Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI SOC and MSSP repatriation: what should security teams change?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI-driven security operations are changing the economics of SOC repatriation, with some teams pulling SecOps back in-house while others keep an outsourced layer for coverage, according to Exaforce. The real question is no longer whether outsourcing is the default, but how much context, triage, and operational knowledge should stay inside the organisation.

NHIMG editorial — based on content published by Exaforce: Rethinking MSSP repatriation: AI SOCs, in-house builds, and the middle ground

By the numbers:

Questions worth separating out

Q: How should security teams decide which SOC functions to keep in-house?

A: Start by separating functions that need local business context from those that can be standardised.

Q: Why does analyst churn matter so much in outsourced SOC models?

A: Because SOC quality depends on context as much as on tooling.

Q: What breaks when an AI SOC platform stops at triage?

A: The workload shifts instead of shrinking.

Practitioner guidance

  • Define SOC decision ownership by control type Separate alert enrichment, tuning, escalation, and response authority into distinct ownership lines.
  • Audit the provider’s real triage contribution Measure whether the MSSP is resolving alerts, enriching them, or simply forwarding noise back to your team.
  • Preserve environment knowledge in reusable artifacts Capture business rhythms, identity exceptions, and known false-positive patterns in runbooks and decision rules that survive staffing turnover.

What's in the full article

Exaforce's full blog post covers the operational detail this post intentionally leaves for the source:

  • Specific examples of how AI SOC triage reduces analyst workload across alert types and shifts.
  • Customer operating-model comparisons showing when teams kept some coverage outsourced and what stayed internal.
  • Practical guidance on comparing MSSP output, alert quality, and investigation depth during a repatriation overlap.
  • Examples of how to decide which SecOps functions need 24/7 coverage versus business-hours ownership.

👉 Read Exaforce's analysis of AI SOC repatriation and MSSP trade-offs →

AI SOC and MSSP repatriation: what should security teams change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI SOC repatriation is really a governance reset, not just a staffing choice. The article is about operational efficiency, but the deeper issue is where security judgment lives when alerts are enriched by systems rather than people. For identity-heavy environments, that matters because access anomalies, service account behaviour, and privilege escalation signals require local context to interpret correctly. Teams that treat this as a pure labour decision risk outsourcing the very knowledge needed to govern identity-driven incidents.

A question worth separating out:

Q: Who should be accountable for identity-related detections in a hybrid SOC model?

A: The internal security organisation should retain accountability for the business meaning of identity events, even if a provider performs parts of the workflow. External teams can help with coverage and enrichment, but internal owners should define the thresholds for privileged access, anomalous authentication, and escalation. That keeps governance aligned with the environment being defended.

👉 Read our full editorial: AI SOC changes the in-house versus MSSP equation for SecOps



   
ReplyQuote
Share: