TL;DR: Fragmented tooling, manual triage and inconsistent case handling leave SOC teams unable to prove impact or keep pace with machine-speed attacks, according to Torq’s case study with Kenvue. The governance shift is from alert handling to measurable, standardised response, where operational consistency becomes a resilience control rather than a workflow preference.
NHIMG editorial — based on content published by torq: Automated security workflows and SOC transformation at Kenvue
By the numbers:
- 89% of cases in Kenvue’s SOC were automated after six months.
- Torq says Kenvue reduced mean time to respond by 60%.
Questions worth separating out
Q: How should security teams use automation in SOC workflows without creating new access risk?
A: Start by limiting each workflow to the minimum authority it needs, then separate enrichment, containment, and approval steps.
Q: Why do fragmented SOC workflows slow threat response?
A: Fragmented workflows force analysts to move across too many tools and reconstruct context manually before they can act.
Q: What do security teams get wrong about automated SOC reporting?
A: They often treat report generation as a formatting task instead of a control point.
Practitioner guidance
- Standardise incident case structures Define a single case schema for observables, notes, evidence, ownership, and escalation so analysts stop rebuilding context in every tool.
- Unify IAM, SIEM, EDR, and cloud context Build workflows that pull identity, endpoint, and cloud signals into the same decision path before closure or escalation.
- Automate repeatable response steps first Target enrichment, routing, and routine validation before automating containment decisions.
What's in the full article
Torq's full case study covers the operational detail this post intentionally leaves for the source:
- Step-by-step examples of the case management structure used to standardise incident handling across teams
- How the automated workflow design supported Kenvue's internal transition from outsourced to in-house SOC operations
- The specific reporting and tagging model that enabled measurable performance tracking over time
- Examples of how interactive forms were used for compliance and third-party incident intake
👉 Read Torq's case study on automated security workflows in the SOC →
Automated security workflows: what they mean for SOC teams?
Explore further
Automated SOC workflows are becoming a governance control, not just an efficiency play. Once incident handling is standardised, the SOC stops being a collection of ad hoc analyst decisions and starts becoming a measurable control environment. That shift matters because business stakeholders care about repeatability, evidence, and risk reduction as much as speed. The practical conclusion is that SOC automation should be evaluated as operational governance, not simply tooling convenience.
A question worth separating out:
Q: How do organisations know if SOC automation is actually improving security?
A: Measure the time from alert creation to validated conclusion, the percentage of investigations that remain auditable, and how often findings produce durable detections or hunting hypotheses. If automation only lowers queue volume without improving evidence quality or detection coverage, it is reducing visibility rather than risk.
👉 Read our full editorial: Automated security workflows are reshaping modern SOC operations