SOCs are facing a human challenge as AI accelerates alerts and threats

“People who work in SOCs are now seeing a lot of data, and they’re getting tired,” Griffiths tells CSO.
AI can help automate parts of analysis, validate alerts, and improve visibility into complex environments. But Griffiths warns that some AI-assisted vulnerability detection tools also generate large numbers of false positives.
That’s important because lies don’t get the job done. They create it. As organizations face an increasing number of consequences, distinguishing real risk from false consequences may be as important as detecting risk in the first place.
Experts agree that technology alone will not determine results. People will do it.
Crowley says cybersecurity professionals need to recognize that uncertainty is part of the job. “We’re a team that deals with uncertainty,” he says. “That’s really and truly what cybersecurity is all about.”
That fact places a burden on both individuals and organizations. Analysts need ways to manage stress. Teams need to recognize when their teammates are reaching their limits. Managers need to establish healthy escalation processes and realistic expectations.
Hubbard rejects the idea that burnout is inevitable.
He says: “It is not a foregone conclusion that security operations should be a misery that everyone hates.
He’s seen organizations where employees stay for years because leaders actively manage workloads, create supportive cultures, and encourage open communication.
That includes making it safe for analysts to agree when they’ve reached their limits. “If people aren’t willing to say, ‘I’m exhausted right now, and I’m going crazy,’ it’s going to break a lot of teams,” Hubbard said.
Paying alone may not solve the problem. Crowley pointed to findings from a SANS/SOC survey showing that compensation ranked fourth among the last factors, behind meaningful work, training, and professional development.
The SOC of the future may look very different
Griffiths believes that organizations will need to respond not only with better technology but with structural changes. SOC models with cultural hierarchies may need to evolve to collaborative teams with different technologies working together in real time.
“I think we will have to remove the hierarchy a little bit and have groups of people with different experiences working together,” he said.
He also says that organizations should invest in people’s knowledge rather than simply expanding the use of AI. “Buy developers, not tokens,” he says.
Professional networks and peer support will be as important as any tool, says Griffiths, because defenders need trusted communities where they can compare notes, share practices, and avoid dealing with constant stress alone.
If there’s a consensus among experts, it’s that AI is exposing pre-existing weaknesses.
The workforce shortages, awareness fatigue, burnout, and process failures affecting SOCs didn’t start with manufacturing AI. AI simply magnifies them.
At the same time, AI is providing new tools that can help organizations manage those challenges themselves.
The SOC of the future may spend less time manually evaluating alerts and more time validating automated findings, conducting threat hunts, and making strategic decisions. Human expertise may increasingly be combined with AI systems that act as active partners.
The transition will not be painful. Other teams will struggle. Some doctors may leave the field. Others will adapt and thrive.
“In a way,” says Griffiths, “we’re bringing the entire SOC inside out.”
Montenegro sees the revolution as a cybersecurity version of the Red Queen effect: defenders and attackers must keep running to stay in place.
Borrowing from science fiction writer William Gibson, Montenegro offered perhaps the simplest description of the industry’s present: “The future is already here. It’s unevenly distributed.”
For security leaders, that future comes in the form of AI-generated vulnerabilities, AI-assisted investigations, and AI-enabled adversaries. The question is no longer whether security operations centers will change. It is whether organizations can adapt quickly enough to keep pace.



