AI & Technology

From Alert Fatigue to Autonomous Defense

By Jeremy Ventura, Field Chief Information Security Officer (CISO) at global systems integrator Myriad360

Today’s SOC is not challenged by the promise of AI, it is challenged by how to operationalize AI in a way that scales security operations effectively. 

Sit in on enough security conversations and a pattern becomes clear: the moment AI in the SOC comes up, enthusiasm quickly gives way to an important question—where and how should organizations begin? 

The State of Today’s SOC 

Here is what I tell people first. This isn’t a technology problem. It’s a scale problem. The entire operating model has stopped scaling. Years ago. The overwhelming volume of alerts is just the “trigger” people notice first. 

Analysts spend their days stuck in triage loops instead of the high-value work they were hired for. We’ve gotten really good at initial detection over the years, but response never caught up. And the biggest issue is context: all of it exists somewhere, just spread across multiple technologies. 

Most environments I walk into are running 20, 30, 50 tools, and none of them are fully integrated with each other. In Splunk’s State of Security 2025, more than half of SOC teams report too many alerts and too many false positives. That is not a tooling gap, it is a volume that the human layer was never built to absorb. 

Why Human Speed No Longer Works 

The overload is real, but it has an external driver, and that driver is speed. Attackers are operating at machine speed, and we’re still asking humans to keep up manually. 

For the last twenty years, there’s been a window every defender got comfortable with, a window we quietly built our entire operating model inside of, assuming an attacker would always need time. The old advanced persistent threat playbook demanded patience: break in, map the environment, move laterally, wait. Agentic AI removes every one of those steps, and the patience that made the model work is gone. That window is closing. 

The old way: Enter. Dwell. Learn. Wait. The new way: blast in, scan everything, execute, and leave. 

The numbers make it concrete. Mandiant’s M-Trends 2026 says attacker handoffs that took more than 8 hours in 2022, are now at 22 seconds today. 

I’ve watched this threat class up close. During my time at Raytheon, I encountered APT41, the Chinese state-sponsored group that sat inside U.S. government networks for months before anyone knew they were there. Months of dwell time, patient and quiet, the way the old model rewarded. Now imagine that same intent running at agentic speed. 

Now compress that kind of dwell time down into seconds and put it against the defender’s clock. Studies find that analysts spend over an hour investigating each alert, and a large share of those turn out to be false positives. Stack an hour per alert against an adversary moving in seconds, and it is obvious who is winning the clock. 

You can’t answer machine speed with human speed. The math doesn’t work. Only software can joust with software. 

Eight in ten security practitioners now say AI-powered defense isn’t optional, and I agree with them. But knowing it and building for it are two different things. 

Where AI Actually Delivers in the SOC 

Let’s strip away the hype and look at what AI actually is inside the SOC. It starts with augmenting the analyst, gathering information and suggesting next steps like a sidekick or teammate who keeps the human in the loop. It adds context automatically, writing accurate summaries and enriching data so analysts spend less time reporting. It reduces manual work by centralizing tools and pivoting across alerts, and it improves decision speed, taking an investigation that used to run forty minutes down to two. 

Put plainly: instead of a human eyeballing 500 alerts, the system surfaces the three that actually matter. The other 497 don’t vanish, they’re triaged, correlated, and closed or escalated without a person burning an hour on each one. 

Here’s how I explain the plumbing to clients. All your telemetry, SIEM, EDR, network, cloud, identity, and SaaS, lands in one place and gets correlated into a single picture instead of ten disconnected ones. The system lines it up against the attack frameworks, like MITRE or NIST, so a machine, not a worn-out analyst at 2 a.m., does the first pass. From there it moves down the line: AI-driven triage and prioritization, automated enrichment and correlation, agentic investigation, and finally response and containment, each stage handing cleaner signals to the next. 

Picture the same alert hitting two different systems at 2:41 in the morning. On the legacy stack, it lands in a queue and waits. An analyst has to wake up to it, log into one console for the identity signal, another for the endpoint signal, and stitch the story together by hand. By the time anyone is confident enough to act, the better part of a day is gone. 

On the AI-driven path, that same alert never sits still. The system has already pulled every one of those signals into one picture, enriched it, scored it against known attacker behavior, and either contained the threat or handed the analyst a finished case to approve. Same alert, same severity. Minutes instead of hours. 

That’s the combination that matters: you’re collapsing steps and saving time at the same moment, and that is the whole reason to bother. 

Operationalizing Responsibly 

None of this is a switch that you can instantly flip. You don’t jump from manual to agentic overnight. This is about progression, not perfection. Each step in the journey matures over time, the way you’d add automation to anything you actually depend on. 

The real shift is what happens to the analyst: they stop gathering data and start making decisions. Stay fully manual and burnout is inevitable, because everything depends on people scaling linearly while the threats don’t. 

But automation on its own isn’t the answer either. It only works for what you’ve already predefined, so anything new or unexpected still breaks the system. That’s the trap teams fall into when they bolt on a pile of rules and call it autonomy. 

Real autonomy only works if you’ve built trust and guardrails into the earlier stages. Otherwise you’re just automating risk, and if your analysts don’t trust the tools, none of it matters. The same honesty applies to your own environment: plenty of enterprises are hesitant about AI while their employees already use it, which is exactly why shadow-AI discovery and governance belong in the plan. 

I’ll be straight about the market. Most vendors are marketing this before they can deliver it, and while the concept is right, the reality is still early. The direction, though, is set: Microsoft published an agentic SOC framework in April, and Google is moving the same way. 

And there’s a human cost to rushing it: strip out the entry-level roles and you remove the scaffolding that lets people grow into senior ones. 

Measuring Success: The ROI Shift 

Move deliberately, and the scorecard changes. In an AI-driven SOC, the question becomes how efficiently you’re operating and how much you’re offloading from humans. 

Closing tickets is activity. Freeing up analyst hours is impact. 

More tools don’t equal better security, and the real question is whether you’re using what you already paid for. Detection is table stakes, so measure how long it takes to reach a confident decision. And response is broad, but containment is the part that actually reduces business risk. 

The contrast shows up fast once you measure it. Teams that were triaging maybe a third of their alerts by hand move to handling nearly all of them, most of it through automated workflows instead of a person clicking through consoles. The tools they already paid for go from barely touched, a fifth of the stack in real use, to most of it actually working, and analysts claw back hours every day, an investigation that once burned 20 minutes dropping to about 3. Treat those as directional, not a guarantee, but the shape is real. 

The sequence is straightforward. Start with high-volume, low-risk use cases, embed AI into existing workflows instead of bolting it on, prioritize data quality and context, and measure outcomes rather than activity. Run it on a cadence: prove value in the first 30 days, expand by 90, harden by 180, and build toward broader autonomy by 360. That discipline isn’t unique to security teams; JPMorganChase laid out ten actions for AI-ready cyber resilience on the same build-deliberately logic. 

Your SOC isn’t broken. AI is a force multiplier, not a replacement. 

There’s no silver bullet right now. Nobody has one. The fundamentals are the same ones we’ve been preaching for a decade: harden your environment, know your assets, invest in your people, and embrace AI where it earns its place. 

There’s no cybersecurity version of pulling up the drawbridge, so move deliberately. Know what you have, know what’s exposed, close what you can close, and build toward an architecture that actually matches the threat. 

That uncertainty everyone feels about AI in the SOC isn’t a reason to wait. The organizations still holding out for a definitive signal will find they already missed it. 

Author

Related Articles

Back to top button