International Cyber Expo International Cyber Expo
  • About Us
Monday, 28 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Is AI entering the SOC at the right stage?

by Lara Joseph
August 13, 2026
in Featured, Opinion
Is AI entering the SOC at the right stage?
Share on FacebookShare on Twitter

By Simon Phillips, CTO, CybaVerse

Alert fatigue is an issue that has plagued Security Operations Centres for years.

As organisations’ digital estates grow, there is more architecture to secure and more architecture for threat actors to attack, which has ultimately led to more alerts.

Today, on average a SOC will face thousands of alerts every day, each of which could indicate a potential threat. Each alert must therefore be analysed and investigated before appropriate action can be taken.

However, ask any SOC analyst and they will tell you the majority of these alerts are benign or false positives.

Yet, analysts will still spend hours investigating activity that ultimately poses little or no risk, hoping to identify the small number of genuine threats hidden amongst the noise.

Given the volume they face, and the possibility of missing something before it’s too late, it’s a noisy, high-stress environment that often leads to burnout and fatigue.

To tackle these issues, many SOCs today are turning to Artificial Intelligence (AI) to support the management of alerts.

In this scenario, the first-line analyst is replaced by an agent that reviews the incident to determine whether it’s malicious and if further action is required. The analyst must then review the conclusion reached by the agent to ensure it is accurate, but they don’t conduct the initial investigations themselves, which reduces the volume of alerts they have to investigate every day.

However, even despite these improvements, is there another way that could reduce the noise even further?

If organisations are still generating huge numbers of unnecessary alerts, have they actually solved the underlying problem, or simply moved it further downstream?

Moving AI upstream

Instead of asking AI to investigate incidents after they have been created, some organisations are using the technology much earlier in the detection process.

Rather than having AI decide whether an alert is malicious, in this scenario it’s used to help build better detection logic and more effective workflows before alerts ever reach an analyst.

For instance, in a phishing attack when an employee reports an email as suspicious, many security platforms immediately generate an incident that someone must investigate.

Traditionally, either a human analyst or an AI assistant would then collect additional context, checking whether links have been clicked, whether anyone else received the email, or whether similar activity appeared elsewhere in the environment.

If these types of checks are incorporated into the detection process, and the answers to the questions are no, then an incident would never need to be created in the first place.

The AI would determine that there was no wider threat, meaning the alert could be filtered out before it ended up in the SOC ticket queue.

The result is a faster, more efficient SOC, with far fewer unnecessary alerts reaching analysts.

From a customer perspective, this can also reduce the costs of working with an outsourced SOC partner.

Many AI-powered investigation platforms price their services according to the number of alerts they process, so reducing unnecessary alerts before they reach the investigation stage can improve efficiency while also helping organisations control operational costs.

Improving security through engineering

Another benefit of moving AI further upstream is that it limits access to sensitive customer data.

Many AI-driven investigation platforms analyse real customer logs and incident data to determine whether activity is malicious. While providers implement safeguards, some organisations are uncomfortable with sensitive operational data being processed by external AI systems, particularly where regulatory or contractual obligations apply.

Using AI during detection engineering changes this process. The AI is used to create the logic that identifies threats, not to inspect live customer data.

Once the detection rules have been verified, they can be applied consistently across customer environments without repeatedly sending operational data through AI models.

Solving the cause, not the symptom

The cyber security industry has become very good at handling alert fatigue, but not so good at preventing it. Is it time a different approach was adopted?

If security teams continue generating thousands of low-value alerts every day, replacing analysts with AI may improve efficiency, but it won’t address why the alerts exist in the first place.

As AI becomes more deeply embedded within security operations, organisations should consider where it delivers the greatest value. In many cases, the answer may not be at the point where analysts investigate incidents, but much earlier, where better detection engineering prevents unnecessary incidents from being created at all.

By reducing false positives at the source, this allows analysts to spend more time on genuine threats, while improving consistency, cutting costs and helping organisations make better use of both their technology and their people.

ShareTweet
Previous Post

Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks

Next Post

Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack

Recent News

cyber threat intelligence

New Guide from Filigran Highlights the Many Routes Women Take into Cyber Threat Intelligence

September 28, 2026
James Moore, CultureAI Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind

James Moore, CultureAI Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind

September 28, 2026
Attackers build “silent” cryptominer on victim’s machine and give themselves away

Attackers build “silent” cryptominer on victim’s machine and give themselves away

September 25, 2026
OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

September 25, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol