HomeMalware & ThreatsProphet Security Research Reveals AI Reduces SOC Investigation Times, Yet Nearly Half...

Prophet Security Research Reveals AI Reduces SOC Investigation Times, Yet Nearly Half of In-House Builds Do Not Succeed

Published on

spot_img

Security operations centers (SOCs) are increasingly leveraging artificial intelligence (AI) to help manage the overwhelming volume of alerts competing for the attention of cybersecurity teams. Recent research conducted by Prophet Security revealed compelling insights into how AI is transforming the landscape of security operations, particularly in its ability to streamline investigative workflows.

The report, titled “State of AI in Security Operations 2026,” involved a survey of 250 IT and cybersecurity professionals. Among the key findings, it was revealed that 40% of these professionals have already integrated AI into their daily SOC workflows. In addition, 56% are either assessing or piloting AI-related initiatives, with a mere 4% indicating that they have no plans to adopt AI technologies at all.

The efficacy of AI in alert management is underscored by the experience of those currently utilizing it. Specifically, 72% of AI users reported that the technology has enabled them to reduce alert investigation times by at least 25%. A notable 18% even experienced a reduction exceeding 50%. These statistics serve as a testament to AI’s role in alleviating the pressure on cybersecurity personnel who often find themselves inundated with alerts.

Despite these advancements, the report highlights a significant challenge faced by organizations: many alerts remain uninvestigated. On average, an organization receives 100 alerts daily, with larger entities receiving nearly 1,000 alerts. Alarmingly, the research indicates that an estimated 28% of alerts go completely unexamined, with a median of 22% left untouched. More than a third of the respondents confessed that at least 30% of their alerts were ignored.

Worryingly, many of these neglected alerts are not benign. In fact, 60% of respondents disclosed that an alert they had overlooked or not examined later turned out to be critical, jeopardizing customer data, system availability, or overall business operations. This negligence seems to disproportionately affect larger organizations; 46% of those with at least 5,000 employees reported experiencing three or more significant incidents due to ignored alerts, compared to only 13% of smaller organizations.

The report also sheds light on the demand for AI in cybersecurity, spurred on by the increasing sophistication of attacker methods. Over half of the survey participants (56%) reported a rise in AI-driven attacks over the last year. These attacks primarily take the form of phishing schemes, often involving content generated by large language models (LLMs). Additionally, 14% encountered deepfake technologies used in business email compromise, while others reported more sophisticated account takeovers or AI-generated malware.

As the challenges mount, the priorities for security leaders reflect a dual focus: securing AI systems themselves while simultaneously utilizing AI to enhance overall security operations. A notable 56% of respondents deem securing AI systems a top priority, closely followed by 53% who prioritize employing AI to optimize security workflows.

Organizations contemplating the implementation of AI SOC tools cite faster response times and improved detection capabilities as primary motivations. Approximately 73% aim to lower the mean time to respond, while 71% are interested in broadening detection coverage and reducing analyst burnout—a concern for 37% of the respondents.

The report indicates that organizations currently employing AI have seen average investigation times decrease, with 54% noting reductions ranging between 25% and 50%. This translates to approximately 25 minutes saved per alert, enhancing efficiency in the SOC environment. Various organizations track their success metrics differently, with 61% focusing on mean time to respond and 41% examining mean time to investigate.

Interestingly, while many organizations have explored building AI solutions in-house, results have been mixed. Among those who attempted to create internal tools, 46% reported abandoning, replacing, or failing to deploy those projects. Surprisingly, the speed improvements achieved through internal builds did not significantly surpass those reported by external AI solutions.

Despite these advancements, human oversight remains integral to the process of AI decision-making. More than half of the organizations (57%) indicated that they review every AI-generated verdict before an alert is considered closed. A cautious approach is evident: although 30% of respondents allow AI to execute low-risk actions autonomously, none reported allowing AI to operate with full, unsupervised authority.

Concerns regarding privacy, transparency, and regulatory aspects also feature prominently in the discourse around AI adoption. Regulatory hurdles related to data privacy emerged as a prevalent concern, cited by 44% of respondents. Explainability—the capacity to understand AI’s decision-making processes—was also flagged by 41% as a barrier to broader AI adoption in SOCs.

Looking to the future, the anticipated impact of AI deployment in security operations is not necessarily a reduction in workforce. A significant 57% of respondents believe that the cybersecurity landscape will change but maintain existing headcount levels over the next two years. This shift is expected to redirect analyst focus from routine triaging and investigations towards more strategic domains such as threat hunting and incident response.

In summary, the ongoing integration of AI into SOC operations presents both significant benefits and considerable challenges. While AI has already shown promise in enhancing response times and operational efficiency, the risks of neglected alerts and the need for human oversight continue to underscore the need for balance in leveraging this technology. The evolving landscape of cybersecurity will likely see increased reliance on AI as teams aim to outpace both the volume of threats and the sophistication of cybercriminal tactics.

Source link

Latest articles

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

Exploitation of Sogou Input Method: UNC3569 Unleashes GRAYRABBIT Backdoor Recent security assessments have unveiled that...

Defense Cyber Spending Expected to Increase Due to Growing Military Cyber Attacks

Surge in Cybersecurity Spending Anticipated in Defense Sector Amid Rising Cyber Threats Cybersecurity expenditure within...

CPython Makes Rust Optional Instead of Mandatory

The ongoing evolution of the CPython development team has seen a significant shift in...

Sandworm-Linked Cyclops Blink Reemerges with Network Scanning and Packet-Sniffing Features

Emerging Threat: New Cyclops Blink Variant Targets Cisco Secure Firewall Management Center A recent development...

More like this

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

Exploitation of Sogou Input Method: UNC3569 Unleashes GRAYRABBIT Backdoor Recent security assessments have unveiled that...

Defense Cyber Spending Expected to Increase Due to Growing Military Cyber Attacks

Surge in Cybersecurity Spending Anticipated in Defense Sector Amid Rising Cyber Threats Cybersecurity expenditure within...

CPython Makes Rust Optional Instead of Mandatory

The ongoing evolution of the CPython development team has seen a significant shift in...