Increasingly Dangerous Threats, Not More Alerts, Are the New SOC Challenge

149 Views

For years, security operations centres have operated under the same constraints of more alerts than analysts, more investigations than hours in the day, and more pressure than most teams can sustainably absorb. That imbalance is becoming dangerous as frontier models rapidly improve at finding vulnerabilities and turning them into exploits, while defenders are left dealing with the consequences in real time.

Anthropic’s Claude Mythos Preview showed how quickly this capability is advancing. Models are improving quickly at identifying flaws and helping turn them into working exploits. Anthropic said Mythos could identify and exploit zero-day vulnerabilities across major operating systems and web browsers and opted not to release it widely. This decision signals where offensive capability is heading.

The shift from volume to impact

The impact will not be evenly distributed. Vulnerability management teams are likely to feel the strain first, because if models make it cheaper and faster to uncover exploitable weaknesses, the number of issues demanding attention rises faster than most organisations can patch.

Recent breach data supports this. Verizon’s 2025 Data Breach Investigations Report found that exploitation of vulnerabilities accounted for 20% of breaches as an initial access vector, up 34% year-on-year.

But patching alone will not be enough, because defenders were already struggling to keep pace before this latest jump in capability. Detection and response are now the frontline for defenders. As alerts increase, the issue is not just volume but consequence as a larger share may represent real incidents that need to be understood and acted on quickly. For already stretched SOC teams, that is a far more serious problem than an increase in background noise.

Why investigation is now the bottleneck

The industry also needs to be more precise in how it talks about AI in the SOC. The core functions of the SOC have not changed. Teams still need to investigate alerts, contain threats, understand attacker behaviour and protect the business from impact.

What has changed is the intensity of those tasks. If attackers can move faster and at greater scale, defenders need to respond in the same manner. This means automating the investigative work that consumes most analyst time.

In practice, this comes down to alert investigation. It is the biggest bottleneck in modern detection and response. Most security teams do not have the capacity to thoroughly investigate everything in the queue, creating visibility gaps and increasing the risk that genuine threats are missed.

Used well, and augmented by human analysts, AI and automation can help remove the investigation bottleneck. Teams can investigate every alert, reduce response times from hours to minutes and reserve human effort for the cases that need judgement. The result is a more resilient and efficient SOC that can eliminate false positives faster, give analysts the investigative context they need, and focus human expertise on genuine threats.

Avoiding overreaction and complacency

There are two common mistakes to avoid. The first is panic. The threat is real, but the shift did not happen overnight as model capability has been improving steadily for years, and the current moment is better seen as a tipping point than a sudden break.

The second is complacency. Attackers tend to adopt new technology quickly before defenders fully adapt. CrowdStrike’s 2025 Global Threat Report pointed to a 442% increase in vishing between the first and second half of 2024 and noted that nation-state actors were already exploring generative AI for vulnerability research and exploitation.

That pattern should shape how cybersecurity leaders prepare today. In the short term, attackers may have the advantage as these capabilities become cheaper and more accessible, but it does not decide the outcome. Cybersecurity has always been a process of adaptation, and large language models do not change that basic dynamic. What they do change is how well organisations execute.

Organisations that continue to rely on overstretched analysts to run detection and response will continue to make high-risk decisions under pressure. Those that use automation to expand coverage and accelerate investigation will be in a far stronger position to contain threats early.

What the SOC will look like next

Over time, the SOC is likely to look less like a queue of humans working tickets and more like a team of experienced practitioners directing specialised AI agents. A useful comparison is modern software teams, where senior engineers guide and review work rather than doing everything themselves.

Security analysts and engineers will still own outcomes and handle the complex and high-risk decision, but much of the repetitive investigative work should no longer sit with them.

It is important to note that not everything can or should be automated. Remediation in complex environments still demands context, precision and risk trade-offs that carry significant business consequences if handled badly. Improving visibility across systems and working with other teams to make environments more observable will remain human-centric work. These responsibilities will become increasingly important as level-one analysis is automated.

As such, the real question for security leaders is not whether AI belongs in the SOC, but whether they can afford to let investigation remain the bottleneck as attackers become more sophisticated. For many SOC teams, the answer will define how effectively they operate in the next few years.