Tag: soc operations
2 articles

Evaluating AI in Security Operations Requires New Framework
When evaluating AI in security operations, it's crucial to determine if it can deliver accurate verdicts across various scenarios and attack surfaces - and surprisingly, verdict quality only improves dramatically once a certain threshold of relevant data, such as identity and context, is reached. Below that threshold, no amount of fine-tuning can compensate.

AI Overload: SOCs Struggle to Keep Pace with Alert Backlog
The harsh reality is that security operations centers (SOCs) are drowning in a sea of alerts, with a typical workload of 120-150 alerts per day, which translates to 40-50 analyst-hours of work - far exceeding the capacity of most teams. This means many alerts are left uninvestigated or pushed to the next shift, leaving SOCs vulnerable to threats.