Today’s security operations centres (SOCs) are facing multiple challenges. According to a new report by the SANS Institute, a lack of skilled staff is the top operational challenge faced by SOCs, with 14% of those surveyed saying this is their main issue.
Security Information and Event Management (SIEM) is the most sought-after skill in hiring, with nearly double the demand of Endpoint Detection and Response (EDR). This is despite the fact that more day-to-day SOC responses come from endpoint security (86%), rather than SIEM alerts (78%).
It comes as AI is being considered to help lighten the load on SOCs. The survey found 79% of respondents use AI or machine learning tools, yet only 36% have built them into a defined SOC workflow.
As AI continues to become part of day-to-day business, how can CISOs build a resilient SOC?
Volume Matters
The volume of cyber-attacks is increasing, but experts say this alone does not paint a full picture of the issues faced by SOCs.
Tristan Shortland, CTO, Infinity Group says the volume of signals matters beyond simply the number of attacks. “Most SOC analysts spend their time separating genuine threats from noise, while managing increasingly complex environments spanning cloud platforms, identities, endpoints, SaaS applications and operational technology. Visibility without context can create just as many problems as blind spots."
Practitioners and leaders still face “a volume versus capacity issue,” says Rob Demain, CEO of e2e-assure.
It is fuelled by the fact that alert queues grow faster than headcount, and “most SOCs still run a human-first triage model whereby analysts process alerts in sequence,” says Demain. “This is where many CISOs and cyber leaders feel the pressure to integrate AI into workflows to reduce the alert volume that analysts need to handle.”
AI Boost
There’s no doubt AI offers a boost to some aspects of the SOC. Enrichment, triage, correlation and evidence gathering are areas “where AI genuinely helps,” says Martin Riley, CTO at Bridewell. “This is work that is repetitive, well bounded and evidence driven.”
When integrated correctly, with the suitable technology, AI should manage the “high-volume, repeatable work” at machine speed, says Demain. “If multiple models are used to create a ‘council,’ with each model specialising in a particular discipline such as threat identification, risk scoring, MITRE ATT&CK mapping, forensic planning, log comprehension, and hunt query consensus, they can then cross-check one and another and any areas of dispute can be flagged to the analyst. It then frees up the human in the loop to focus on the areas where they bring the most value, improving efficiencies and resilience standards.“
Even so, the technology should be approached with caution. “Everybody in security operations is using AI because the promise is substantial, but we're still in the phase where the reality hasn't quite caught up with the marketing,” says Christopher Crowley, senior instructor, SANS Institute and independent consultant at Montance, LLC, who also wrote the 2026 SANS SOC Survey.
He says one of the areas showing the most promise today is machine learning-driven detection. “When properly trained, machine learning tools can be extremely effective at highlighting anomalous activity and alerting analysts to take a closer look.”
Generative AI is less mature in security operations, largely because its consistency and reliability is still inadequate for many SOC use cases, says Crowley. “That said, it’s already proving its value in reporting and communication. Cybersecurity practitioners understand the technical details, but often struggle to translate those into why they matter to the business. Gen AI can help add that layer of context, making technical findings easier for decision-makers to understand and act on.”
AI Mistakes
Where AI does not yet help is autonomous response, says Riley. “The consequences of automated containment on a production system are too significant for current governance models to carry. We are blending AI reasoning with evidence to support connecting AI with deterministic automation, keeping the agent out of control for making changes.”
The mistake is “treating AI as an autonomous security analyst,” adds Shortland. Today, he thinks the technology’s real strength is “acting as a force multiplier that helps experienced analysts investigate incidents faster and focus their attention where human judgement matters most”.
It’s often touted as cure-all, but if initial configuration of alerts and general hygiene is not strong enough, AI “will not be able to fix the problem,” concurs Demain. “Cyber teams need the head space to fix their known configuration and alerting issues before they consider adding AI into their tech stacks.”
Resilient SOC
With all this in mind, how can firms build a resilient SOC in an age of AI and amid the growing skills gap?
Right now, Demain’s advice to CISOs is to log everything. “It's very tempting with extortionate logging charges to turn monitoring off, but you cannot protect what you cannot see. AI is being integrated across organisations and it's vital that the SOC has visibility of what it's doing and whether its behaviour matches baseline normal.”
Shortland advises starting with three foundations: Strong telemetry, effective automation and skilled people. “Remove any one of those and the model starts to struggle. AI strengthens the second pillar, but it doesn't eliminate the need for the other two."
A resilient SOC needs people “with the experience and judgement to oversee AI effectively,” says Crowley. “Although AI can process and analyse information at a scale that’s difficult for people to match, expertise is built through experience. If we're not careful, we risk creating a generation of practitioners who are expected to supervise increasingly sophisticated systems without having developed the skills needed to challenge their outputs. This makes human-in-the-loop integration critical.”
Crowley thinks organisations need to build this into their approach to AI and ask: “How do you know it is trustworthy?”
“There needs to be a default of constant scepticism,” he advises. “Fundamentally, that’s what cybersecurity is about – not trusting things automatically.”
Written by
Kate O'Flaherty
Cybersecurity and privacy journalist