TL;DR: SACR’s 2026 AI SOC Market Report says an AI SOC operating layer that classifies alerts, constructs cases, and routes remediation through deterministic or agentic workflows is how Torq is better understood, with customers citing a 1 minute mean time to triage and a 94% reduction in mean time to respond. Closed-loop automation, not copilot-style summarisation, is now the real evaluation test for SOC governance.
NHIMG editorial — based on content published by torq: LLMjacking: How Attackers Hijack AI Using Compromised NHIs
By the numbers:
- On average, large enterprises achieve a mean time to triage (MTTT) of 1 minute, a 60x improvement over manual triage.
- A global biotech titan cites a 97% reduction in noise entering the SOC.
- A well-known financial services enterprise achieved 99% faster threat triage after deploying Torq.
Questions worth separating out
Q: How should SOC teams decide which alert actions can be automated safely?
A: Start by separating response actions into tiers: low-risk tasks that can be automated, medium-risk tasks that require human approval, and high-risk tasks that should remain manual.
Q: Why do AI evaluations need identity and access context?
A: Because many AI failures happen through who can retrieve, prompt, or act on data, not just through model quality.
Q: What breaks when case management does not preserve investigation context?
A: Analysts have to reconstruct the same evidence after every handoff, which slows response and increases inconsistency.
Practitioner guidance
- Define autonomous response boundaries Classify response actions into approved autonomous, human-reviewed, and never-autonomous tiers before enabling agentic workflows in the SOC.
- Validate identity context feeding triage Audit whether access history, business role, and entity relationships are current enough to support triage decisions.
- Measure closed-loop performance Track mean time to triage, mean time to respond, and case closure quality as a single operating chain rather than separate metrics.
What's in the full article
Torq's full analysis covers the operational detail this post intentionally leaves for the source:
- How the Auto Triage context pipeline is assembled from identities, assets, policies, and analyst decisions
- How Socrates coordinates investigations and response actions across different workflow modes
- How Reflex and Recall feed continuous learning from confirmed verdicts and prior cases
- Customer-facing performance data that shows how the operating model behaves in real SOC environments
👉 Read Torq's analysis of the 2026 AI SOC Market Report and autonomous triage →
AI SOC autonomy and closed-loop response: what should teams expect?
Explore further
Closed-loop SOC automation is becoming the category standard. The market is moving beyond AI summarisation and toward systems that classify, construct cases, assign work, and close remediation without reassembling context at every step. That matters because summary-only tools still leave the bottleneck in place, while closed-loop systems change how decisions are made and retained. The practitioner conclusion is simple: evaluation should focus on closure quality, not just alert speed.
A question worth separating out:
Q: How can analysts tell whether AI-driven SOC automation is actually working?
A: Look beyond alert volume and measure whether the platform produces accurate incidents, preserves tenant context, and shortens time to closure without creating rework. If analysts still need to reconstruct the story manually, the automation is reducing noise but not truly improving operational control.
👉 Read our full editorial: AI SOC autonomy depends on closed-loop triage and response