TL;DR: A survey of nearly 300 CISOs, SOC leaders, and SecOps practitioners found large enterprises generate 3,181 alerts a day, 40% of alerts go uninvestigated, and average alert dwell time is 56 minutes, according to Prophet Security. The operational problem is not just volume, but whether SOC workflows can preserve triage quality as AI absorbs more of the workload.
NHIMG editorial — based on content published by Prophet: 6 Key Takeaways from the AI in SOC Survey Report
By the numbers:
- Alert dwell time, the interval between an alert firing and initial triage, averages about 56 minutes.
- Within three years, respondents anticipate AI will manage approximately 60% of SOC workloads.
Questions worth separating out
Q: How should financial institutions use AI SOC agents without losing investigation quality?
A: Use AI SOC agents to gather evidence, correlate telemetry, and draft case narratives, but keep human review on the final decision path.
Q: Why do large alert volumes create security risk even when tools are working?
A: High alert volume creates risk because analysts cannot investigate everything at the same speed, so important signals wait in queue or get ignored.
Q: What do security teams get wrong about GenAI in the SOC?
A: They often assume the model reduces the need for analyst judgment.
Practitioner guidance
- Rationalise alert sources and deduplicate detections Inventory the 28 or more alert-producing tools that typically feed large SOCs, then remove overlapping detections, redundant enrichments, and low-value noise before adding more automation.
- Build AI triage into the case-management path Use AI to summarize, cluster, and enrich alerts inside existing SOC workflows so analysts can validate evidence without switching tools or losing context.
- Prioritise identity and privilege signals for fast triage Route authentication anomalies, service account misuse, and unusual privileged activity above generic noise so identity-related incidents do not sit behind lower-value alerts.
What's in the full report
Prophet's full report covers the operational detail this post intentionally leaves for the source:
- Survey breakdowns by practitioner role, including CISOs, SOC leaders, and SecOps respondents
- Reported AI use cases for alert triage, investigation, and workload reduction
- ROI measurement approaches for AI in the SOC
- The full distribution of investigation times and tool counts behind the headline findings
👉 Read Prophet's full report on AI in the SOC survey findings →
AI in the SOC survey: what it means for SOC teams now?
Explore further
Alert fatigue has become a governance failure, not just an operations inconvenience. When 40% of alerts are left uninvestigated, the problem is no longer whether a team is busy. It is whether the SOC can still claim effective control over its detection pipeline. In mature programmes, triage capacity is part of security governance, not an afterthought. The practitioner takeaway is that alert quality, routing, and ownership must be managed as core control design.
A question worth separating out:
Q: How should organisations govern access to data used by AI systems?
A: Treat AI data access as an identity governance problem, not just a data storage problem. Define who or what can use each dataset, what purpose is allowed, and what runtime restrictions apply. Then review humans, service accounts, and AI agents separately so entitlement scope matches actual behaviour rather than a generic AI policy.
👉 Read our full editorial: AI in the SOC survey shows alert overload is driving AI adoption