The images in this article were generated with artificial intelligence. How we publish
Eighteen months ago, the "AI in the SOC" was more a marketing promise than a budget line. Today is the opposite: budgets are emptied to buy models, copilots and agents, but real value indicators do not move to the rate of expenditure. The first target benchmark - the SOCM - CMM 2026 Maturity Report - shows that only 10% of SOCs perceive an excellent value of their IA deployments, another 19% perceive good value and the remaining 71% remains at a limited or zero value. This clear relationship requires reading beyond anecdote: the problem is structural, not just technical.
The data point to two urgent patterns: massive adoption of IA technologies and an implementation model that the community identifies as "taker": off- the- shell solutions are bought and placed on the existing stack without changing operational architecture. Off-the-shell LLMs, copilots and agents are growing at double-digit rhythms in adoption, but most have not been integrated into shared workflows or personalized with the institutional experience of each organization. The result is five IA assistants who do not share context, not a single intelligence that improves end- to- end flow.

This matters because most of the value in a SOC is not in accelerating a timely task but in improving transfers between stages: threat intelligence, hunting, detection, research and mediation. When IA only accelerates each individual silo, cycle times are not reduced in a sustained manner and governance policies are weak. In the report, technology scores higher than processes and people; buying more tools without transforming processes or human capital usually makes the problem worse because it adds new points of context transfer.
The few organizations that do report "excellent" value share three clear architectural decisions. First, they run IA as a layer that connects all the stages of the SOC and maintains the context between them: a finding in investigação feeds a detection rule, a hunt updates intelligence, a remediation is recorded and improves the following execution. Second, the IA is trained and persists on its own data - critical assets, climbing criteria, incident history - so that the exits are no longer the "internet average" and they reflect the customer's operational reality. Thirdly, governance is incorporated: traceability of decisions, limits of autonomy and audit that allow analysts to rely on and delegate progressively.
If your team sees investment without results, the practical reading is simple but difficult to run: you cannot fix the SOC only with more models or more agents. It takes a connective layer that orchestrates flows and preserves knowledge. This layer does not necessarily require replacing all the stack: it can operate on top of IMS, EDR, identity, cloud and ticketing as long as there are integrations, data contracts and a clear model of the SOC "memory" persistence.
The operational and risk implications are real. A fragmented SOC with a silo IA accelerates tasks and at the same time amplifies the likelihood of inconsistent decisions, duplication of effort and inadequate autonomy controls. In contrast, a SOC with an IA connective fabric can detect faster cross-cutting patterns, reduce false positive by continuous calibration and generate decision records that are essential for compliance and legal response.
In practical and priority terms, security teams must start by mapping flows: identifying handoff points, what data are lost between tools and where the IA consumes or creates artifacts that no one stores. The following layer is governance: to require traces of reasoning, to set authorisation limits per agent and to define minimum metrics to accept autonomy (for example, hit / no-hit accuracy and actual MTTR reduction before allowing automatic executions). Finally, a knowledge retention plan must be established that survives staff rotation and tool changes, because institutional customization is the difference between noise and decision.
From a technical perspective, the second wave of IA in safety will be architectural, not features. This involves designing a context bus or "fabric" that accepts standard telemetry, enriched events and agent results, and that delivers that context to each component in usable format. It also requires continuous testing: detection benchmarks in its own environment, adverse testing and validation of remediations in controlled environments to avoid unexpected effects on production.

Governance must be aligned with recognized reference frameworks: implement risk management policies for IA, document decisions and ensure traceability. The teams can rely on public guides to structure controls and audits; for example, the NIST AI Risk Management Framework provides guidelines for integrating risk, governance and transparency into IA deployments ( NIST TO RMF). In parallel, a technical integration based on robust threat models and telemetry benefits from frames such as MITRE ATT & CK to map detections and validate coverage ( MITRE ATT & CK).
For purchase managers and security equipment: require clear answers to three questions to suppliers: can the solution operate and share context throughout the entire cycle of an incident? How do you capture, validate and preserve institutional experience? and what records and controls do you provide to audit automated decisions? If the response is evasive or technical without full use, it is probably the first wave of adoption and its ROI will be limited.
Finally, it is not a matter of technology vs. people: transformation requires simultaneous investment in detection and processes, training of analysts to monitor "on the loop" agents, and metrics to measure real progress (reduction of time to detection and response, reduction of false operational positives, resolution time per category). Doing this fast does not require breaking all the stack, but a coherent vision that prioritizes the flow architecture over the multiplication of attendees. If the goal is to go from 10% to 50% that really gets value, the route is clear: to connect, to govern and to persist the institutional memory within the IA.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...