TL;DR: AI-assisted attackers can compress malware development from weeks to hours, while Torq cites 94% of organisations using AI in the SOC, 80% still running fragmented tools, and an average of seven AI tools per SOC. Human-speed triage is no longer a stable operating assumption for defensive operations.
NHIMG editorial — based on content published by torq: LLMjacking: How Attackers Hijack AI Using Compromised NHIs
By the numbers:
- 94% of organizations are using AI in the SOC in some capacity
- 80% are still running fragmented tools
- 85% of security leaders say they want consolidation over fragmented point solutions
Questions worth separating out
Q: What breaks when a SOC relies too heavily on human triage queues?
A: The system becomes sensitive to utilisation spikes, so wait time grows faster than the team can compensate.
Q: Why do AI-driven attacks change SOC operating assumptions?
A: They compress attacker cycles from days or weeks into hours or minutes, which breaks the assumption that defenders have time to investigate before acting.
Q: How do SOC teams know whether automation is reducing risk or just hiding work?
A: They should measure whether investigation time, case quality, and containment accuracy improve together.
Practitioner guidance
- Map every response workflow to a decision boundary Identify which SOC actions require human approval, which can be pre-authorised, and which can run automatically under policy.
- Assign privileged identities to automation paths Treat response bots, orchestration engines, and AI agents as non-human identities with named ownership, scoped permissions, and short-lived credentials.
- Reduce handoffs in high-volume triage flows Start with the incidents that generate the most repetitive analyst work and remove unnecessary approvals, duplicate enrichment, and manual ticket translation.
What's in the full article
Torq's full article covers the operational detail this post intentionally leaves for the source:
- How the Torq AI SOC Platform is positioned to support investigation, prioritisation, and response workflows
- The reported operating-model metrics behind faster detection-to-containment and lower manual workload
- John White's first-hand examples from SOC transformation work across enterprise environments
- The article's view on how AI should be embedded into the SOC execution layer rather than layered on top
👉 Read torq's analysis of how AI is reshaping SOC operating models →
AI SOC automation and the governance gap teams are missing?
Explore further
Machine-speed defence gap: The core issue is not that teams lack tools, but that they still govern response as a human-paced process. Once adversaries can adapt in hours, the defence model must assume that detection, triage, and containment can no longer depend on manual sequencing. The practical conclusion is that SOC design now sits inside the same governance conversation as identity and access control.
A question worth separating out:
Q: Who is accountable when an AI SOC platform takes the wrong action?
A: The organisation remains accountable, because delegation does not transfer responsibility. Security, risk, and control owners need clear approval rules, logging, and override authority so each action can be traced back to a human governance decision. Without that, the control environment is not defensible.
👉 Read our full editorial: AI SOC operating models are changing faster than human triage