Skip to main content

Tag: soc operations

2 articles

Security operations center analyst working at a workstation with multiple monitors and equipment.

Evaluating AI in Security Operations Requires New Framework

When evaluating AI in security operations, it's crucial to determine if it can deliver accurate verdicts across various scenarios and attack surfaces - and surprisingly, verdict quality only improves dramatically once a certain threshold of relevant data, such as identity and context, is reached. Below that threshold, no amount of fine-tuning can compensate.

Analyst 207
Security analysts overwhelmed in a brightly lit operations center with multiple screens.

AI Overload: SOCs Struggle to Keep Pace with Alert Backlog

The harsh reality is that security operations centers (SOCs) are drowning in a sea of alerts, with a typical workload of 120-150 alerts per day, which translates to 40-50 analyst-hours of work - far exceeding the capacity of most teams. This means many alerts are left uninvestigated or pushed to the next shift, leaving SOCs vulnerable to threats.

Analyst 207