By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Legion AIPublished January 6, 2026

TL;DR: Most SOCs are wasting analyst capacity on repetitive work, onboarding drag, and manual investigation steps rather than facing a pure hiring problem, according to Legion AI. The real issue is governance of analyst time, because automation that stays with analysts can reclaim expertise, reduce burnout, and improve investigation quality.


At a glance

What this is: This is Legion AI's argument that SOC underperformance is driven less by headcount gaps than by wasted analyst time, repetitive workflows, and poor automation design.

Why it matters: It matters to IAM and security leaders because the same governance failure that wastes SOC talent also wastes identity, PAM, and NHI operations capacity when manual processes are left to accumulate.

By the numbers:

  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

👉 Read Legion AI's analysis of SOC talent waste and workflow automation


Context

SOC burnout is often treated as a people problem, but the article describes it as a workflow problem. Analysts spend too much time on repetitive enrichment, copy-and-paste investigations, and onboarding tasks that do not improve detection quality. In that sense, the primary issue is operational design, not simply the availability of staff.

That pattern has a close governance parallel in identity security. When access reviews, secrets handling, or NHI lifecycle work are left as manual routines, teams lose time, context, and consistency in exactly the same way. The article's starting position is common across mature security programmes, which is why the problem deserves to be framed as control design rather than staffing sentiment.


Key questions

Q: How should SOC teams reduce analyst burnout without hiring more staff?

A: Start by removing repetitive work from senior and tiered analysts, then convert the most common investigation steps into reusable workflows. Burnout usually reflects poor task design, not weak commitment. If analysts spend their day on copy-and-paste enrichment, the team will keep losing time, context, and retention even when hiring continues.

Q: Why does manual SOC work create security risk as well as inefficiency?

A: Manual work creates risk because it slows investigations, introduces variation between analysts, and pushes skilled people away from hunting and tuning. When the best defenders are trapped in routine steps, attackers get more time and the SOC gets less signal. The result is weaker detection quality, not just lower morale.

Q: What are the signs that an automated SOC workflow is failing?

A: Common signs include repeated manual overrides, reopened cases, approval delays, duplicate tickets, and failed containment actions. If analysts keep rebuilding context outside the case record, the workflow is not absorbing work. The best indicator is whether the case moves forward with fewer touches and clearer accountability across shifts.

Q: How do identity and SOC programmes both suffer from control toil?

A: Both fail when high-value staff spend too much time on repetitive administrative steps. In identity work, that can mean access reviews, lifecycle cleanup, or entitlement exceptions. In SOC operations, it means triage and investigation loops. The common fix is to standardise the routine and preserve human judgment for decisions that need it.


Technical breakdown

Why repetitive SOC workflows create talent waste

Talent waste happens when skilled analysts spend most of their time on low-value, repeatable tasks that do not require judgment. In a SOC, that includes routine alert enrichment, standard triage steps, and repetitive onboarding. The technical issue is not just inefficiency. It is that the organisation forces human expertise into deterministic workflows that could be encoded, reused, or delegated. Over time, this produces slower investigations, uneven quality, and lower analyst retention because the work no longer matches the capability of the people doing it.

Practical implication: Map repeatable tasks into automatable workflows before asking for more headcount.

How analyst-led automation changes SOC operating models

Analyst-led automation shifts workflow design away from engineering bottlenecks and into the hands of the people who actually perform the work. Instead of requiring API development or scripting support, analysts capture the steps they already follow, then reuse them consistently across cases. That matters because automation is most effective when it reflects real investigative behaviour, not a generic playbook. It also reduces variance between analysts, which improves training, response consistency, and time to resolution.

Practical implication: Let frontline analysts own the automation of their most repeated investigations.

Why AI-enabled orchestration needs organisational context

The article points to a broader security principle: AI systems are only useful in operations if they understand the environment they are acting in. In the SOC, that means the difference between a useful orchestrator and a noisy assistant is contextual grounding in tools, workflows, and prior decisions. Without that context, automation may accelerate the wrong action or reproduce bad process. With it, AI can support triage, recommendation, and action while preserving human accountability.

Practical implication: Treat context capture as a control requirement, not a convenience feature.


Threat narrative

Attacker objective: The practical objective is to keep defenders stuck in low-value work so they cannot devote enough time to detection, tuning, and response.

  1. Entry occurs through uncontrolled repetitive work and manual workflows that consume analyst time rather than through a single exploit event.
  2. Escalation happens as burnout, inconsistency, and onboarding drag degrade institutional knowledge and reduce the team's ability to act on higher-value threats.
  3. Impact is slower detection, lower-quality investigations, and reduced SOC capacity to hunt, tune, and respond effectively.

NHI Mgmt Group analysis

Talent waste is the hidden governance failure in many SOCs. The article correctly argues that staffing counts alone do not explain SOC underperformance. When skilled analysts are consumed by repetitive work, the real loss is not labour, but judgment, context, and process quality. That is a governance problem because leadership has allowed human expertise to become a disposable control surface. Practitioners should measure whether analyst time is being used for judgment or clerical repetition.

Workflow automation debt: many SOCs have accumulated manual process debt in the same way other security programmes accumulate identity debt. Repetition is not inherently bad, but repetition without reuse forces every analyst to reinvent the same steps. Over time that creates inconsistent outcomes and makes scale depend on headcount rather than control design. Teams should treat workflow standardisation as an operational resilience issue, not just a productivity improvement.

Analyst-led automation is the right operating principle for repeatable SOC work. Central automation projects often fail because they separate process knowledge from process building. The article's strongest point is that the people doing the work should be able to encode it themselves. That model is more likely to preserve nuance, improve adoption, and reduce bottlenecks. Practitioners should prioritise control ownership at the point of execution.

The same misallocation problem appears across identity and NHI programmes. Identity teams often bury their best people in manual access review, credential handling, and exception processing. In NHI governance, that means analysts spend time chasing inventory rather than reducing risk. The shared lesson is that control design must reduce toil or it will eventually degrade both security and retention. Practitioners should ask whether their identity programme is protecting expertise or burning it.

Named concept: human signal depletion. The article describes a condition where talented analysts lose effectiveness because the organisation keeps them in repetitive, low-value loops. That weakens SOC performance in the same way unmanaged identity sprawl weakens access governance. Practitioners should look for any control that consumes human judgment without increasing security value, then redesign it so expertise is preserved for decisions that actually require it.

What this signals

The broader signal for security leaders is that capacity problems are increasingly control-design problems. If a programme still depends on expert humans to perform the same routine steps over and over, it will eventually trade resilience for familiarity. That is true in SOC operations and just as true in identity governance, where manual processes quietly absorb the time that should be spent on risk reduction.

Human signal depletion: when organisations keep skilled staff inside repetitive loops, they consume the very judgment they need for escalation decisions. The answer is not simply to automate more, but to design workflows so analysts can spend time on exceptions, not repetition. For teams that also manage NHIs, that same logic applies to lifecycle cleanup and access review, where the operating model must preserve expert review for actual risk.

If the programme already uses identity and NHI controls, the next question is whether those controls are measured by output or by toil. Security leaders should expect a future in which automation is judged less by volume and more by how much human expertise it frees for higher-value decisions.


For practitioners

  • Identify high-frequency analyst workflows Inventory repetitive triage, enrichment, and onboarding steps that occur dozens of times per day, then rank them by time consumed and inconsistency.
  • Turn analyst steps into reusable workflows Have senior analysts document their real investigation paths so those steps can be reused, standardised, and shared across the team.
  • Push automation ownership to the SOC floor Let frontline analysts build or adjust automations without waiting on developers, so fixes happen when inefficiencies are discovered.
  • Track operational value, not just staffing Measure MTTA, MTTI, MTTR, onboarding time, and workflow usage together so leadership can see whether automation is actually improving capacity.
  • Protect senior time for judgment work Reserve senior analysts for threat hunting, detection tuning, and case review so institutional knowledge is spent on high-value decisions rather than repeated instruction.

Key takeaways

  • The article's core claim is that SOC performance failures often come from wasted analyst time rather than a lack of available people.
  • Repetitive work, weak onboarding design, and manual workflow ownership reduce both morale and defensive effectiveness.
  • The practical answer is to move routine automation closer to analysts while preserving human judgment for investigations that actually need it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Workflow standardisation supports controlled access to repeated SOC actions.
NIST SP 800-53 Rev 5AU-6SOC workflow quality depends on reviewable, consistent investigative actions.
CIS Controls v8CIS-8 , Audit Log ManagementLogging and repeatable investigation steps support measurable SOC operations.
ISO/IEC 27001:2022A.8.12Operational procedures need controlled, documented execution to reduce SOC variance.

Use PR.AC-4 to ensure analyst workflows are repeatable and approval-gated where needed.


Key terms

  • SOC Talent Waste: The loss of security value that occurs when skilled analysts spend most of their time on repetitive, low-judgment work instead of investigations, tuning, or hunting. It is a design problem in how work is assigned and automated, not just a staffing or morale issue.
  • Lifecycle automation debt: The risk that automation speeds up access creation while leaving revocation, review, and exception handling incomplete. It is a governance problem, not a tooling problem, because the organisation inherits the operational burden later in the identity lifecycle.
  • Analyst-led Automation: An operating model where the people performing security work can capture, modify, and reuse their own workflows without waiting on engineering teams. It improves adoption because automation reflects the real investigative process rather than an abstract design.
  • Human Signal Depletion: A condition where organisations drain the judgment and intuition of experts by keeping them in repetitive tasks for too long. In security operations, it weakens retention and reduces the quality of decisions available when high-value threats require attention.

What's in the full article

Legion AI's full post covers the operational detail this post intentionally leaves for the source:

  • Customer examples showing how analysts translated repeat investigations into reusable workflows
  • The workflow recording approach used to reduce onboarding drag and standardise common SOC steps
  • Metric examples for MTTA, MTTI, MTTR, onboarding time, and workflow usage that teams can adapt
  • The operating model detail behind letting analysts automate without waiting on developers

👉 Legion AI's full post covers analyst onboarding, workflow reuse, and the metrics used to prove capacity gains.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security practitioners connect identity controls to the operational realities their programmes depend on.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org