TL;DR: SOCs built around Tier 1 and Tier 2 alert handling struggle when 40% of alerts are never investigated, phishing-led breaches can succeed in under an hour, and burnout remains widespread, according to D3. Tiered operations are no longer enough when automation can investigate, enrich, and contextualise every alert before a human ever sees it.
NHIMG editorial — based on content published by D3: Morpheus automates L1 and L2 SOC operations
By the numbers:
Questions worth separating out
Q: How should security teams govern AI SOC triage without losing accountability?
A: Security teams should require clear escalation thresholds, logged decision paths, and retained evidence for every automated outcome.
Q: Why do tiered SOC models break down under modern alert volumes?
A: They assume humans can manually separate signal from noise before time-sensitive threats advance.
Q: What do security teams get wrong about alert suppression?
A: They often treat suppression as a noise-reduction exercise rather than a risk decision.
Practitioner guidance
- Define automation boundaries for SOC triage Separate alerts that can be enriched automatically from those that must go directly to a human analyst, especially cases involving privileged accounts, identity anomalies, or confirmed data exfiltration paths.
- Track evidence loss across the triage workflow Measure how often cases arrive at L2 or L3 with missing context, incomplete timelines, or disconnected identity data.
- Review suppression logic as a governed control Audit the rules that drop, merge, or deprioritise alerts and require change control for any suppression tied to identity activity, endpoint telemetry, or network indicators.
What's in the full article
D3's full analysis covers the operational detail this post intentionally leaves for the source:
- The analyst workspace workflow for assembling and reviewing full case files before escalation.
- The Deep Research investigation sequence across north-south telemetry, east-west correlation, and temporal enrichment.
- The vendor's explanation of how deterministic guidance keeps automated investigations auditable and modifiable.
- The role-shift narrative for junior and senior analysts after L1 and L2 automation.
👉 Read D3's analysis of how Morpheus changes SOC tiering and analyst work →
AI-driven SOC automation: what it means for tiered analyst teams?
Explore further
Automated SOC triage is becoming a governance problem, not just an efficiency problem. Once first-pass investigation is machine-led, the key question is no longer how quickly alerts are closed but how reliably evidence is assembled, preserved, and escalated. That changes the control conversation from staffing ratios to decision traceability. Practitioners should treat automated triage as part of the control plane, not a convenience layer.
A question worth separating out:
Q: How do organisations know if SOC automation is actually improving security?
A: Measure the time from alert creation to validated conclusion, the percentage of investigations that remain auditable, and how often findings produce durable detections or hunting hypotheses. If automation only lowers queue volume without improving evidence quality or detection coverage, it is reducing visibility rather than risk.
👉 Read our full editorial: AI-driven SOC automation exposes the limits of tiered analyst models