Before you go shopping for an agentic engine, you need to know whether your SOC is ready to run one. That is not a philosophical question. It is an engineering question, and it has a measurable answer. This research gives you the diagnostic to find it.
We assess your operations across four domains: the quality of your data, the determinism of your logic, the readiness of your workflow, and the maturity of your governance.
The output is a decision, not a roadmap. And it is a decision with a third option that the market has not yet resolved: do you build the foundation yourself, do you hand it to a managed provider who already has, or do you buy agentic software and assume that the vendor has solved the engineering problem for you?
This research will help you understand which of those three paths is honest given where you actually stand, and why the third option carries risks that the sales deck will not mention.
Our Advice
Critical Insight
Cyberattacks are increasing in frequency, volume, and vectors, all at a scale that can’t be matched by adding more staff, refining processes, or buying more tools.
AI and agentic SOC tools abound, but attempting to layer such solutions onto unrefined data, without a set of defined guardrails for decision-making, is a recipe for accelerating chaos and further burying the SOC in unmanaged complexity.
We don’t have a tool crisis; we have a data crisis. Therefore, we need a data engineering solution.
Impact and Result
This research focuses on the critical first step that most organizations skip: an honest assessment of whether your SOC is ready for AI augmentation – and what form that augmentation should take.
- Assess Your Readiness: A structured SOC readiness assessment that evaluates your current operational maturity and surfaces the gaps that will undermine any AI initiative.
- Make the Decision: A framework for determining whether to build or buy your path to augmentation – and what that decision means for your people, your architecture, and your risk posture.
Get Ready for Augmented Security Operations
You can't fix a broken SOC with agentic AI agents. But you can fix the SOC to get it ready for AI.
An agentic AI platform will not fix the data crisis plaguing the SOC
Find out if you're ready to deploy one, and whether to build that readiness yourself or buy it.
Before you go shopping for an agentic engine, you need to know whether your SOC is ready to run one. That is not a philosophical question. It is an engineering question, and it has a measurable answer. This research gives you the diagnostic to find it.
We assess your operations across four domains: the quality of your data, the determinism of your logic, the readiness of your workflow, and the maturity of your governance.
The output is a decision, not a roadmap. And it is a decision with a third option that the market has not yet resolved: do you build the foundation yourself, do you hand it to a managed provider who already has, or do you buy agentic software and assume that the vendor has solved the engineering problem for you?
This research will help you understand which of those three paths is honest given where you actually stand, and why the third option carries risks that the sales deck will not mention.

Fred Chagnon
Principal Research Director
Security & Privacy
Info-Tech Research Group
Executive summary
Your Challenge |
Common Obstacles |
Info-Tech’s Approach |
|---|---|---|
The modern security operations center (SOC) is currently a reactive ticket factory, overwhelmed to the point where they’re only looking at 37% of their alerts (“just the critical ones, please”). Skilled analysts are trapped in guard duty, performing manual triage and repetitive data-gathering tasks that fail to scale with the increasing sophistication of the threat landscape. |
Cyberattacks are increasing in frequency, volume, and vectors, all at a scale that can’t be matched by adding more staff, refining processes, or buying more tools. AI and agentic SOC tools abound, but attempting to layer such solutions onto unrefined data, without a set of defined guardrails for decision-making, is a recipe for accelerating chaos and further burying the SOC in unmanaged complexity. We don’t have a tool crisis; we have a data crisis. Therefore, we need a data engineering solution. |
This research focuses on the critical first step that most organizations skip: an honest assessment of whether your SOC is ready for AI augmentation – and what form that augmentation should take.
|
An overloaded SOC is not a people, process, or tool problem – it's a data engineering crisis.
Before you spend a dollar on AI tooling in response to this crisis, you need an honest picture of where your operations actually stand. Use that evidence to make a confident, defensible decision about whether to build your augmentation capability in-house or buy it from a managed provider. That decision, made with clear eyes on your actual operational maturity, is the foundation everything else is built on.
The traditional human-led SOC has been mathematically eliminated from relevance
Too many incoming EVENTS to process |
Not enough time to TRIAGE all the events |
|---|---|
The result is blindness by design: Legacy SIEM economics have forced a SIEM tax on visibility, where the more you see, the more you pay, resulting in a conscious decision to leave the organization vulnerable. |
The result is uncodified heroics: When the thinking layer of the SOC is starved of time and clean data, it defaults to Intuition. High-speed threats are being met with "Gut Feel" triage, creating a critical failure in defense integrity. |
The traditional human-led SOC has been mathematically eliminated from relevance
So much FRICTION to act |
Complete lack of OVERSIGHT |
|---|---|
The result is an inability to act: You aren't running a security operation; you are running a cyber bureaucracy. The system is designed to prioritize compliance over velocity resulting in operational irrelevance. |
Liability by design: If your system can isolate a server but can't explain why it did so against a version-controlled trust registry of some kind, you’ve automated a random outage generator. |
Everyone says AI is the solution, but security leaders don’t trust AI
- The Velocity of Failure: The fear isn't just that the AI will be wrong – it’s that it will be wrong at machine speed.
- The "Black Box" Liability: If a CISO cannot explain the reason behind an automated, yet “bad” decision to the board, the result is a career-ending event.
- The "God-Mode" Paradox: We are granting AI agents high-level API access to sensitive tools (EDR, IAM, firewalls) without a permission broker.
- Contextual Blindness: An AI often sees the threat but forgets the mission. Without vetted business context, the machine might treat an industrial controller and a multi-function printer with the same blunt force containment action.
The "human-in-the-loop" requirement isn't a strategy; it’s a symptom of engineering failure.
74% of organizations are actively limiting AI autonomy in their SOC until explainability improves.
Kiteworks, 2026
Only 5% of CISOs feel fully prepared to contain a compromised or "rogue" AI agent once it starts acting in their environment.
Cybersecurity Insiders, 2026
Only 14% of organizations allow AI to take independent remediation actions. The vast majority (70%) still require a human to click "approve" before the AI can act.
Kiteworks, 2026
If your logging isn’t pristine, you’re not ready for AI in the SOC
If you ask an agent to act on data that is stale, sterile, or structurally ambiguous, you’re asking for hallucinations.
- Stale Logs: Telemetry that arrives in 15-30 minute batches is sufficient for human forensics but useless for autonomous containment.
- Sterile Logs: Raw logs often lack business context. An agent cannot determine risk if it doesn't know if a targeted IP belongs to a guest Wi-Fi printer or a domain controller.
- Ambiguous Logs: Without a standardized schema (like OCSF), different tools use different labels for the same entities. This forces the AI to waste compute cycles on translation and guesswork, often leading to hallucinated correlations between unrelated events.
- Noisy Logs: High-volume, low-value heartbeat logs clutter the AI’s finite context window. This noise tax pushes critical security signals out of the agent's active memory, causing it to miss the actual threat.
Data Layer – The fuel of the SOC machine
Where raw telemetry is collected from endpoints, network, cloud, and identity sources.
SIEM/Telemetry Pipelines (EDR, XDR, ITDR telemetry)
If your decision logic isn’t deterministic, you’re not ready for AI in the SOC
If an agent can’t explain the reasoning behind its decision, it should not have the authority to act.
- The "Black Box" Trap: Traditional risk scores (1-100) are sterile. If an agent inherits a "90/100" score without the underlying reasoning path, it is forced to guess the context. This leads to a reasoning hallucination where the AI invents a threat to justify the score it was given.
- Contextual Blindness: Without a standardized schema (like OCSF), the AI wastes finite context window cycles translating different labels for the same entity. This "noise tax" pushes critical security signals out of active memory.
- The Token Spiral: Every "thought" has a price. Using a high-cost large-language model to triage "low-fidelity trash" data is a fiscal liability. If your analytics aren't pruned, you will face an uncontrollable cost overrun through wasted compute.
Logic Layer – The spark of the SOC engine
Where data is transformed into a decision verdict through reasoning, correlation, and risk scoring.
Threat Detection Engines
If your response actions aren’t codified, you’re not ready for AI in the SOC
If a playbook requires a human to "just know" when to skip a step, the AI will fail at machine speed.
- The "No-Kill" Zone Gap: Humans know that "locking out a doctor in the ER" is a non-starter. Without explicitly defined business guardrails, the agent will prioritize the security event over the business mission, leading to technically correct but operationally fatal actions.
- Monolithic Playbook Failure: 40-page PDF runbooks are for humans. To an AI, these are "ambiguous maps." You must deconstruct these into deterministic atomic operations – code-based steps where there is zero room for "probabilistic improvisation.”
- The Reversibility Requirement: Traditional workflows lack a "kill switch." If an action isn't technically reversible, the agent should never be given autonomous control. Safety interlocks must be engineered into the workflow, not audited after the outage.
Workflow Layer – The SOC Transmission
Where decisions are translated into actionable, deterministic response steps.
SOAR, Playbooks
If actions aren’t strictly governed, you’re not ready for AI in the SOC
If you grant an agent the power to act without an architectural “veto,” you have engineered a machine-speed liability.
- Unmanaged Blast Radius: Traditional permissions tend to be binary – an analyst is usually an admin or user. An AI agent should have more discrete entitlements that limit its power based on the specific risk of the command it is sending (principle of least privilege).
- Irreversibility: Isolating a laptop is a "Low-Stakes" action because it can be reversed; wiping a production database is "High-Stakes." Without a map of what can be "undone," you cannot safely grant the agent autonomous permission.
- Bypassing the "Kill Switch": In a manual SOC, the human is the ultimate safety interlock. If you haven't engineered a decision proxy that can "veto" an agent's request in real-time, you are allowing a probabilistic model to make high-consequence business calls without oversight.
- The "Reasoning" Audit Trail: If an action causes an outage, the CISO must be able to explain why it happened. Every action must be locked to an immutable chain of custody from the initial alert to the final API call.
Policy Layer – The Guardrails
Where entitlement actions are checked, governed, and audited across endpoints, networks, cloud, and identity.
API Connectors/Safety Interlocks/Permission Brokers
Case study: The failure of unchecked autonomy
Blindly offloading response authority to an AI without a deterministic data schema transforms a security tool into a high-speed engine for operational self-sabotage.
INDUSTRY: Financial
SOURCE: Dark Reading, 2026
Challenge |
Solution |
Results |
|---|---|---|
A security leader at a major financial institution conducted a six-month trial to test a "Self-Driving SOC" concept. The organization attempted to move beyond deterministic, human-written playbooks by granting an AI agent broad permissions to manage alerts and execute response actions – such as removing users and closing accounts – across a non-production environment. |
The team deployed an autonomous AI agent designed to navigate both structured and unstructured data feeds. The agent was given the authority to interpret security signals and take remediating actions without a human-in-the-loop, aiming to solve the velocity gap through total machine-led response. |
The trial failed due to the "messy reality" of SOC data. Inconsistent identifiers and incomplete data fields led the AI to make incorrect associations, resulting in the accidental removal of legitimate users from the system. |
Info-Tech’s methodology for assessing your security operations for AI augmentation

Case study: The success of augmented intelligence
AI achieves its highest ROI as a “cognitive force multiplier” that directs the human gaze, reducing discovery time by up to 36% without surrendering control of critical infrastructure.
INDUSTRY: Food Manufacturing
SOURCE: Dark Reading, 2026
Challenge | Solution | Results |
|---|---|---|
Shilpi Mittal, lead for a global food manufacturing company, faced the challenge of correlating massive volumes of telemetry across EDR, network, and operational technology (OT) environments. The goal was to increase the speed of detection without risking the "safety interlocks" of the manufacturing floor. | The organization adopted an augmented security operations (ASO) approach. They deployed a large language model (LLM) strictly as a triage assistant. The AI was tasked with synthesizing disparate alerts into a single narrative and providing "next best action" recommendations. Crucially, the AI was forbidden from taking any direct action on production equipment, serving only to "direct the gaze" of the human analyst. | The augmented model functioned as a true force multiplier. The team recorded a 26% to 36% improvement in mean time to detect (MTTD) and a 22% improvement in mean time to respond (MTTR). |
You benefit from this work even before an agent is deployed
IT/SecOps Benefits |
Business Benefits |
|---|---|
|
|
Don't spend a dollar on AI until you know if your SOC is ready for it
This assessment delivers four concrete outcomes before you commit to a single tool purchase:
- A documented build or buy recommendation supported by evidence across 16 assessment questions — so your decision has a defensible rationale, not just a vendor's pitch.
- A scored readiness baseline across data, logic, workflow, and policy that can be remeasured after gap closure to track real progress.
- A prioritized gap closure action list that tells you exactly what needs to be fixed, and whether it's faster to fix it yourself or buy your way out of it.
- Protection from the most expensive mistake in security technology: Deploying a high-performance AI agent against contaminated data and broken processes, then paying twice to fix the problems you should have caught here first.
Augmented Security Operations Assessment

This assessment will step you through the following:
- Data — Can the AI actually see and understand your environment?
- Logic — Is there a repeatable methodology for the AI to augment?
- Workflow — Is the plumbing ready for bidirectional AI communication?
- Policy — Is the organization ready to trust and audit an autonomous system?
At the end of each domain, you will receive a build or buy recommendation based on your answers.
Security leaders are highly motivated by an AI SOC
However, the studies show a massive disconnect between intent and execution.
- The Intent: 85% of CISOs view AI as a key enabler (Microsoft), with 60% planning an evaluation this year (Prophet Security, 2025).
- The Execution Gap: 42% of SOCs attempt to use AI "out of the box" with zero customization (SANS Institute, 2025).
- The Result: AI/ML tools currently rank at the bottom of the satisfaction list for SOC technologies (SANS Institute, 2025).
We are witnessing a rush to adopt “autonomous” tools by organizations that still rely on “manual” data and logic.
If we don't fix the underlying information and logic gaps identified in Phases 1 and 2, the next 12 months will be defined by expensive, high-speed hallucinations rather than defensible security outcomes.
The four layers of ASOC failure
High-speed autonomy cannot be built on a foundation of unmanaged data and intuitive logic.
The Data Layer |
42% of SOCs dump unrefined data into a SIEM. |
|---|---|
The Logic Layer |
72% of analysts rely on intuition. |
The Workflow Layer |
57% of companies suppress rules to manage noise. |
The Policy Layer |
Only 10% of leaders prioritize AI infrastructure protection. |
“If you want effective analysis and containment [on an incident], you have to talk to all of these different siloed technologies and come up with a complete picture of what happened. But if you're missing any of these layers, you're painting a picture, but it’s incomplete."
– Jawed Ahmad, Author
Augmented Security Operations
1.1 Assess SOC readiness for AI
Download the Augmented Security Operations Assessment Tool
1 hour
Move through the 17 points in the ASOC readiness assessment. For each item, facilitate the following three-step loop:
- The Reality Check: Ask the specific owner (data, process, or architecture) if the capability is documented, automated, and repeatable.
- The "Why" Context: Read the "Why is this important?" column aloud. This ensures the CISO understands that a "NO" isn't just a missed feature – it’s a machine-speed risk.
- The Binary Verdict: Record the YES or NO. Do not allow "Partial" or "In-Progress" answers. If it isn't functional today, it’s a NO.
Input |
Output |
|---|---|
|
|
Materials |
Participants |
|
|
1.1 Assess SOC readiness for AI (cont’d)
Once a section is complete, or if the "NO" count becomes overwhelming, trigger the strategic realization protocol:
- Read the "BUY" Column: If the team lacks the "will or skill" to remediate a layer (e.g. data normalization), read the corresponding strategic realization text aloud.
- The Pivot Decision: Force a candid discussion: “Do we spend the next six months fixing the plumbing (BUILD), or do we buy a provider who has already sanitized the data (BUY)?”
Build Your Security Operations Program From the Ground Up
Develop a Security Operations Strategy
Develop and Deploy Security Policies
Build an Effective IT Controls Register
Select a Security Outsourcing Partner
Reinforce End-User Security Awareness During Your COVID-19 Response
Cybersecurity Priorities in Times of Pandemic
Build a Security Metrics Program to Drive Maturity
Build a Service-Based Security Resourcing Plan
Secure IT/OT Convergence
Integrate Physical Security and Information Security
Prepare for Post-Quantum Cryptography
Build an Automation Roadmap to Streamline Security Processes
Build an Autonomous Security Delivery Roadmap
Build a Robust Security Architecture With Microsoft Technologies
Get Ready for Augmented Security Operations
AI in Seven Charts
Emerging AI Trends and Predictions From Our Global Technical Counselor Team
Turn Customer Friction Into Agentic Opportunity
People Change in the Face of Disruptive Technology
Lead IT Like a Business: Every Dollar Is a Decision
Reinventing Cybersecurity in the AI Era
Optimize Cloud & AI Spend With Agentic FinOps
Reinvent Zero Trust for the Agentic Era Keynote
Influence Unleashed: The IT Leader’s Superpower
The Challenge of Ethics in the Use of AI
Revolutionize Risk Management With Agentic AI
Introducing the Info-Tech Speakers Bureau
Inside the Agentic Enterprise
Agents 2.0: From Autonomy to Architecture
Agentic IT: From Hype to Value
Tech Trends 2027 Keynote
Become an Exponential CIO
Securing Agentic AI and the New Security Reality
Beyond the Agent: The Leadership Ecosystem for an AI-Enabled World
Five Key Takeaways From Info-Tech LIVE 2026
Streamline Security Detection & Response Outsourcing