defend why a decision was made or reconstruct how a case was handled. That is where governance frameworks such as NIST CSF and NIST SP 800-53 matter, because SOC automation has to preserve detection, logging, and accountability. The practical conclusion is simple: automation should reduce analyst burden, not reduce investigability.

AI SOC is likely to widen the gap between mature and immature security programmes. Enterprises with clean telemetry, well-governed identity data, and clear escalation criteria can absorb machine-led investigation more safely than teams already struggling with data quality. That means adoption will not be uniform. Practitioners should expect pressure to improve identity, cloud, and SIEM data hygiene before AI SOC delivers its promised operating value.

What this signals

Alert-bottleneck governance is becoming the real SOC maturity test. As AI SOC adoption grows, programmes will be judged less by how many alerts they ingest and more by how well they preserve decision quality while reducing backlog. That makes escalation policy, evidence retention, and identity correlation part of operational resilience, not just SOC tooling configuration. For teams managing NHIs, this also means machine identity signals need to be reliable enough for automated triage to trust them.

Cross-domain correlation will expose weak identity data first. If access events, token activity, and privilege changes cannot be resolved cleanly across tools, AI SOC value will plateau quickly. The practical pressure point is data hygiene, especially where cloud, endpoint, and identity systems disagree on asset and principal identity. Teams should expect to improve telemetry quality before they can safely expand machine-led investigation.

From our research: 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, which helps explain why identity data quality remains uneven across programmes. That confidence gap becomes more visible once SOC workflows start depending on identity context at machine speed.


For practitioners

  • Define human-review thresholds for machine-led triage Set explicit escalation thresholds for alerts that require analyst judgment, and document which identity, cloud, and endpoint signals must be present before a case is auto-escalated. Preserve the decision logic so reviewers can reconstruct why the system handled an alert the way it did.
  • Integrate identity telemetry into SOC workflows Route authentication anomalies, privilege changes, token misuse, and NHI activity into the same investigation queues as endpoint and cloud signals. This helps the SOC correlate incidents across domains instead of treating identity events as separate administration records.
  • Require evidence retention for every automated decision Keep the artefacts, scoring rationale, and correlation context that led to suppression, escalation, or closure. Without retained evidence, machine-scale investigation can lower noise while creating audit and reconstruction gaps.
  • Validate correlation quality before expanding automation Test whether your SOC can reliably link identities, workloads, and assets across SIEM, cloud, and endpoint sources without inflating false positives. Poor entity resolution will undermine the value of AI-led investigation.

Key takeaways

  • AI SOC shifts security operations from manual alert handling to machine-scale investigation, changing how teams allocate analyst attention and preserve evidence.
  • The most important risk is not automation itself but loss of context, because identity, cloud, and endpoint signals can only be defended if the decision trail survives triage.
  • Practitioners should treat identity telemetry quality, escalation logic, and auditability as core SOC controls before expanding machine-led investigation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1AI SOC depends on continuous monitoring across identity and security telemetry.
NIST SP 800-53 Rev 5AU-6Automated triage still needs review and analysis of audit events and decisions.

Tie machine-led triage to continuous monitoring objectives and verify identity signals are covered.


Key terms

  • AI-SOC: An AI-SOC is a security operations model where AI systems help triage alerts, investigate events, and trigger response actions. In practice, it is valuable only when the automation is observable, bounded, and tied to accountable identity and evidence records.
  • Forensic depth: Forensic depth means an investigation preserves enough context, evidence, and reasoning to explain what happened and why an alert was escalated or dismissed. In SOC operations, it supports auditability, incident reconstruction, and defensible decision-making.
  • Alert bottleneck: An alert bottleneck is the point at which more security events are generated than analysts can reasonably investigate with full context. It creates a governance risk because prioritisation happens before all evidence is available, which can hide real incidents in the backlog.
  • Identity Telemetry: Identity telemetry is the collection of signals generated by authentication, session, and access events across human and non-human identities. It becomes useful for governance when teams can baseline normal behavior and detect drift in source, privilege, or access frequency.

What's in the full article

Intezer's full post covers the operational detail this analysis intentionally leaves for the source:

  • Revenue and retention context behind the company's year-over-year growth
  • Coverage examples and analyst recognition cited in the article
  • The full description of how Intezer frames 100% alert investigation at forensic depth
  • The market positioning detail behind its AI SOC operating model

👉 Intezer's full post covers the growth metrics, market signals, and SOC operating model in more detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need to connect identity controls to broader security operations and risk management.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org