ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Do we want or need the autonomous SOC?

The idea of an autonomous Security Operations Centre (SOC) is now back in the spotlight thanks to Agentic AI. Like flying cars, space planes and living on Mars, the autonomous SOC has long been viewed as a futuristic dream that handles the majority of detection and response with minimal human intervention. Agentic AI brings us a step closer to that reality because it sees AI break free from the need for human prompting, enabling the technology to go off and find the relevant tools and datasets it needs to complete a given task. 

 

However, there are real dangers in not having a human in the loop (HITL), as attested to by the recent revelation from Anthropic. The AI company disclosed that its coding tool, Claude Code, was manipulated by Chinese nation state actors to attack 30 entities in September, with 80-90% of the operations performed without HITL. Anthropic goes on to warn this has substantial implications for cyber-security in the age of AI agents and that it could increase the viability of large-scale cyber-attacks. Suddenly, a fully autonomous SOC no longer sounds so appealing.

 

But it’s not just the potential for abuse that brings into question the viability of such a SOC. Early explorations into the accuracy of responses when investigating an alert suggest AI will return different assessments each time. Even when attempts were made to fine tune or adjust prompts, the problem of a consistent response to the same input remained and this inconsistency could pose major problems for incident response.

 

Too expensive for TDIR

What’s more, experimenting with AI to discern these issues is way beyond the scope of most SOC teams because AI is prohibitively expensive. We calculate it’s at least twice as expensive to use for threat detection and incident response (TDIR) compared to using an automated SOC with Security Orchestration Automation and Response (SOAR) and detection engineering capabilities, for instance.

 

While More’s law would suggest that the cost for AI processing will decrease and with it probably the cost of AI SOC analyst, any deployment will need to be trialled, and the financial impact thoroughly assessed before putting into production.

 

Such issues create a real dilemma for many SOC service providers who are looking to capitalise on advances in AI and to defend against AI-enabled attacks. OpenAI noted in October that threat actors are using ChatGPT to produce malware or attempt to create spyware, although it hasn’t yet seen novel offensive capabilities i.e. attack-types that are new to defenders that utilise the technology.

 

Yet the expectation is that it is only a matter of time, with Sam Altman stating on record that he foresees some really bad stuff will happen because of the technology. Consequently, AI will need guard rails.

 

In the context of the SOC, that means having a human in the loop (HITL). The SOC will eventually use AI to not just handle repetitive tasks but also carry out complex ones such as dynamically running and constructing playbooks on the fly for investigations, determining whether the verdicts from those investigations point to suspicious or malicious activity, and remediating or containing threats automatically.

 

But these will need to be overseen by a human to ensure consistency in approach, whether the information has been correctly interpreted and to green light actions.

 

Getting to that point will require a gradual, phased approach to prevent the AI from overstepping the mark and analysts from becoming too trusting of AI outcomes.

 

Becoming AI-assisted

It’s a transition that will see the SOC move from the current rule-based approach we see today, which utilises multi-source correlation rules for detections and utilises SOAR and other systems for investigation, response and remediation, towards an AI-assisted model. This will involve the use of machine learning algorithms that self-tune for better detections while AI is used to simplify and streamline detection, engineering, investigation, response and remediation.

 

It’s only once this stage is reached that we can move on to partial autonomy, whereby LLM-based detections are used to predict new attacks and create detection logic for them. At this point, an AI analyst will be able to suggest remediation strategies for high-risk situations while leaving the high-risk and strategic decision making to the human analyst.

 

Therefore, while the AI analyst will draw upon and feed into automated tools, utilise predefined playbooks and will progress investigations, there will be a trickle-down effect from these tools that always ends with a human analyst.

 

Just how fast the SOC moves through these phases will depend on a multitude of factors. The team will need to consider where the technology can enhance use cases, the effect on analysts, the potential to tune and adapt outcomes of an investigation, and the number of additional system integrations required to achieve the outcome, as well as the costs involved.

 

That’s because using AI to carry out this level of threat hunting will be of another magnitude, with processing power ramping up in line with alert volumes, making the technology difficult to scale.

 

Realistically, this means the team will need to pick and choose where it deploys AI to deliver the optimum results, at least initially.  And, even when it is more widely used across the SOC, there will still be a need for the oversight, expertise and intuition that only human analysts can bring to the table.

 


 

Martin Jakobsen is CEO at Cybanetix

 

Main image courtesy of iStockPhoto.com and EvgeniyShkolenko


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543