Content
Services
Industries
Talk to an expert

AI in the SOC: what works in practice and where analysts decide

· 7 min read · Network Secure

Artificial intelligence has become a selling point for almost every security tool. For anyone running or hiring a SOC, the useful question is not "does it have AI?" but rather: at which stages does AI actually reduce the time and effort of operations, and where is human judgment still indispensable? The short answer: AI handles the volume; the specialist makes the decisions that carry consequences.

Where AI genuinely helps

The classic SOC bottleneck is volume: many events, many repetitive alerts and little analyst time for each one. That repetitive, high-volume work is where AI and automation deliver the most.

  • Alert triage and prioritization. Models group related alerts, discard known noise and rank what remains by a combination of severity, asset criticality and observed behavior.
  • Context enrichment. Before a human opens the case, the platform has already attached IP and domain reputation, threat intelligence data, the asset's owner and role, the user's history and known vulnerabilities on the host.
  • Cross-source correlation. An after-hours login, an unusual process on an endpoint and an abnormal volume of file reads may be isolated events or a single incident. AI connects these signals from endpoint, network, cloud and identity and rebuilds the timeline.
  • Incident summarization. Language models turn dozens of events into a readable summary: what happened, on which assets, which MITRE ATT&CK techniques appear and what has already been done.
  • Threat hunting support. AI helps turn a hypothesis into queries and points out anomalies to investigate; the hypothesis and the conclusion remain the analyst's.
  • Response automation under agreed rules. Playbooks carry out actions such as isolating an endpoint, disabling an account or blocking traffic. In well-defined, pre-approved scenarios, containment can be automatic and happen in seconds; in all others, the action is prepared and waits for an analyst's approval.

This is the design of what we call a modern SOC (see Traditional vs. modern SOC): the machine absorbs the mechanical part of the work so that people can spend their time on what requires judgment.

Where AI does not yet replace the analyst

The limits matter as much as the gains.

  • Containment decisions with business impact. Isolating an intern's workstation is one thing; taking down the payments server at month-end close is another. Actions outside what was pre-approved, or with a significant effect on operations, need a person who weighs the cost of acting against the cost of waiting.
  • Business context. The model does not know that the "anomalous transfer" is the data migration agreed last week, or that a given supplier has just been offboarded.
  • Hallucination. Language models can produce fluent, wrong answers. NIST's generative AI profile (NIST AI 600-1) addresses this risk as confabulation. In a SOC, it can mean a summary that cites an IP address not present in the logs, or a conclusion without evidence. Every AI-generated claim must point back to the raw data.
  • Attacks against the models themselves. An assistant that reads emails, tickets or logs can receive instructions hidden in that content (prompt injection) and be led to classify an alert as benign. The MITRE ATLAS knowledge base catalogs adversary tactics and techniques against AI systems, in the same spirit as ATT&CK.

Automatic does not mean unsupervised. Automatic containment is only safe when the scenario, the action and the limits have been defined in advance with the customer, and when every action is logged and can be reversed.

Risks and governance: frameworks that help

Using AI in the SOC also means placing an AI system inside the company's most sensitive perimeter: it reads telemetry, credentials that show up in logs and personal data. Three public references help structure that risk.

  • NIST AI RMF 1.0. The AI Risk Management Framework, published by NIST in January 2023, organizes AI risk management into four functions: Govern (policies, roles and responsibilities), Map (context and intended uses), Measure (assessment and monitoring) and Manage (treating and prioritizing risks). The companion profile NIST AI 600-1, from 2024, details risks specific to generative AI.
  • OWASP Top 10 for LLM Applications. The OWASP GenAI Security Project list highlights risks such as prompt injection, sensitive information disclosure, improper output handling and excessive agency, that is, giving the model more permissions and autonomy than it needs. That last point is central to any response automation.
  • MITRE ATLAS. Maps how adversaries attack AI systems (data poisoning, evasion, prompt injection) and supports threat modeling against the SOC's own tools.

In practice, this translates into concrete controls: least privilege for automation agents, separation between what AI suggests and what it executes, logging of every decision and action, periodic review of automatic containment rules, and clarity about where customer data is processed, which also matters for data protection laws such as Brazil's LGPD.

Human in control: designing the division of labor

A useful model is to classify each type of action by impact and reversibility:

  1. AI does it alone. Enrichment, correlation, grouping, summarization and prioritization. None of these steps changes the customer's environment.
  2. AI executes within pre-approved rules. Low-impact, easily reversible containment in scenarios defined with the customer, such as disabling a compromised account or isolating a workstation, with immediate notification and human review afterwards.
  3. AI prepares, the human decides. Actions with significant operational impact, on critical systems or outside the planned scenarios.
  4. Human only. Communication with leadership, customers and regulators, decisions about triggering the incident response plan, and the final conclusion about what happened.

This division follows the logic of NIST SP 800-61 Rev. 3, which integrates incident response into risk management: roles and responsibilities are defined before an incident, not during it.

Metrics to measure the gain

"We use AI" is not a metric. To know whether AI is helping, compare before and after on the same indicators:

  • MTTD and MTTR. Have mean time to detect and mean time to respond dropped since AI took on triage and containment?
  • Rate of escalated false positives. How many alerts reach the customer's team without requiring action.
  • AI accuracy. In how many cases the analyst disagreed with the AI's classification or summary.
  • Reverted automatic actions. Automatic containments undone because they were unwarranted. This is the gauge of whether autonomy is well calibrated.

In practice: Network Secure's Autonomous SOC

In Network Secure's Autonomous SOC, the Open-XDR platform performs triage, enriches context with threat intelligence and triggers containment through playbooks; analysts validate criticality, investigate what is critical, map the attack to MITRE ATT&CK and tune the rules. The SOC is ISO/IEC 27001:2022 certified, with certification validated by Bureau Veritas.

Frequently asked questions

Will AI replace SOC analysts?

Not in any practical horizon. It replaces tasks, such as manual lookups, alert grouping and writing summaries, not judgment about business context, high-impact decisions or the investigation of new threats. The expected effect is that each analyst covers more, with higher quality.

Is it safe to let AI contain threats automatically?

Yes, when automation is limited to scenarios and actions defined in advance with the customer, that are low-impact and reversible, with every action logged and reviewed by a human. Outside that, the action should be prepared by AI and approved by an analyst.

How can I tell whether my SOC provider's AI works?

Ask for before-and-after metrics: MTTD, MTTR, escalated false positives, the rate of disagreement between analysts and AI, and reverted automatic containments. Also ask which actions AI can take without approval and where your data is processed.

Sources consulted: NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0, NIST AI 100-1, 2023); NIST AI 600-1, Generative Artificial Intelligence Profile (2024); OWASP GenAI Security Project, Top 10 for LLM Applications; MITRE ATLAS; MITRE ATT&CK; NIST SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management. This article is educational; the suggested division of tasks should be adapted to each organization's environment, risk appetite and agreements.

Official references

Read next