Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI autonomous SOCs: what they change for security teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Attackers now reach lateral movement in under 48 minutes while average alert investigation takes 70 minutes, and 40% of security alerts are never investigated, according to Torq and the SACR AI SOC Market Landscape 2025 and SANS 2025 SOC Survey. The real shift is from AI-assisted triage to AI-autonomous response, where agentic systems act end-to-end instead of leaving remediation to humans.

NHIMG editorial — based on content published by Torq: AI-powered SOC operations and the case for agentic automation

By the numbers:

Questions worth separating out

Q: How should organisations decide when AI can act on its own in the SOC?

A: Use autonomy only where the action is low-risk, reversible, and already approved in policy.

Q: Why do identity signals matter in AI-driven SOC investigations?

A: Identity signals matter because many security decisions depend on who acted, from where, with what access, and whether the behaviour fits the user's normal pattern.

Q: What breaks when SOC automation and orchestration are split across tools?

A: The seams become a manual governance problem.

Practitioner guidance

  • Define autonomy boundaries for routine response Map which cases AI can close on its own, which actions require approval, and which systems are always human-reviewed.
  • Instrument identity telemetry in SOC workflows Ensure alerts can be enriched with IAM, PAM, and session data before a case is assigned.
  • Measure response against containment outcomes Track not only MTTD and MTTR, but also alert clearance rate, percentage of cases fully closed by automation, and the time from first alert to session termination.

What's in the full article

Torq's full article covers the operational detail this post intentionally leaves for the source:

  • Production examples of AI-autonomous triage, investigation, and response across SOC workflows
  • Vendor evaluation questions about explainability, human-on-the-loop design, and measurable outcomes
  • Named customer scenarios showing how autonomous response reduced analyst workload and sped up handling
  • Examples of how AI agents coordinate across SIEM, EDR, IAM, cloud, and ticketing systems

👉 Read Torq's analysis of AI-autonomous security operations in the SOC →

AI autonomous SOCs: what they change for security teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI-autonomous SOCs are becoming a control-plane issue, not just a staffing issue. The article is right to frame the problem as a speed mismatch, but the deeper point is that security operations now depend on whether machines can make bounded response decisions across control planes. That shifts the conversation from analyst efficiency to governance of machine action. Teams should treat autonomous response as an access-control problem for the SOC itself.

A question worth separating out:

Q: How do organisations know if AI is actually helping the SOC?

A: Look for lower alert backlog, faster triage, fewer false positives, and better investigator confidence in the outputs. If AI only speeds up noise, or if analysts still need to rework most findings, the system is not adding reliable operational value and probably needs data or rule tuning.

👉 Read our full editorial: AI autonomous SOCs are reshaping the response gap in 2026



   
ReplyQuote
Share: