Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic SOCs and NHI sprawl: what changes for security teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Customer environments processed 79 billion events and 1.29 million alerts in 2025, with 97% of alerts requiring no analyst investigation and 98% later judged benign or false positives, while NHI density reached 14.5:1 and AWS made up 67% of telemetry on average, according to Exaforce. The operating lesson is that cloud-scale SOCs now depend on identity context, not just more log volume.

NHIMG editorial — based on content published by Exaforce: Exaforce Agentic SOC 2025 year in review

By the numbers:

Questions worth separating out

Q: What breaks in SOC triage when non-human identities are not modelled separately?

A: Alert context becomes too shallow to distinguish a person, a service account, or a delegated workflow, so analysts investigate the wrong actor or miss the real access path.

Q: Why do non-human identities complicate incident response more than user accounts?

A: Non-human identities are often embedded in tools, collectors, pipelines, and third-party services, so the affected access path is distributed rather than centralized.

Q: How do SOC teams know whether automation is reducing risk or just hiding work?

A: They should measure whether investigation time, case quality, and containment accuracy improve together.

Practitioner guidance

  • Map alerts to non-human identity ownership Require every cloud alert to resolve to a workload, service account, token, or integration owner before it is triaged or dismissed.
  • Separate benign automation from risky delegated access Classify routine service activity, third-party integrations, and privileged automation into distinct detection buckets so SOC analysts can see when normal-looking behaviour crosses an access boundary.
  • Require explanation before auto-disposition If an agentic SOC workflow closes or suppresses an alert, retain the model reason, identity context, and contributing events for later review.

What's in the full article

Exaforce's full review covers the operational detail this post intentionally leaves for the source:

  • Customer-by-customer outcome data showing how many alerts were auto-disposed versus escalated for human review
  • The specific false-positive patterns by source, including CWPPs, SIEMs, native cloud tools, email security, and EDR
  • Examples of the extended research areas, including supply chain and cloud identity attack paths
  • The company milestones, funding context, and product packaging details behind the year-in-review narrative

👉 Read Exaforce's year-in-review analysis of agentic SOC operations and NHI pressure →

Agentic SOCs and NHI sprawl: what changes for security teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Cloud telemetry has outgrown legacy SOC assumptions. Security teams still behave as if most useful evidence can be centrally ingested, correlated, and reviewed at human speed. In cloud-heavy estates, that assumption fails because the data is too voluminous and the resources are too ephemeral. Practitioners need operating models that treat telemetry reduction and context preservation as core control objectives, not reporting conveniences.

A question worth separating out:

Q: What should organisations do when third-party access is part of routine operations?

A: Treat supplier credentials, integrations, and delegated access as in-scope security objects with ownership, review, and revocation rules. The practical test is whether you can identify who granted the access, what it is for, and how quickly it can be removed when the relationship changes.

👉 Read our full editorial: Agentic SOCs are redefining triage as identity and cloud noise grows



   
ReplyQuote
Share: