TL;DR: More than 25 million security alerts were processed across live enterprise SOC environments in 2025, with 126% net revenue retention and adoption across Fortune 500 organisations pointing to a wider shift toward AI SOC models that investigate every alert at machine scale, according to Intezer. The operational question is no longer whether automation helps, but how teams govern machine-led triage without losing decision quality, auditability, or internal control.
NHIMG editorial — based on content published by Intezer: Intezer’s 2025 momentum reflects rapid adoption of AI SOC in global enterprise
By the numbers:
- In 2025, Intezer processed more than 25 million security alerts across live enterprise SOC environments.
- Intezer says adoption expanded across Fortune 500 organisations as enterprises looked for a more scalable way to run security operations.
Questions worth separating out
Q: How should security teams govern AI SOC triage without losing accountability?
A: Security teams should require clear escalation thresholds, logged decision paths, and retained evidence for every automated outcome.
Q: Why do identity events matter in AI SOC workflows?
A: Identity events often provide the earliest signal of compromise, especially when attackers use valid accounts, tokens, or privilege changes instead of noisy malware.
Q: What breaks when alert volume is handled only by manual triage?
A: Manual triage forces teams to prioritise before they have full context, which means lower-severity or less obvious alerts can hide genuine incidents.
Practitioner guidance
- Define human-review thresholds for machine-led triage Set explicit escalation thresholds for alerts that require analyst judgment, and document which identity, cloud, and endpoint signals must be present before a case is auto-escalated.
- Integrate identity telemetry into SOC workflows Route authentication anomalies, privilege changes, token misuse, and NHI activity into the same investigation queues as endpoint and cloud signals.
- Require evidence retention for every automated decision Keep the artefacts, scoring rationale, and correlation context that led to suppression, escalation, or closure.
What's in the full article
Intezer's full post covers the operational detail this analysis intentionally leaves for the source:
- Revenue and retention context behind the company's year-over-year growth
- Coverage examples and analyst recognition cited in the article
- The full description of how Intezer frames 100% alert investigation at forensic depth
- The market positioning detail behind its AI SOC operating model
👉 Read Intezer's analysis of AI SOC momentum and enterprise adoption →
AI SOC in the enterprise: what changes for security operations teams?
Explore further
AI SOC is becoming an operating model, not a point product category. The article’s core signal is that enterprises are buying relief from investigation overload, not just another detection layer. That matters because security operations now has to govern how machine-led triage changes the relationship between alerts, evidence, and analyst decision-making. For practitioners, the relevant question is whether the SOC can still explain why an alert was escalated or suppressed, not whether it was automatically processed.
A question worth separating out:
Q: Who is accountable when automated investigation suppresses a real incident?
A: Accountability stays with the organisation, not the automation. Security leaders need ownership for tuning, oversight, and review of automated triage decisions, plus governance that shows how the SOC will detect suppression errors, reconstruct cases, and escalate exceptions quickly.
👉 Read our full editorial: AI SOC adoption is reshaping enterprise security operations at scale