The accepted wisdom in cybersecurity is that the Security Operations Centre (SOC) has become overwhelmed. There’s some truth in this. Yes, the time taken to detect and remediate has grown, with IBM stating this now stands at 241 days. Yes, alert fatigue remains an issue, with SOC analysts snowed under 10,000 alerts per day leading to confirmation bias whereby positive alerts are discounted. And yes, alert volumes are rocketing due to a thriving black-market economy in attack kits and services, not to mention the emergence of AI-enabled attacks. Yet the SOC can adjust to these challenges and move with a rising tide if it adopts a paranoid posture.
One of the key attack trends over the past year is for threat actors to gain and maintain access legitimately. It’s for this reason we’ve seen a rise in credential theft (with an 800% increase in 1H2025) and the use of living off the land techniques (LotL). The attacker can log-in and use legitimate, trusted tools to evade detection and move laterally across the network to escalate those privileges. But the very fact these attacks don’t leave telltale footprints can make them much harder to detect. The SOC needs to rely on tools such as endpoint detection and response (EDR) and monitor tool usage to look for anomalies and that means listening to the less noisy network activity and low-severity alerts.
SOC: Selective Hearing
However, most SOCs focus on the high-severity alerts to such an extent that they even measure their success against the resolution of these incidents. SOC service level agreements typically specify a mean time to detection (MTTD) of 30 minutes and a mean time to respond (MTTR) of 15 minutes but the small print will often reveal this only applies critical alerts. Medium level alerts will typically be responded to within 1-2 hours and those low-level alerts that could indicate a LotL attack? Those are relegated to a window of 12 hours or more.
To capture this range of alerts will require the SOC to process ten times the usual volume of events. This presents the SOC with a quandary. How do you increase the monitoring and the ingest of alerts without submerging a SOC team who may already be drowning? For that to happen, the SOC must stop being selective and instead become more efficient.
To begin with, automation must be extended. Many teams will already be using Security Orchestration Automation and Response (SOAR) which can be configured to automatically remediate and close cases. But there are numerous other processes that can also benefit from automation. These can see the application of threat intelligence, automatic threat hunting and telemetry gathering, artificial testing, correlation with other alerts, and entity mapping, all of which can be used to enrich cases to the point where the SOC analyst doesn’t need to gather any further information when picking up the case.
Recovering from Cybersecurity Incidents
If we take the pre-defined playbooks that contain the recipe for how to detect, contain, eradicate and recover from specific cybersecurity incidents, for example, these can be automated to respond in a cascading effect. This sees one playbook used to trigger another depending on what the first has discerned, so that sub-playbooks iterate through lists of entities for each part of the case. Assuming 4,000 alerts coming into the SOC, triggering 100 playbooks per alert, with each playbook performing around ten actions such as enrichment lookups, correlation queries and containment steps, that’s equivalent to over four million triggered automations being executed per day before these cases are passed to a human analyst.
AI and the Analyst
AI, too, has a role to play. It currently enables the translation of free text questions into syntactical queries of Security Incident and Event Management (SIEM) and EDR data and can also be used to explain alerts, investigations and findings using human-friendly language and to summarise cases. It also lends itself to detection engineering, facilitating the faster creation of playbooks through the creation of code and detection syntax. With many detections sharing the same remedial actions, using AI to recommend a course of action makes sense, reducing analyst workloads substantially. And looking to the future, we can expect it to be used to optimise SOC operations by building playbooks on the fly and through the use of predictive investigative outcomes.
Applying these methods of automation enables any alert to be dealt with much more efficiently. The alert will initially be put through a process of enrichment, with threat intelligence used to compare the alert with known threats. SIEM and EDR searches will then correlate information, after which any associated alerts pertaining to the same entities (i.e. IPs, users, accounts, devices etc.) are linked to the case for the analyst to review. Using these processes, it’s possible to automate 65-70% of all SOC activity, dramatically reducing case workloads and allowing the SOC to process those massive alert volumes.
Human in the Loop
Yet, while automation is critical to adopting a paranoid posture capable of responding to evolving threats, it’s no substitute for the skills of the SOC analyst. Human expertise is invaluable in evaluating, verifying and deciding upon the best course of action and the likelihood is that those skills will become even more pertinent as AI becomes more widely used. This is because the technology can become so goal-driven that it becomes blinkered and can make incorrect deductions. In one instance, an AI agent went on to misinterpret a threat and produce a fictitious kill chain and mitigation advice, revealing the need for a human in the loop (HITL) and traceability in AI.
Paranoid monitoring does require the generation of more alerts for investigation. But we do have the tools and automation capabilities to handle those volumes so that this uptick needn’t equate to a massive increase in alert fatigue. What it does mean is that the role of the analyst will subtly change. They will be augmented by these processes and need to develop additional skillsets associated with validating these outputs, so the SOC will need to continue to invest in continuous training and progression, particularly if they want to hang on to that talent which remains in short supply. But unless we make these changes, the SOC won’t be able to keep pace with emerging threat patterns and will almost certainly fail to meet the challenge of AI-driven attacks.
Learn more at cybanetix.com
- Cybersecurity
- Cybersecurity in FinTech
- Digital Strategy
- Infrastructure & Cloud