Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI in the SOC: what it automates, what it cannot replace


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19415
Topic starter  

TL;DR: AI can reduce breach lifecycle and costs while 42% of SOCs still deploy out-of-the-box AI and ML tools that score low on satisfaction, underscoring a gap between automation promise and operational reality, according to Panther. The real issue is not replacement but whether teams can supervise AI, tune detections, and preserve human judgment where context matters.

NHIMG editorial — based on content published by Panther: Will AI Replace SOC Analysts? The Honest Answer Is More Complicated

By the numbers:

Questions worth separating out

Q: How should security teams use AI in the SOC without losing human control?

A: Use AI to remove repetitive work, enrich alerts, and accelerate triage, but keep humans accountable for escalation, containment, and exception handling.

Q: Why do identity signals matter in AI-driven SOC investigations?

A: Identity signals matter because many security decisions depend on who acted, from where, with what access, and whether the behaviour fits the user's normal pattern.

Q: What do security teams get wrong about GenAI in the SOC?

A: They often assume the model reduces the need for analyst judgment.

Practitioner guidance

  • Separate repetitive triage from judgment calls Use AI for alert prioritisation, enrichment, and first-pass summarisation, but require human review for privileged access events, production-impacting actions, and ambiguous identity activity.
  • Adopt detection-as-code for AI-supervised workflows Version-control detection logic, test changes in staging, and peer-review rule updates so AI output can be validated against known cases.
  • Normalise identity telemetry before scaling AI Ensure login events, privilege changes, cloud actions, and endpoint logs share consistent timestamps and identifiers so correlation is reliable.

What's in the full article

Panther's full blog covers the operational detail this post intentionally leaves for the source:

  • Cresta-style workflow examples showing how Panther AI reduced triage time in a live SOC setting.
  • The specific detection engineering examples behind AI-assisted investigation summaries and alert tuning.
  • Data architecture guidance on normalising cloud, identity, and endpoint telemetry for better AI correlation.
  • The practical comparison between high-volume triage automation and human-led validation in ambiguous cases.

👉 Read Panther's analysis of how AI is changing SOC analyst roles →

AI in the SOC: what it automates, what it cannot replace?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 19006
 

AI in the SOC is an augmentation layer, not a replacement layer. The vendor's evidence points to a narrow but real gain in repetitive triage, while the hard work of interpretation still sits with analysts. That means the market is moving toward human validated automation rather than autonomous closure. For security leaders, the lesson is to redesign work allocation, not count on headcount elimination.

A question worth separating out:

Q: How do organisations know if AI is actually helping the SOC?

A: Look for lower alert backlog, faster triage, fewer false positives, and better investigator confidence in the outputs. If AI only speeds up noise, or if analysts still need to rework most findings, the system is not adding reliable operational value and probably needs data or rule tuning.

👉 Read our full editorial: AI will not replace SOC analysts: the real shift is role change



   
ReplyQuote
Share: