TL;DR: Customer environments processed 79 billion events and 1.29 million alerts in 2025, with 97% of alerts requiring no analyst investigation and 98% later judged benign or false positives, while NHI density reached 14.5:1 and AWS made up 67% of telemetry on average, according to Exaforce. The operating lesson is that cloud-scale SOCs now depend on identity context, not just more log volume.
NHIMG editorial — based on content published by Exaforce: Exaforce Agentic SOC 2025 year in review
By the numbers:
- Exaforce processed 79 billion events and over 1.29M alerts across customer environments in 2025.
- AWS dominated telemetry in tenants with AWS, accounting for 67% of events on average.
- Verizon's 2025 DBIR noted that ransomware was present in 44% of breaches and third-party involvement doubled from 15% to 30%.
Questions worth separating out
Q: What breaks in SOC triage when non-human identities are not modelled separately?
A: Alert context becomes too shallow to distinguish a person, a service account, or a delegated workflow, so analysts investigate the wrong actor or miss the real access path.
Q: Why do non-human identities complicate incident response more than user accounts?
A: Non-human identities are often embedded in tools, collectors, pipelines, and third-party services, so the affected access path is distributed rather than centralized.
Q: How do SOC teams know whether automation is reducing risk or just hiding work?
A: They should measure whether investigation time, case quality, and containment accuracy improve together.
Practitioner guidance
- Map alerts to non-human identity ownership Require every cloud alert to resolve to a workload, service account, token, or integration owner before it is triaged or dismissed.
- Separate benign automation from risky delegated access Classify routine service activity, third-party integrations, and privileged automation into distinct detection buckets so SOC analysts can see when normal-looking behaviour crosses an access boundary.
- Require explanation before auto-disposition If an agentic SOC workflow closes or suppresses an alert, retain the model reason, identity context, and contributing events for later review.
What's in the full article
Exaforce's full review covers the operational detail this post intentionally leaves for the source:
- Customer-by-customer outcome data showing how many alerts were auto-disposed versus escalated for human review
- The specific false-positive patterns by source, including CWPPs, SIEMs, native cloud tools, email security, and EDR
- Examples of the extended research areas, including supply chain and cloud identity attack paths
- The company milestones, funding context, and product packaging details behind the year-in-review narrative
👉 Read Exaforce's year-in-review analysis of agentic SOC operations and NHI pressure →
Agentic SOCs and NHI sprawl: what changes for security teams?
Explore further
Cloud telemetry has outgrown legacy SOC assumptions. Security teams still behave as if most useful evidence can be centrally ingested, correlated, and reviewed at human speed. In cloud-heavy estates, that assumption fails because the data is too voluminous and the resources are too ephemeral. Practitioners need operating models that treat telemetry reduction and context preservation as core control objectives, not reporting conveniences.
A question worth separating out:
Q: What should organisations do when third-party access is part of routine operations?
A: Treat supplier credentials, integrations, and delegated access as in-scope security objects with ownership, review, and revocation rules. The practical test is whether you can identify who granted the access, what it is for, and how quickly it can be removed when the relationship changes.
👉 Read our full editorial: Agentic SOCs are redefining triage as identity and cloud noise grows