Cybersecurity / Source date:

Security Operations With AI Analysts: What Humans Still Do

Triage automation cut alert fatigue while escalation judgment and adversary reasoning stayed human.

Illustration of an analyst comparing a redacted event record with a separate notebook of human review reasoning.

The triage layer of security operations was always the weakest part of the discipline, not because the people were weak but because the work was structurally impossible. Thousands of alerts a day, most of them benign, examined by whoever is on shift, with a quality that varies by hour of the night. Automating it is not a threat to the profession. It is the removal of a job nobody should have been doing. What it does change is the shape of the team, the failure modes and the things that go unnoticed — and those consequences arrive faster than most operations centres plan for.

Automated triage does not reduce the number of alerts anyone looks at. It changes which alerts a human never sees, which is a much larger decision than it sounds

Here is what an artificial-intelligence-assisted security operation actually looks like when it works.

What the machine layer does well

Enrichment, unambiguously. Gathering context from six systems before a human reads the alert removes the single largest time cost in triage and carries almost no risk. Correlation across sources, where the volume defeats human attention and the pattern is genuinely detectable. First-pass classification of high-volume, well-understood alert types, where the base rate is known and the consequence of a miss is bounded. Drafting the investigation narrative, which saves real time in handover and reporting and is trivially checkable.

What it does badly

Novelty. An alert type that has never been seen before is exactly the one the classifier handles worst, and it is exactly the one that matters. Any design that routes low-confidence items to the same place as low-severity ones will bury the interesting cases. Also, judgement about business context — whether this administrator working at this hour on this system is unusual for this company. That knowledge lives in people and is rarely written down anywhere a model can read.

The design decisions that matter

Route by confidence, not only by severity, and make low-confidence items a distinct queue that a senior person reviews. This is the control that preserves your ability to see the unexpected. Sample the auto-closed population continuously. A triage layer that closes eighty per cent of alerts is making eighty per cent of your security decisions, and the only way to know whether it is right is to review a random sample regularly and permanently. Keep the analyst's reasoning in the record. When the machine drafts and a human confirms, the record must distinguish the two, or your post-incident review will be reconstructing who actually decided what.

Keep the human controls explicitArticle-derived review responsibilities, not a universal AI accuracy or auto-closure benchmark.
Automated activityHuman control
Enrichment and classificationProvide business context and route uncertain cases separately.
Auto-closureReview random samples and test known-bad scenarios.
Drafted investigation narrativeRecord which reasoning came from the machine and who confirmed it.
Model changesReview classification behavior and detection-rule noise after changes.

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

The staffing consequence nobody plans for

The entry-level tier was where analysts learned. Remove it and you have a team of senior people with no pipeline behind them, in a market where senior security staff are already the scarcest resource you have. Design the learning path deliberately, because the traditional one has been deleted.

Practical Guidance for SOC Modernization Review

  • Automate enrichment first; it is pure gain.
  • Route low-confidence items to a separate senior queue.
  • Sample auto-closed alerts continuously and permanently.
  • Keep machine and human reasoning distinguishable in the record.
  • Feed business context in explicitly; the model cannot infer it.
  • Measure missed detections, not only time saved.
  • Rebuild the analyst learning path you just removed.
  • Review classification behaviour after every model change.

The Regional Angle

The first regional consideration is that scarcity of experienced analysts is more acute in the Gulf than the global figures suggest, and the competition is not only commercial — national cybersecurity programmes and large government initiatives absorb a substantial share of the experienced pool. For most regional organisations, automated triage is therefore not a cost-reduction exercise but the only realistic way to achieve continuous coverage with the small number of skilled people they can actually retain. The business case here is capability, not savings, and it should be written that way. The second concerns the outsourced model, which dominates regional security operations, and the question of where the automation sits. If your provider runs the triage layer, the auto-closure decisions are being made inside a system you cannot inspect, against thresholds you did not set, with sampling you do not see. Regional buyers should require visibility of the closure rate, the right to sample the auto-closed population themselves, and notification when the provider changes models — none of which appears in a standard regional service agreement. The third is about the data that makes any of this work. Security operations depend on log retention, and regional organisations frequently retain far less than the investigation timeline requires, partly for cost and partly because storage decisions were made before anyone anticipated the sovereignty constraints on where those logs can sit. Settle retention duration and location before building the automated layer, because a triage system reasoning over thirty days of logs cannot detect the intrusion that started in March.

The objection worth taking seriously

The strongest objection is that automated triage optimises the metric that never mattered. Alert volume was always an artefact of poorly tuned detection, and the correct response was to fix the detections rather than to industrialise the processing of noise. By making a high-volume, low-quality alert stream cheap to handle, automation removes the pressure that would otherwise force teams to tune their rules, and the result is a permanently louder environment where the true positive is harder to find rather than easier. You have automated the symptom and entrenched the disease. That is a genuinely strong argument and the incentive effect it describes is observable. The counter is partly a concession: tuning should continue and automation makes it easier to neglect, so the discipline has to be imposed deliberately through a periodic review of which detection rules generate the auto-closed volume. But the objection assumes a false ceiling on how much can be tuned away. A meaningful share of alert volume comes from activity that is genuinely ambiguous without context — not bad rules, just insufficient information at the point of firing — and no amount of tuning resolves those without the enrichment step that automation provides. The right position is both: automate enrichment and classification, and use the resulting data on auto-closed volume as the tuning backlog you never previously had visibility into. Automation without that feedback loop does exactly what the objection predicts.

Common Questions

What auto-closure rate is reasonable?

There is no defensible universal figure. What matters is whether you are sampling the closed population and finding acceptable error rates, which is a question you can answer and a benchmark is not.

Does this reduce headcount?

It generally reduces the junior tier and increases the need for senior investigators. In most regional organisations the net cost is flat and the coverage improves.

How do we validate the triage layer?

Continuous random sampling plus deliberate injection of known-bad scenarios. Both are needed; sampling alone will not surface the novel-case weakness.

What should we expect over the next twelve months?

Expect platform vendors to make automated triage a default rather than an option. Expect the first public discussion of a breach that an automated layer closed. Expect regional providers to market this heavily without exposing closure rates. And expect the analyst pipeline problem to become visible about two years after it was created.


SOC Modernization Review — we design the confidence routing and the sampling regime first, because those are what keep the automation honest.

Continue reading

Talk to OPS

Start with the operating problem.