TL;DR: Traditional SIEM workflows still force analysts to reconstruct what happened across identity, cloud, SaaS, endpoint, and collaboration tools, which slows containment and increases the chance of over- or under-scoping, according to Exaforce. The practical shift is from event collection to evidence-backed answers that expose blast radius, ownership, and enabling change.
NHIMG editorial — based on content published by Exaforce: The SIEM Possible Challenge, Moving From Events to Answers in a Modern SOC
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: What breaks when a SIEM can only show events and not current exposure state?
A: The team loses the ability to make narrow, evidence-backed containment decisions.
Q: Why do identities and permissions matter so much in SOC investigations?
A: Because blast radius is determined by effective access, not by the alert alone.
Q: How do security teams know whether their SOC is answering the right questions?
A: They should test whether the platform can answer who has access, what changed, what is shared, and what is reachable without forcing manual pivots across multiple tools.
Practitioner guidance
- Map effective access paths, not just assigned roles Build investigation views that show direct permissions, inherited group access, delegated access, and linked identities for every high-value account so responders can see real blast radius quickly.
- Correlate configuration changes with security alerts Connect sharing changes, token creation, role assumption, integration approvals, and policy edits to runtime detections so analysts can identify the enabling change behind an alert.
- Add identity and NHI evidence to every major SOC workflow Ensure the platform can show who acted, on whose behalf, and with what privilege when an incident spans users, service accounts, OAuth apps, or AI-assisted actions.
What's in the full article
Exaforce's full post covers the operational detail this post intentionally leaves for the source:
- Step-by-step examples of the question patterns the vendor uses to benchmark SOC answer quality across identity, cloud, SaaS, and collaboration data.
- Customer examples showing how evidence-backed triage reduced investigation time and improved response for critical incidents.
- The specific workflow the vendor uses to connect alerts, configuration changes, and identity context into one investigation path.
- Demonstration detail on how AI-assisted SOC analysis is structured when the platform is asked to answer blast-radius questions.
👉 Read Exaforce's analysis of the SIEM possible challenge in modern SOC operations →
SIEM and SOC context gaps: can your team answer questions fast?
Explore further
Event visibility without state visibility is not enough for a modern SOC. SIEM-centric operations still assume analysts can stitch together truth from events, but containment decisions depend on current access state, not only historical activity. That gap becomes visible when the environment spans identity, cloud, SaaS, and collaboration platforms. The field needs answers-first investigation models, because correlation alone does not deliver defensible decisions.
A question worth separating out:
Q: What is the difference between alert triage and evidence-backed investigation?
A: Alert triage decides whether something deserves attention. Evidence-backed investigation explains current state, enabling change, and likely blast radius well enough to support a containment choice. The first is about prioritisation, while the second is about proving scope and cause before the incident expands.
👉 Read our full editorial: SIEM cannot answer modern SOC questions without identity and context