TL;DR: Security leaders are seeing AI-driven productivity fail when it is layered onto overloaded SOC workflows, inconsistent data schemas, and rising analyst burden, according to Anomali. The real constraint is not tool availability but workflow redesign, because speed only matters when it removes work instead of shifting it around.
At a glance
What this is: This is an analysis of why security productivity initiatives often stall, with the key finding that AI and analytics tools do not improve SOC output unless data, workflows, and ownership are redesigned together.
Why it matters: It matters to IAM practitioners because the same governance problem appears across identity, NHI, and SOC programmes: if structure, context, and decision rights are weak, automation adds load instead of reducing risk.
By the numbers:
- Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.
👉 Read Anomali's analysis of why security productivity breaks at scale
Context
Security productivity breaks when organisations assume that more data, more dashboards, and more AI automatically translate into faster decisions. In practice, the SOC becomes busier rather than better, especially when teams keep legacy workflows intact while layering new analytics on top. The same pattern shows up in identity programmes when context is fragmented and decision ownership is unclear.
The article is fundamentally about governance, not technology procurement. That matters for NHI and IAM teams because automation only improves outcomes when the underlying data model, access context, and response workflow are consistent enough for people and systems to trust the result.
The starting position described here is common rather than exceptional: most security teams are already overloaded, so any productivity programme that adds tuning, supervision, or manual validation without removing work will stall.
Key questions
Q: How should security teams improve productivity without adding more analyst workload?
A: They should start by removing work, not automating every step. The best gains come from standardised data, workflows designed around decisions, and enrichment that reduces uncertainty early. If a new platform creates more tuning, more validation, or more handoffs, it is likely shifting effort rather than improving productivity.
Q: Why do security productivity programmes fail even when new AI tools are deployed?
A: They fail because tools are often layered onto unchanged processes. If analysts still need to double-check outputs, maintain inconsistent schemas, and manually interpret alerts, the programme adds complexity instead of reducing it. Productivity improves only when the operating model changes along with the technology.
Q: What signals show that access analytics is actually working?
A: Access analytics is working when analysts can trace unusual access back to a user, device, and workflow context without manual reconciliation. Useful signals include fewer unresolved cases, faster review cycles, and access records that support compliance and incident investigation without rework.
Q: Who should remain accountable when AI reduces security team workload?
A: Accountability should remain with the security function that owns the control, not with the model that helped process the work. AI can reduce workload, but it does not replace the need for clear decision ownership, especially where identity, escalation, or incident response outcomes are affected.
Technical breakdown
Why security analytics become noisy at scale
Security analytics degrade when teams ingest data faster than they standardise it. Logs arrive with different field names, event structures, and semantic meanings, so correlation engines and analysts spend time translating rather than deciding. AI can only reason reliably when the context is stable. Without schema alignment, enrichment, and clear data intent, volume creates ambiguity and suppresses trust in detections.
Practical implication: standardise event schemas before expanding analytics coverage or AI-assisted triage.
How workflow misalignment destroys productivity gains
Productivity fails when new tooling is overlaid on existing processes instead of replacing steps. If every alert still needs manual validation, every enrichment still requires analyst review, and every playbook still depends on senior engineer sign-off, the total work barely changes. Automation may shorten one task, but it does not reduce the number of decisions the SOC must make. That is why redesigning ownership matters as much as adding capability.
Practical implication: map each detection to the decision it should remove, not just the event it should enrich.
What fast search and enrichment actually change in investigations
Fast search only improves security operations when it reduces cognitive drag. Analysts can move from question to answer more quickly if enrichment provides user behaviour, access patterns, asset importance, and peer context in the same workflow. That makes triage less speculative and limits escalation to senior specialists. In identity-linked investigations, the same principle applies to service accounts, tokens, and privileged sessions, where context determines whether access is expected or suspicious.
Practical implication: build investigation views around identity context and access behaviour, not raw log retrieval alone.
Threat narrative
Attacker objective: The attacker objective is to outpace defensive decision-making long enough to expand access, conceal movement, and increase the eventual blast radius.
- Entry begins when attackers exploit speed gaps in the SOC, using automated tactics to create more alerts and lateral movement opportunities than analysts can comfortably investigate.
- Escalation occurs when defenders rely on manual validation across noisy telemetry, allowing adversary activity to progress while teams are still triaging and correlating events.
- Impact follows when delayed decisions widen the window for data theft, persistence, or broader operational disruption before containment is complete.
NHI Mgmt Group analysis
Security productivity is a governance problem before it is a tooling problem. The article shows that organisations often buy analytic capability without redesigning the work that surrounds it. That pattern is familiar in identity programmes too, where access reviews, enrichment, and exception handling can consume more effort than the control saves. Practitioners should treat workflow design as the control surface, not the dashboard.
Data context is the real productivity layer. AI-assisted operations fail when logs, identity signals, and asset context are inconsistent or incomplete. Standardisation matters because machines and analysts both need stable meaning, not just more events. In identity and NHI programmes, the same lesson applies to entitlement data, token lineage, and service ownership. The programme that cannot normalise its context will not scale its decisions.
Detection speed without decision speed is a false metric. Faster alert generation can still leave teams trapped in the same bottleneck if investigation, validation, and escalation steps remain untouched. This is where SOC operations and identity governance intersect: the control is only as effective as the time it takes to decide whether access or activity is legitimate. Practitioners should measure time-to-decision, not just time-to-detect.
Decision drag: this is the gap between seeing an event and being able to act on it with confidence. The article implies that productivity stalls when that gap is widened by noisy telemetry, fragmented schemas, and duplicated approvals. For identity and security leaders, the practical conclusion is to remove ambiguity early enough that analysts and systems can trust the next action.
Modernisation has to be staged, not sentimental. Replacing security platforms in one move usually fails because the response chain cannot absorb the disruption. Coexistence with clear boundaries, rollback planning, and validated milestones is the survivable model. That is as true for SOC analytics as it is for IAM and NHI programmes that need to modernise without breaking operational continuity.
What this signals
The practical signal for SOC and identity leaders is that productivity work must be treated as control design, not software deployment. If telemetry remains inconsistent and workflows remain fragmented, AI will amplify throughput pressure rather than relieve it. The next budgeting cycle should therefore prioritise data normalisation, decision mapping, and measurable time-to-decision improvements.
Decision drag: organisations should expect this gap between detection and confidence to become a central operational metric. For identity-adjacent investigations, that means prioritising access context, service ownership, and privilege lineage so analysts can decide faster. The same principle strengthens controls around service accounts and NHI workflows, where speed is only useful if the result can be trusted.
For practitioners
- Standardise security event schemas before scaling AI analytics Define a common field model across identity, endpoint, cloud, and application logs so correlation and enrichment work on consistent inputs rather than vendor-specific formats.
- Redesign SOC workflows around decisions, not data volume Map each alert class to the human decision it should support or eliminate, then remove steps that do not change containment, escalation, or closure outcomes.
- Track time-to-decision as the primary productivity metric Measure how long it takes from first signal to confident triage, because shorter alert latency means little if analysts still need hours to validate the event.
- Use identity context to reduce investigation friction Enrich security telemetry with user behaviour, privileged session detail, service ownership, and access scope so analysts can decide faster whether the activity is expected.
- Stage modernisation with rollback boundaries Move workloads in controlled phases, keep legacy coverage in place during transition, and define rollback criteria before replacing core detection or investigation paths.
Key takeaways
- Security productivity breaks down when teams buy more capability without changing how work flows through the SOC.
- Inconsistent data schemas and extra validation steps are the main reasons AI-assisted operations fail to deliver measurable gains.
- The right measure is time-to-decision, because productivity only exists when fewer events require human effort to resolve.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.DS-1 | Data consistency and context are central to this article's analytics problem. |
| NIST SP 800-53 Rev 5 | AU-6 | The article centres on turning raw logs into usable security decisions. |
| CIS Controls v8 | CIS-8 , Audit Log Management | Effective log management is the foundation for reducing noisy security operations. |
| NIST AI RMF | MANAGE | AI is used as an operational capability that must be governed for trustworthy output. |
| MITRE ATT&CK | TA0008 , Lateral Movement; TA0040 , Impact | The article references adversary speed and the consequences of delayed containment. |
Align telemetry normalisation and enrichment to PR.DS-1 so analytics can support faster, trusted decisions.
Key terms
- Decision drag: Decision drag is the delay between detecting an event and being able to act on it with confidence. It appears when noisy telemetry, inconsistent context, and duplicated approvals make analysts spend more time validating than responding. In practice, it is a governance and workflow problem, not just a tooling issue.
- Security productivity: Security productivity is the degree to which a security programme removes work, shortens investigations, and improves decision quality without increasing operational burden. It is measured by outcomes such as faster triage, fewer escalations, and reduced manual verification, not by how many tools or dashboards a team deploys.
- Workflow alignment: Workflow alignment means designing analytics, detections, and automation around the actual sequence of decisions the SOC must make. When the workflow is aligned, each signal supports a clear next action. When it is not, teams accumulate alerts, handoffs, and rework that slow containment.
- Data Context: Data context is the operational understanding of what data exists, where it lives, how sensitive it is, and which identities can reach it. In incident response, data context turns alerts into decisions by showing whether a system holds regulated records, test copies, or low-risk content. It is essential for defensible containment and notification scope.
What's in the full article
Anomali's full article covers the operational detail this post intentionally leaves for the source:
- The webinar discussion points on AI-driven productivity and the specific SOC friction points the speakers say are most common.
- The full breakdown of how noisy telemetry, schema inconsistency, and analyst overload interact in day-to-day operations.
- The concrete examples of modernisation sequencing and coexistence planning that the article uses to argue against big-bang replacement.
- The leadership signals discussed for measuring whether productivity work is actually reducing workload rather than shifting it.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need to connect identity controls to broader security operations and governance outcomes.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org