By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: D3Published April 10, 2026

TL;DR: XDR has improved detection and correlation, but SOC teams still spend about 70 minutes investigating each alert while enterprise volumes remain far above human capacity, according to D3 and industry research cited in the article. The structural gap is investigation and response, not visibility, so automation must extend beyond alert reduction.


At a glance

What this is: This is an analysis of why XDR improves detection but does not resolve the manual investigation workload that still dominates SOC operations.

Why it matters: It matters because identity, endpoint, cloud, and network telemetry only reduces risk if analysts can investigate and respond at the pace of the threat, especially when identity activity is part of the incident chain.

By the numbers:

  • Leading XDR platforms scored 100% technique-level detection in the 2025 MITRE ATT&CK Evaluations, which expanded to include cloud attack scenarios and reconnaissance for the first time.
  • The average investigation takes 70 minutes per alert, according to industry research compiled in the AI SOC Market Landscape for 2025 report.
  • Enterprise SOCs receive an average of 960 alerts per day, and large enterprises see over 3,000, generated by 30 or more security tools, according to SACR 2025.
  • A 2025 Omdia study commissioned by Microsoft found that 42 percent of all alerts are never investigated at all.

👉 Read D3's analysis of why XDR stops short of the autonomous SOC


Context

XDR solves a visibility problem, but it does not solve the operational problem of deciding what an alert means, how far it spread, and what to do next. In practice, that leaves SOC teams with correlated incidents that still require manual triage, timeline reconstruction, scope analysis, and containment decisions. For identity-rich incidents, the same pattern appears in NHI and human identity telemetry: the signal exists, but the investigative work still lands on analysts.

The article argues that the bottleneck has shifted from alert noise to investigation capacity. That is a governance issue as much as a tooling issue, because security outcome depends on whether the SOC can convert detection into timely, coordinated action. Where XDR platforms see identity events alongside endpoint and cloud activity, practitioners still need policy, process, and response automation that can keep pace with the incident.


Key questions

Q: What breaks when XDR is used as a complete SOC strategy?

A: XDR breaks down when organisations assume correlation equals investigation. It can reduce noise and improve visibility, but it still leaves analysts to determine scope, root cause, containment, and coordinated response. If those steps remain manual, the SOC can still be slower than the attacker, especially in identity-rich incidents where access abuse unfolds quickly.

Q: Why do correlated incidents still overwhelm SOC teams?

A: Correlated incidents still overwhelm SOC teams because each one requires human judgment, not just alert reading. Analysts must validate maliciousness, reconstruct timelines, and decide on response actions across multiple tools. If the organisation receives hundreds or thousands of alerts daily, investigation capacity becomes the true constraint, even when the signal quality improves.

Q: How do security teams know if automation is actually helping investigation?

A: They know automation is helping when time to verdict, not just alert volume, falls across the highest-risk incident classes. Useful automation shortens scope analysis, reduces handoffs, and speeds containment decisions. If analysts still queue incidents for most of a shift, the platform is improving visibility but not investigative throughput.

Q: Who owns the gap between detection and response in a modern SOC?

A: The SOC owner owns it, but the gap usually spans several functions: security engineering, detection operations, incident response, and identity teams. In practice, the organisation needs one accountable process for investigation and response orchestration, not separate teams each assuming the next layer will close the loop.


Technical breakdown

Why XDR correlation still leaves an investigation gap

XDR correlates telemetry across endpoints, networks, email, cloud, and identity so that multiple alerts become a single incident. That reduces noise, but correlation is not the same as analysis. Investigation still requires deciding whether the activity is malicious, reconstructing the attack path, identifying blast radius, and selecting the right response. The result is a structural handoff from machine detection to human judgment, which is where queue backlogs form. Practical implication: treat XDR as a signal consolidation layer, not a complete investigation capability.

Practical implication: measure how many incidents still require manual scope analysis after correlation.

Why response automation is not the same as SOC investigation

XDR can isolate hosts, block IPs, or disable accounts, but those are tactical actions that depend on prior investigation. A platform can trigger response steps, yet still leave the analyst to decide whether the action is justified and what broader workflow should follow. That distinction matters in identity-heavy incidents because a disabled account may be a symptom, while the real issue is token theft, standing privilege, or delegated access abuse. Practical implication: separate containment automation from investigative reasoning in your operating model.

Practical implication: map which response actions can be automated only after a confirmed investigative verdict.

Where AI copilots help and where they stop short

AI copilots can summarise alerts, suggest next steps, and speed up manual analysis, but they do not remove the need for investigation across the whole stack. They are strongest when the problem is search and summarisation, weaker when the problem is cross-tool correlation, runtime workflow generation, or repair of broken integrations. In mature SOCs, that means copilots reduce friction but do not erase workload. Practical implication: use copilots to compress analyst effort, not as evidence that the investigation function is solved.

Practical implication: benchmark whether copilots reduce investigation time or only improve alert reading speed.


NHI Mgmt Group analysis

The SOC bottleneck has shifted from alert volume to investigation depth. XDR reduced the first generation of SOC pain, which was disconnected alerts across many tools. The remaining problem is more structural: correlated incidents still need human interpretation, and that interpretation is what consumes time. For identity security teams, this matters because access abuse is often visible only after correlation, not after the fact. Practitioners should evaluate whether their SOC is solving noise, or merely repackaging it.

Identity data makes the investigation problem more urgent, not less. When endpoints, cloud, email, and identity are correlated in one incident, the analyst still has to determine whether a user account, token, or service identity has been abused. That is a governance and evidence problem, not a visibility problem. NIST-CSF and MITRE ATT&CK both map cleanly to this challenge because they emphasise detection, analysis, and response as distinct functions. Practitioners should not confuse visibility with decision readiness.

Detection-first architectures create investigation debt. Investigation debt: the backlog created when detection capacity outpaces the organisation’s ability to interpret and respond to alerts. This debt accumulates even in mature SOCs because every new sensor or correlation rule expands the queue of incidents that still require triage. In identity-heavy environments, the debt is compounded by privilege context, token lifetimes, and delegated access paths that are hard to reason about quickly. Practitioners should measure investigation debt as a core SOC risk.

AI copilots improve analyst throughput, but they do not replace the investigative control plane. Summaries and recommendations are useful, but they leave the core control question unchanged: who determines scope, containment, and coordinated response. That gap is why AI assistance and autonomous investigation are not the same thing. NHI and agentic AI programmes should watch this closely, because tool-assisted triage still depends on human decision latency. Practitioners should align automation ambition with the actual control they are trying to remove from the queue.

What this signals

Investigation debt is becoming a board-level SOC issue because visibility improvements do not automatically translate into containment speed. The practical signal for programmes is simple: if correlated incidents still sit in a queue while attackers move through identity, cloud, and endpoint layers, the architecture is incomplete. Teams should anchor their operating model to detection, analysis, and response as separate controls, using MITRE ATT&CK Enterprise Matrix to map where the handoff fails.

For identity-heavy environments, the next wave of SOC improvement will be judged less by how many alerts are suppressed and more by how quickly an incident can be explained. That shifts priority toward evidence quality, identity context, and workflow orchestration. The organisation that can turn identity signals into verdicts faster will have a materially better response posture than one that only improves alert hygiene.


For practitioners

  • Measure investigation debt by incident class Track how many correlated incidents still require manual scope analysis, how long each class takes, and how often alerts age out before closure. Use that data to distinguish false positive reduction from real investigation compression.
  • Separate containment from diagnosis in playbooks Write response workflows so isolation, blocking, or account disablement only occur after defined investigative conditions are met. That keeps tactical actions from substituting for evidence-based decisions.
  • Prioritise identity-rich incidents for deeper automation Focus the first automation work on incidents involving user accounts, tokens, service identities, and delegated access paths, because those cases often require the most context to resolve and the fastest containment.
  • Test whether copilots reduce time to verdict Benchmark whether summarisation and guided analysis actually shorten time to verdict, not just time to read an alert. If verdict time stays flat, the SOC still owns the same investigative load.

Key takeaways

  • XDR improves correlation, but investigation remains the control point that determines whether the SOC can keep pace with real attacks.
  • The scale problem is operational as much as technical, because alert volumes and 70-minute investigations create a queue that human teams cannot clear consistently.
  • Programmes should measure time to verdict and investigation debt, then automate the parts of response that currently depend on manual scope analysis.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral Movement; TA0040 , ImpactThe article centres on attack progression and response gaps across identity and endpoint telemetry.
NIST CSF 2.0DE.CM-1Continuous monitoring is the article's starting point, but analysis and response remain the gap.
NIST SP 800-53 Rev 5SI-4System monitoring and analysis are directly tied to the SOC investigation workload discussed here.
CIS Controls v8CIS-8 , Audit Log ManagementLog collection helps visibility, but the article shows why log volume alone does not solve investigation.
NIST AI RMFMANAGEAI copilots and autonomous investigation both require governance of how AI affects security operations.

Map investigation delays to ATT&CK tactics and prioritise controls where identity abuse can progress unnoticed.


Key terms

  • Investigation Debt: Investigation debt is the backlog of alerts that were closed, deferred, or partially reviewed without complete evidence. It behaves like technical debt in operations because it hides risk until a later incident or postmortem shows the missed context.
  • Mean Time to Verdict: Mean time to verdict is the time it takes to move from an alert to a defensible conclusion about whether it is benign or malicious. It is a better operational measure than alert counts alone because it captures enrichment, analysis, and decision latency.
  • Correlated Incident: A security event that combines multiple signals from different tools into one case for investigation. Correlation reduces noise, but it does not determine meaning, blast radius, or response priority, which is why human or automated investigation still has to follow.
  • Autonomous Investigation: A model in which a security system performs scope analysis, path reconstruction, and response recommendation without waiting for an analyst to manually assemble the case. It aims to reduce queue pressure, but it still requires governance over accuracy, accountability, and response authority.

What's in the full article

D3's full analysis covers the operational detail this post intentionally leaves for the source:

  • A deeper breakdown of the autonomous investigation model and how it differs from alert summarisation.
  • Practical examples of response workflows generated at runtime across multiple tool categories.
  • Details on 800+ tool integration repair and how self-healing integrations change SOC operations.
  • The side-by-side workflow comparison between conventional XDR handling and autonomous investigation.

👉 The full D3 analysis covers the investigation gap, the control handoff problem, and the autonomous SOC model.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle controls. It helps practitioners connect identity decisions to the wider security operating model they have to defend.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org