Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

XDR is doing more work, so why are analysts still overloaded?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: XDR has improved detection and correlation, but SOC teams still spend about 70 minutes investigating each alert while enterprise volumes remain far above human capacity, according to D3 and industry research cited in the article. The structural gap is investigation and response, not visibility, so automation must extend beyond alert reduction.

NHIMG editorial — based on content published by D3: XDR solved visibility. It didn’t solve investigation. Here’s why the gap is structural

By the numbers:

  • Leading XDR platforms scored 100% technique-level detection in the 2025 MITRE ATT&CK Evaluations, which expanded to include cloud attack scenarios and reconnaissance for the first time.
  • Enterprise SOCs receive an average of 960 alerts per day, and large enterprises see over 3,000, generated by 30 or more security tools, according to SACR 2025.

Questions worth separating out

Q: What breaks when XDR is used as a complete SOC strategy?

A: XDR breaks down when organisations assume correlation equals investigation.

Q: Why do correlated incidents still overwhelm SOC teams?

A: Correlated incidents still overwhelm SOC teams because each one requires human judgment, not just alert reading.

Q: How do security teams know if automation is actually helping investigation?

A: They know automation is helping when time to verdict, not just alert volume, falls across the highest-risk incident classes.

Practitioner guidance

  • Measure investigation debt by incident class Track how many correlated incidents still require manual scope analysis, how long each class takes, and how often alerts age out before closure.
  • Separate containment from diagnosis in playbooks Write response workflows so isolation, blocking, or account disablement only occur after defined investigative conditions are met.
  • Prioritise identity-rich incidents for deeper automation Focus the first automation work on incidents involving user accounts, tokens, service identities, and delegated access paths, because those cases often require the most context to resolve and the fastest containment.

What's in the full article

D3's full analysis covers the operational detail this post intentionally leaves for the source:

  • A deeper breakdown of the autonomous investigation model and how it differs from alert summarisation.
  • Practical examples of response workflows generated at runtime across multiple tool categories.
  • Details on 800+ tool integration repair and how self-healing integrations change SOC operations.
  • The side-by-side workflow comparison between conventional XDR handling and autonomous investigation.

👉 Read D3's analysis of why XDR stops short of the autonomous SOC →

XDR is doing more work, so why are analysts still overloaded?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

The SOC bottleneck has shifted from alert volume to investigation depth. XDR reduced the first generation of SOC pain, which was disconnected alerts across many tools. The remaining problem is more structural: correlated incidents still need human interpretation, and that interpretation is what consumes time. For identity security teams, this matters because access abuse is often visible only after correlation, not after the fact. Practitioners should evaluate whether their SOC is solving noise, or merely repackaging it.

A question worth separating out:

Q: Who owns the gap between detection and response in a modern SOC?

A: The SOC owner owns it, but the gap usually spans several functions: security engineering, detection operations, incident response, and identity teams. In practice, the organisation needs one accountable process for investigation and response orchestration, not separate teams each assuming the next layer will close the loop.

👉 Read our full editorial: XDR visibility is improving, but investigation remains the SOC bottleneck



   
ReplyQuote
Share: