Command Zero
SOC

Direction of the Modern SOC: From Alert Queue to Outcome

When AI can pick up, investigate, and close most alerts faster than a person, the queue stops being the analyst's job description, and security leaders are still working out what replaces it.

James Therrien — avatarJames TherrienSeptember 17, 2026 · 7 min read
 — cover image

The alert queue used to be the job. Automate the queue and you have to explain what the analyst is actually for.

The big picture: For two decades, the SOC analyst's day has had the same shape regardless of tooling: pick up the next alert, pull context from however many tools are open, decide if it's real, write up what happened, close it, repeat. AI-driven triage is now good enough to run most of that chain itself for Tier 1 and a meaningful share of Tier 2, start to finish, without a human touching the ticket until there's a verdict to review. That isn't a productivity upgrade to the existing job. It removes the activity the job was built around, and the SOC has to decide what fills the space left behind.

Why it matters: SOCs have staffed, trained, and measured themselves around throughput for so long that alerts closed, mean time to detect, and mean time to respond function as proxies for whether the operation is working at all. Once AI absorbs most of that volume automatically, those numbers describe the AI's performance more than the analyst's, and a tier structure built to escalate volume through layers of increasing seniority stops mapping to how the work actually flows. Leaders who don't redefine the job and the scorecard end up either paying for a queue that no longer exists or losing track of who is accountable for the outcomes that used to surface in manual review.

By the numbers:

  • AI use in security operations jumped from 50% to 78% of practitioners in a single year, per SANS' 2026 AI Survey.
  • That adoption is outrunning trust: 63% of practitioners report real shortcomings in AI's threat detection and response, up from 45% the year before, and 67% say they've been misdirected by AI guidance at least once in the past year.
  • Automated incident response has reached 39% adoption, but the confidence gap runs top to bottom: 50% of security leaders believe they have a formal AI risk program in place, while only 36% of practitioners agree.
  • Separately, 71% of SOC analysts report burnout and 64% are considering leaving their job within the year, according to Tines' Voice of the SOC Analyst survey of 468 analysts, reported by Dark Reading. Triage is the task those same analysts rank as least preferred, well behind reporting and monitoring.

Where the job actually moves:

  • What disappears: The manual chain of pulling indicators, checking them against a half-dozen tools, and writing up a determination for the case that turns out routine. That's both the most repeatable part of the job and, per Tines' survey, one analysts say they'd rather not do.
  • What gets promoted: Threat hunting against AI-generated hypotheses instead of raw logs, detection engineering informed by what the AI got wrong or missed entirely, and incident response for the cases that don't resolve cleanly on the first pass.
  • What's new entirely: Governing the system doing the triage. Someone has to decide what the AI investigation layer is allowed to touch, review its decision log for drift, and approve the detection changes it proposes. That function didn't exist when a human executed every step by hand.

What industry experts are saying

Command Zero's leadership frames the shift as a relocation of effort rather than a reduction of it. CPO Alfred Huger put it plainly: "Agents can now do all of that grunt work, while the human moves up the stack to judgment," he told Insight Partners. On what that means for staffing, Huger added, "They can certainly do more with less, but in many cases, they can simply do more with more," pointing to organizations that reinvest the recovered time into threat hunts and previously deprioritized investigations rather than cutting the team.

CEO Dov Yoran raised the harder question underneath that optimism: where the next generation of senior analysts comes from if the entry-level tier gets automated away. "You'll certainly still need those Tier 2 and 3 analysts that have the experience," he told the same publication. "Where are those going to come from, if you all of a sudden kill your Tier 1 footprint?" Tier 1 has functioned as the SOC's training ground for as long as the tiered model has existed, and no one in the industry has a clean answer yet for what replaces it.

Microsoft's security leadership describes the same transition in its own language. In an April post on the agentic SOC, corporate vice presidents Rob Lefferts and David Weston wrote that analysts move "from triaging alerts to supervising outcomes," reviewing AI-led investigations, deciding when a case needs deeper inquiry, and feeding judgment back into how the system learns, according to the Microsoft Security Blog. The post cites internal agents automating 75% of phishing and malware investigations under human supervision, a scale of delegation that would have been unthinkable in a SOC organized around manual triage.

Tines co-founder Thomas Kinsella ties the retention math directly to the task itself: "What's dragging them under is repetitive, manual tasks, which in turn keep them from working on higher-impact projects that contribute to their organization's overall security posture," he told Dark Reading. Removing triage isn't only a speed play. For a workforce with 64% turnover intent, it's plausibly a retention one too.

The limits of the transition

Between the lines: The real risk isn't a shrinking SOC, it's a widening gap between how fast AI is being adopted and how much practitioners actually trust it. The open question is Yoran's, not a headcount question but a pipeline one. If Tier 1 has always been where analysts built the pattern recognition to eventually do Tier 2 and Tier 3 work, and AI absorbs most of Tier 1's casework, organizations need a new way to develop that judgment that doesn't run through years of manually closing tickets. Rotating junior analysts through structured threat hunts and detection engineering under senior supervision is the leading candidate, but it's a training redesign, not a tool purchase, and most SOCs haven't started it.

The bottom line: Automating the queue doesn't automate the job, it relocates it. What moves off the analyst's plate is the task they liked least and were most likely to quit over. What moves on is judgment: hunting against hypotheses instead of logs, tuning detections instead of clearing them, and deciding what an AI investigation layer should be trusted to touch. The metrics have to move with it, especially as attackers move faster: some intrusions now reach a stolen cloud credential within nine to seventeen minutes of exposure, per research on post-automation SOC metrics, a pace that alerts-closed and MTTR were never built to measure. A SOC that still reports alert volume and calls it a scorecard is measuring the AI, not the team, and missing the question that actually matters: whether the attacker's path to their objective got interrupted before it succeeded.

Terms in this post

Terms defined in Command Zero's glossary are linked below. Terms without a glossary entry yet are defined here.

What is a tiered SOC model?

A tiered SOC model is the traditional structure in which Tier 1 analysts perform initial triage, Tier 2 handles deeper investigation and confirmed incidents, and Tier 3 covers advanced threat hunting and incident response leadership.

What is attack-window coverage?

Attack-window coverage is a proposed outcome-based metric that compares a defender's actual containment time against an attacker's real execution timeline for a given attack path, rather than measuring alert-processing speed in isolation.

What is dwell time?

Dwell time is the length of time an attacker remains active in an environment before being detected and removed.

Keep reading

More from SOC.

Get Started

See what your team can achieve.

Live in under an hour. No migration. No friction.

Book a Demo
No training data requiredSOC 2 CompliantDirect-to-data