Our systems detected an issue with your IP. If you think this is an error please submit your concerns via our contact form.

Security icon

Get Ready for Augmented Security Operations

You can't fix a broken SOC with agentic AI agents. But you can fix the SOC to get it ready for AI.

Before you go shopping for an agentic engine, you need to know whether your SOC is ready to run one. That is not a philosophical question. It is an engineering question, and it has a measurable answer. This research gives you the diagnostic to find it.

We assess your operations across four domains: the quality of your data, the determinism of your logic, the readiness of your workflow, and the maturity of your governance.

The output is a decision, not a roadmap. And it is a decision with a third option that the market has not yet resolved: do you build the foundation yourself, do you hand it to a managed provider who already has, or do you buy agentic software and assume that the vendor has solved the engineering problem for you?

This research will help you understand which of those three paths is honest given where you actually stand, and why the third option carries risks that the sales deck will not mention.

Our Advice

Critical Insight

Cyberattacks are increasing in frequency, volume, and vectors, all at a scale that can’t be matched by adding more staff, refining processes, or buying more tools.

AI and agentic SOC tools abound, but attempting to layer such solutions onto unrefined data, without a set of defined guardrails for decision-making, is a recipe for accelerating chaos and further burying the SOC in unmanaged complexity.

We don’t have a tool crisis; we have a data crisis. Therefore, we need a data engineering solution.

Impact and Result

This research focuses on the critical first step that most organizations skip: an honest assessment of whether your SOC is ready for AI augmentation – and what form that augmentation should take.

  • Assess Your Readiness: A structured SOC readiness assessment that evaluates your current operational maturity and surfaces the gaps that will undermine any AI initiative.
  • Make the Decision: A framework for determining whether to build or buy your path to augmentation – and what that decision means for your people, your architecture, and your risk posture.

Get Ready for Augmented Security Operations Research & Tools

1. Get Ready for Augmented Security Operations Storyboard — A practical playbook for assessing your readiness to deploy AI agents in the SOC.

Before you deploy any AI agents in your security operations function, use this research to determine your readiness to have the right data, codify the right logic, and establish the right guardrails for your workflows. Or conclude that an MDR partnership can get you there faster.

2. Augmented Security Operations Readiness Assessment Tool — Supporting tool that helps you assess your current state and make a build or buy decision as it relates to machine-speed security operations.

The workbook includes the assessment activity that will lead you to understand the requirements to build your own augmented security operation function, or to partner with an MDR provider that can bring it to you (or a blend of both).


Get Ready for Augmented Security Operations

Get Ready for Augmented Security Operations

You can't fix a broken SOC with agentic AI agents. But you can fix the SOC to get it ready for AI.

An agentic AI platform will not fix the data crisis plaguing the SOC

Find out if you're ready to deploy one, and whether to build that readiness yourself or buy it.

Before you go shopping for an agentic engine, you need to know whether your SOC is ready to run one. That is not a philosophical question. It is an engineering question, and it has a measurable answer. This research gives you the diagnostic to find it.

We assess your operations across four domains: the quality of your data, the determinism of your logic, the readiness of your workflow, and the maturity of your governance.

The output is a decision, not a roadmap. And it is a decision with a third option that the market has not yet resolved: do you build the foundation yourself, do you hand it to a managed provider who already has, or do you buy agentic software and assume that the vendor has solved the engineering problem for you?

This research will help you understand which of those three paths is honest given where you actually stand, and why the third option carries risks that the sales deck will not mention.

Fred Chagnon.

Fred Chagnon
Principal Research Director
Security & Privacy
Info-Tech Research Group

Executive summary

Your Challenge

Common Obstacles

Info-Tech’s Approach

The modern security operations center (SOC) is currently a reactive ticket factory, overwhelmed to the point where they’re only looking at 37% of their alerts (“just the critical ones, please”).

Skilled analysts are trapped in guard duty, performing manual triage and repetitive data-gathering tasks that fail to scale with the increasing sophistication of the threat landscape.

Cyberattacks are increasing in frequency, volume, and vectors, all at a scale that can’t be matched by adding more staff, refining processes, or buying more tools.

AI and agentic SOC tools abound, but attempting to layer such solutions onto unrefined data, without a set of defined guardrails for decision-making, is a recipe for accelerating chaos and further burying the SOC in unmanaged complexity.

We don’t have a tool crisis; we have a data crisis. Therefore, we need a data engineering solution.

This research focuses on the critical first step that most organizations skip: an honest assessment of whether your SOC is ready for AI augmentation – and what form that augmentation should take.

  • Assess Your Readiness: A structured SOC readiness assessment that evaluates your current operational maturity and surfaces the gaps that will undermine any AI initiative.
  • Make the Decision: A framework for determining whether to build or buy your path to augmentation – and what that decision means for your people, your architecture, and your risk posture.

An overloaded SOC is not a people, process, or tool problem – it's a data engineering crisis.

Before you spend a dollar on AI tooling in response to this crisis, you need an honest picture of where your operations actually stand. Use that evidence to make a confident, defensible decision about whether to build your augmentation capability in-house or buy it from a managed provider. That decision, made with clear eyes on your actual operational maturity, is the foundation everything else is built on.

The traditional human-led SOC has been mathematically eliminated from relevance

Too many incoming EVENTS to process

Not enough time to TRIAGE all the events

  • Large enterprises are now facing approximately 3,000 alerts per day (with even mid-market firms hitting 500+). Because of this volume and poor data quality, 40% of all security alerts go completely uninvestigated (Prophet Security, 2025).
  • Even more alarming, 61% of security teams admitted to ignoring alerts that later proved to be critical security incidents. This is not negligence; it is a forced adaptation to impossible demands (SANS Institute, 2025).
  • 42% of SOCs admit to dumping all incoming telemetry into their SIEM without a retrieval or normalization plan, turning the expensive storage into a graveyard of unused data (SANS Institute, 2025).
  • On-prem SIEM costs surged by 116% in 2024, reaching an average of $93 per seat. While cloud SIEM costs dropped to $77 per seat, they are still considered a "premium" choice for those wanting AI-driven automation (SANS Institute, 2025).

The result is blindness by design: Legacy SIEM economics have forced a SIEM tax on visibility, where the more you see, the more you pay, resulting in a conscious decision to leave the organization vulnerable.

  • The fastest a mature human team can perform a high-fidelity triage (checking the user, host, and process tree) is 7.3 minutes per alert. That’s a total capacity of 65 alerts a day per analyst (without lunch) (Palo Alto Networks 2025).
  • With 3,000 events per day to process, it’s no wonder 63% of all security alerts go completely unaddressed (Vectra AI, 2026).
  • 40% of teams are now using AI for triage without a documented strategy or version-controlled logic, leading to "Shadow AI" where the reasoning behind a "Close Ticket" action is unknown (SANS Institute, 2025).

The result is uncodified heroics: When the thinking layer of the SOC is starved of time and clean data, it defaults to Intuition. High-speed threats are being met with "Gut Feel" triage, creating a critical failure in defense integrity.

The traditional human-led SOC has been mathematically eliminated from relevance

So much FRICTION to act

Complete lack of OVERSIGHT

  • 69% of SOCs still rely on mostly manual processes for their primary reporting and workflow triggers (SANS Institute, 2025).
  • Analysts spend up to 30% of their triage time simply switching between tools (EDR, SIEM, Identity, email) to gather the context required to execute a single workflow (Palo Alto Networks 2025).
  • In organizations with low automation maturity, the Mean Time to Contain (MTTC) averages 45 minutes (IBM, 2025).
  • Because workflows are manual, increasing the SOC to handle a 20% increase in alert volume requires a 20% increase in staff — an economic impossibility in a 350-event-per-second world.

The result is an inability to act: You aren't running a security operation; you are running a cyber bureaucracy. The system is designed to prioritize compliance over velocity resulting in operational irrelevance.

  • 20% of organizations have already suffered a breach specifically caused by the use of ungoverned LLMs to make access or policy decisions without an audit trail (Arcade.dev, 2025).
  • 97% of organizations that suffered an AI-related incident lacked a central automated action registry to define exactly what the machine is allowed to touch (Arcade.dev, 2025).
  • In 64% of automated containment actions, the chain of thought that led to the decision is lost, making it impossible for the CISO to provide a forensic audit to regulators or the board (Arcade.dev, 2025).

Liability by design: If your system can isolate a server but can't explain why it did so against a version-controlled trust registry of some kind, you’ve automated a random outage generator.

Everyone says AI is the solution, but security leaders don’t trust AI

  • The Velocity of Failure: The fear isn't just that the AI will be wrong – it’s that it will be wrong at machine speed.
  • The "Black Box" Liability: If a CISO cannot explain the reason behind an automated, yet “bad” decision to the board, the result is a career-ending event.
  • The "God-Mode" Paradox: We are granting AI agents high-level API access to sensitive tools (EDR, IAM, firewalls) without a permission broker.
  • Contextual Blindness: An AI often sees the threat but forgets the mission. Without vetted business context, the machine might treat an industrial controller and a multi-function printer with the same blunt force containment action.

The "human-in-the-loop" requirement isn't a strategy; it’s a symptom of engineering failure.

74% of organizations are actively limiting AI autonomy in their SOC until explainability improves.
Kiteworks, 2026

Only 5% of CISOs feel fully prepared to contain a compromised or "rogue" AI agent once it starts acting in their environment.
Cybersecurity Insiders, 2026

Only 14% of organizations allow AI to take independent remediation actions. The vast majority (70%) still require a human to click "approve" before the AI can act.
Kiteworks, 2026

If your logging isn’t pristine, you’re not ready for AI in the SOC

If you ask an agent to act on data that is stale, sterile, or structurally ambiguous, you’re asking for hallucinations.

  • Stale Logs: Telemetry that arrives in 15-30 minute batches is sufficient for human forensics but useless for autonomous containment.
  • Sterile Logs: Raw logs often lack business context. An agent cannot determine risk if it doesn't know if a targeted IP belongs to a guest Wi-Fi printer or a domain controller.
  • Ambiguous Logs: Without a standardized schema (like OCSF), different tools use different labels for the same entities. This forces the AI to waste compute cycles on translation and guesswork, often leading to hallucinated correlations between unrelated events.
  • Noisy Logs: High-volume, low-value heartbeat logs clutter the AI’s finite context window. This noise tax pushes critical security signals out of the agent's active memory, causing it to miss the actual threat.

Data Layer – The fuel of the SOC machine
Where raw telemetry is collected from endpoints, network, cloud, and identity sources.
SIEM/Telemetry Pipelines (EDR, XDR, ITDR telemetry)

If your decision logic isn’t deterministic, you’re not ready for AI in the SOC

If an agent can’t explain the reasoning behind its decision, it should not have the authority to act.

  • The "Black Box" Trap: Traditional risk scores (1-100) are sterile. If an agent inherits a "90/100" score without the underlying reasoning path, it is forced to guess the context. This leads to a reasoning hallucination where the AI invents a threat to justify the score it was given.
  • Contextual Blindness: Without a standardized schema (like OCSF), the AI wastes finite context window cycles translating different labels for the same entity. This "noise tax" pushes critical security signals out of active memory.
  • The Token Spiral: Every "thought" has a price. Using a high-cost large-language model to triage "low-fidelity trash" data is a fiscal liability. If your analytics aren't pruned, you will face an uncontrollable cost overrun through wasted compute.

Logic Layer – The spark of the SOC engine
Where data is transformed into a decision verdict through reasoning, correlation, and risk scoring.
Threat Detection Engines

If your response actions aren’t codified, you’re not ready for AI in the SOC

If a playbook requires a human to "just know" when to skip a step, the AI will fail at machine speed.

  • The "No-Kill" Zone Gap: Humans know that "locking out a doctor in the ER" is a non-starter. Without explicitly defined business guardrails, the agent will prioritize the security event over the business mission, leading to technically correct but operationally fatal actions.
  • Monolithic Playbook Failure: 40-page PDF runbooks are for humans. To an AI, these are "ambiguous maps." You must deconstruct these into deterministic atomic operations – code-based steps where there is zero room for "probabilistic improvisation.”
  • The Reversibility Requirement: Traditional workflows lack a "kill switch." If an action isn't technically reversible, the agent should never be given autonomous control. Safety interlocks must be engineered into the workflow, not audited after the outage.

Workflow Layer – The SOC Transmission
Where decisions are translated into actionable, deterministic response steps.
SOAR, Playbooks

If actions aren’t strictly governed, you’re not ready for AI in the SOC

If you grant an agent the power to act without an architectural “veto,” you have engineered a machine-speed liability.

  • Unmanaged Blast Radius: Traditional permissions tend to be binary – an analyst is usually an admin or user. An AI agent should have more discrete entitlements that limit its power based on the specific risk of the command it is sending (principle of least privilege).
  • Irreversibility: Isolating a laptop is a "Low-Stakes" action because it can be reversed; wiping a production database is "High-Stakes." Without a map of what can be "undone," you cannot safely grant the agent autonomous permission.
  • Bypassing the "Kill Switch": In a manual SOC, the human is the ultimate safety interlock. If you haven't engineered a decision proxy that can "veto" an agent's request in real-time, you are allowing a probabilistic model to make high-consequence business calls without oversight.
  • The "Reasoning" Audit Trail: If an action causes an outage, the CISO must be able to explain why it happened. Every action must be locked to an immutable chain of custody from the initial alert to the final API call.

Policy Layer – The Guardrails
Where entitlement actions are checked, governed, and audited across endpoints, networks, cloud, and identity.
API Connectors/Safety Interlocks/Permission Brokers

Case study: The failure of unchecked autonomy

Blindly offloading response authority to an AI without a deterministic data schema transforms a security tool into a high-speed engine for operational self-sabotage.

INDUSTRY: Financial

SOURCE: Dark Reading, 2026

Challenge

Solution

Results

A security leader at a major financial institution conducted a six-month trial to test a "Self-Driving SOC" concept.

The organization attempted to move beyond deterministic, human-written playbooks by granting an AI agent broad permissions to manage alerts and execute response actions – such as removing users and closing accounts – across a non-production environment.

The team deployed an autonomous AI agent designed to navigate both structured and unstructured data feeds.

The agent was given the authority to interpret security signals and take remediating actions without a human-in-the-loop, aiming to solve the velocity gap through total machine-led response.

The trial failed due to the "messy reality" of SOC data. Inconsistent identifiers and incomplete data fields led the AI to make incorrect associations, resulting in the accidental removal of legitimate users from the system.
The experiment proved that without strict governing principles and human oversight, autonomous AI cannot yet navigate the ambiguity of enterprise environments without creating significant operational risk.

Info-Tech’s methodology for assessing your security operations for AI augmentation

Info-Tech’s methodology for assessing your security operations for AI augmentation.

Case study: The success of augmented intelligence

AI achieves its highest ROI as a “cognitive force multiplier” that directs the human gaze, reducing discovery time by up to 36% without surrendering control of critical infrastructure.

INDUSTRY: Food Manufacturing

SOURCE: Dark Reading, 2026

Challenge

Solution

Results

Shilpi Mittal, lead for a global food manufacturing company, faced the challenge of correlating massive volumes of telemetry across EDR, network, and operational technology (OT) environments.

The goal was to increase the speed of detection without risking the "safety interlocks" of the manufacturing floor.

The organization adopted an augmented security operations (ASO) approach. They deployed a large language model (LLM) strictly as a triage assistant.

The AI was tasked with synthesizing disparate alerts into a single narrative and providing "next best action" recommendations. Crucially, the AI was forbidden from taking any direct action on production equipment, serving only to "direct the gaze" of the human analyst.

The augmented model functioned as a true force multiplier. The team recorded a 26% to 36% improvement in mean time to detect (MTTD) and a 22% improvement in mean time to respond (MTTR).
By keeping the human as the “governor” and the AI as the “information architect,” the organization successfully closed the visibility gap while maintaining total control over high-stakes OT outcomes.

You benefit from this work even before an agent is deployed

IT/SecOps Benefits

Business Benefits

  • Cleaner Data: You fix the chaos of stale and messy logs. This makes your current SIEM better for humans and actually usable for AI.
  • Predictable Playbooks: You turn 40-page PDFs into code. The AI stops guessing and starts following exact instructions.
  • Controlled Access: You won’t be giving AI "God-mode" keys. It only gets the specific, temporary permissions it needs to fix a specific problem.
  • Faster Response: You remove the "human-in-the-loop" bottleneck for simple tasks, stopping threats before they spread.
  • Lower Risk of Outages: Because the AI has "brakes," it won't accidentally kill a production database while trying to "help.“
  • Better Use of Talent: Your expensive analysts stop clicking "approve" on basic alerts and start actually engineering the defense.
  • Executive Confidence: You can explain exactly why the AI took an action. This gives the board the trust to let you keep the "auto-pilot" on.
  • Shift Toward Machine-Speed Defense: You finally start to move as fast as the attacker. You stop the breach in seconds, not hours.

Don't spend a dollar on AI until you know if your SOC is ready for it

This assessment delivers four concrete outcomes before you commit to a single tool purchase:

  • A documented build or buy recommendation supported by evidence across 16 assessment questions — so your decision has a defensible rationale, not just a vendor's pitch.
  • A scored readiness baseline across data, logic, workflow, and policy that can be remeasured after gap closure to track real progress.
  • A prioritized gap closure action list that tells you exactly what needs to be fixed, and whether it's faster to fix it yourself or buy your way out of it.
  • Protection from the most expensive mistake in security technology: Deploying a high-performance AI agent against contaminated data and broken processes, then paying twice to fix the problems you should have caught here first.

Augmented Security Operations Assessment

ASOC Readiness Assessment

This assessment will step you through the following:

  • Data — Can the AI actually see and understand your environment?
  • Logic — Is there a repeatable methodology for the AI to augment?
  • Workflow — Is the plumbing ready for bidirectional AI communication?
  • Policy — Is the organization ready to trust and audit an autonomous system?

At the end of each domain, you will receive a build or buy recommendation based on your answers.

Security leaders are highly motivated by an AI SOC

However, the studies show a massive disconnect between intent and execution.

  • The Intent: 85% of CISOs view AI as a key enabler (Microsoft), with 60% planning an evaluation this year (Prophet Security, 2025).
  • The Execution Gap: 42% of SOCs attempt to use AI "out of the box" with zero customization (SANS Institute, 2025).
  • The Result: AI/ML tools currently rank at the bottom of the satisfaction list for SOC technologies (SANS Institute, 2025).

We are witnessing a rush to adopt “autonomous” tools by organizations that still rely on “manual” data and logic.
If we don't fix the underlying information and logic gaps identified in Phases 1 and 2, the next 12 months will be defined by expensive, high-speed hallucinations rather than defensible security outcomes.

The four layers of ASOC failure

High-speed autonomy cannot be built on a foundation of unmanaged data and intuitive logic.

The Data Layer
Data & Observability

42% of SOCs dump unrefined data into a SIEM.
Stale, sterile "fuel" leads to hallucinated context
(SANS Institute, 2025).

The Logic Layer
Process, Logic & Reasoning

72% of analysts rely on intuition.
Without deterministic logic, the AI cannot arrive at a defensible verdict (Prophet Security, 2025).

The Workflow Layer
Orchestration & Determinism

57% of companies suppress rules to manage noise.
Implicit, monolithic playbooks cause operational paralysis (Prophet Security, 2025).

The Policy Layer
Authority, Oversight & Governance

Only 10% of leaders prioritize AI infrastructure protection.
"God-mode" credentials create an unmanaged blast radius (Cisco Systems, 2025).

“If you want effective analysis and containment [on an incident], you have to talk to all of these different siloed technologies and come up with a complete picture of what happened. But if you're missing any of these layers, you're painting a picture, but it’s incomplete."
– Jawed Ahmad, Author
Augmented Security Operations

1.1 Assess SOC readiness for AI

Download the Augmented Security Operations Assessment Tool

1 hour

Move through the 17 points in the ASOC readiness assessment. For each item, facilitate the following three-step loop:

    • The Reality Check: Ask the specific owner (data, process, or architecture) if the capability is documented, automated, and repeatable.
    • The "Why" Context: Read the "Why is this important?" column aloud. This ensures the CISO understands that a "NO" isn't just a missed feature – it’s a machine-speed risk.
    • The Binary Verdict: Record the YES or NO. Do not allow "Partial" or "In-Progress" answers. If it isn't functional today, it’s a NO.

Augmented Security Operations Assessment Tool.

Input

Output

  • List of key PPM decision points
  • List of who is accountable for PPM decisions
  • List of who has PPM decision-making authority
  • Completed ASOC Readiness Assessment
  • The Build/Buy Pivot: A definitive strategy choice
  • The Roadmap Backlog: A list of "Gap Closure Actions" derived directly from the "NO" answers.

Materials

Participants

  • Augmented Security Operations Assessment Tool
  • The 5-Layer Framework Reference
  • SIEM Administrators, Data Engineers, and Cloud Architects.
  • SOC Manager, Tier 3 Analysts, and Detection Engineers.
  • CISO, GRC Lead, and Infrastructure/Network Owners

1.1 Assess SOC readiness for AI (cont’d)

Once a section is complete, or if the "NO" count becomes overwhelming, trigger the strategic realization protocol:

    • Read the "BUY" Column: If the team lacks the "will or skill" to remediate a layer (e.g. data normalization), read the corresponding strategic realization text aloud.
    • The Pivot Decision: Force a candid discussion: “Do we spend the next six months fixing the plumbing (BUILD), or do we buy a provider who has already sanitized the data (BUY)?”
1.1 Assess SOC readiness for AI (cont’d)

You can't fix a broken SOC with agentic AI agents. But you can fix the SOC to get it ready for AI.

About Info-Tech

Info-Tech Research Group is the world’s fastest-growing information technology research and advisory company, proudly serving over 30,000 IT professionals.

We produce unbiased and highly relevant research to help CIOs and IT leaders make strategic, timely, and well-informed decisions. We partner closely with IT teams to provide everything they need, from actionable tools to analyst guidance, ensuring they deliver measurable results for their organizations.

What Is a Blueprint?

A blueprint is designed to be a roadmap, containing a methodology and the tools and templates you need to solve your IT problems.

Each blueprint can be accompanied by a Guided Implementation that provides you access to our world-class analysts to help you get through the project.

Talk to an Analyst

Our analyst calls are focused on helping our members use the research we produce, and our experts will guide you to successful project completion.

Book an Analyst Call on This Topic

You can start as early as tomorrow morning. Our analysts will explain the process during your first call.

Get Advice From a Subject Matter Expert

Each call will focus on explaining the material and helping you to plan your project, interpret and analyze the results of each project step, and set the direction for your next project step.

Unlock Sample Research

Author

Fred Chagnon

Contributors

  • Jawed Ahmad, CTO, Bell Cyber
  • Matthew Holland, CEO, Field Effect
Visit our IT’s Moment: A Technology-First Solution for Uncertain Times Resource Center
Over 100 analysts waiting to take your call right now: +1 (703) 340 1171