Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick
Study & Research Future, Trends and Insight Latest News News & Analysis Security Threat Intelligence Threats and Vulnerabilities

Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick

Kirsten DoyleBy Kirsten DoyleSeptember 14, 20268 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Prophet Security AI cutting SOC investigation
Share
Facebook Twitter LinkedIn Email Copy Link
TL;DR (AI Generated)

Security teams are turning to AI as they struggle to investigate the volume of alerts coming into the SOC, according to new research from Prophet Security.

Sixty percent of respondents said an alert they had ignored or never investigated had later proved material, putting customer data, system availability, or business operations at risk.

Respondents included security operations, incident response, threat detection, and broader security roles.

Basic summary
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Security teams are turning to AI as they struggle to investigate the volume of alerts coming into the SOC, according to new research from Prophet Security.

The State of AI in Security Operations 2026 report surveyed 250 IT and cybersecurity professionals. Forty percent said AI is already part of their day-to-day SOC workflow, and 56% are evaluating or piloting it. Only 4% have no current plans to use AI. 

Among teams already using AI, 72% said it had cut alert investigation time by at least 25%. For 18%, the reduction was more than half. 

However, the research also found that building AI for the SOC in-house has had mixed results. Most AI users have tried it, but nearly half of those projects have since been abandoned, replaced, or failed to reach production.

SOCs are leaving alerts untouched

The median organization receives around 100 alerts a day. At the larger end of the survey, volumes pushed the average close to 1,000. Overall, 74% of organizations receive at least 50 alerts a day, and 27% receive 500 or more. 

A thorough investigation takes around 75 minutes on average, although the median is closer to 45 minutes. Nearly two-thirds of respondents said their mean time to investigate was at least 30 minutes.

Then there is the wait before an investigation starts. Alert dwell time averaged 55 minutes, with a median of around 23 minutes. From the moment an alert fires to the end of the investigation, the average alert is waiting or being worked for more than two hours. 

Alert volume and noise was the most common SOC challenge, selected by 43% of respondents. Slow triage and investigation followed at 41%, and keeping up with new threats at 39%. Analyst burnout or turnover was an issue for 35%, and 34% reported gaps in 24/7 coverage. 

Some alerts never make it to an analyst. On average, organizations estimated that 28% of their alerts go uninvestigated, with a median of 22%. More than a third, 39%, leave at least 30% untouched. 

That does not mean those alerts were harmless. Sixty percent of respondents said an alert they had ignored or never investigated had later proved material, putting customer data, system availability, or business operations at risk. For 34%, that had happened three or more times in the previous year.

The problem was more pronounced in bigger organizations. Among those with at least 5,000 employees, 46% had experienced three or more such incidents, compared with 13% of the smallest organizations surveyed. 

Fourteen percent also admitted turning off a detection rule because they did not have the resources to investigate the alerts it produced. Another 26% said it was possible they had done so. 

AI is moving up the security agenda

The workload inside the SOC is increasing as security teams contend with AI on the attacker side too. Fifty-six percent of respondents said they had seen an increase in AI-driven attacks over the past 12 months. 

Of those who had encountered AI-powered attacks, 64% had seen phishing or social engineering with signs of LLM-generated content. Fourteen percent reported deepfake voice or video used for business email compromise or fraud, while 11% had seen account takeover or credential abuse at an unusual scale or level of sophistication.

Ten percent had encountered malware that appeared to be AI-generated, and 4% reported reconnaissance at an unusual scale. 

Those pressures have put AI near the top of security leaders’ priorities from two directions. Securing AI systems and models was a top-three priority for 56% of respondents, while 53% named using AI to improve security operations. Data security followed at 47%, and cloud security at 45%. 

For organizations considering an AI SOC, the main reasons are faster response and better coverage. Seventy-three percent want to lower mean time to respond, 71% want to improve detection coverage, and 56% want to handle more with the team they already have. Reducing analyst burnout and turnover was cited by 37%. Replacing an MSSP or MDR came much further down the list at 20%.

Investigation times are coming down

Among current AI users, 54% said average investigation times had fallen by between 25% and 50%. For another 18%, they had fallen by more than half. Twenty-one percent reported a reduction of less than 25%, while 7% saw no meaningful change.

Across those respondents, the average reduction was roughly one-third. With an investigation taking about 75 minutes on average, that equates to around 25 minutes saved per alert.

Teams are measuring the impact in other ways, too. Sixty-one percent use mean time to respond, 52% look at 24/7 coverage across all severities, and 46% track the number of false positives reaching human reviewers. Mean time to investigate is used by 41%.

In-house AI builds have had mixed results

Building rather than buying has been a common route into AI for security operations.

Among organizations already using AI, 72% have attempted to build internal AI or LLM-based tooling for SOC workflows. But teams that went down this route did not report a meaningful speed advantage over AI users as a whole.

Seventy-three percent of organizations that attempted an internal build reported investigation-time reductions of at least 25%. Across all AI users, the figure was 72%. 

Many of the projects did not last. Of the organizations that attempted an internal build, 46% have since deprecated it, replaced it with a commercial product, or failed to get it into production. Fifty-four percent are still using what they built.

Across the entire group of AI users, one-third have a failed or abandoned internal build behind them. 

Humans are still checking AI’s work

Organizations are also putting limits on how much responsibility they hand over to AI.

Thirty percent of AI users said their tool reaches the same verdict as an experienced analyst at least 90% of the time. Forty-four percent put agreement between 70% and 89%, and 22% between 50% and 69%. Four percent do not measure agreement. 

Human review remains part of the process for most teams, with over half (57%) saying they check every AI verdict before an alert is closed.

Forty percent also have a senior analyst spot-check a sample of verdicts, while 32% test AI decisions against labeled benchmarks or red-team exercises. Nineteen percent use vendor-reported accuracy figures, and 5% have no formal validation process.

The same caution applies to automated action. Forty-four percent allow AI to recommend an action for a human to carry out, while 30% allow it to execute low-risk actions automatically. Thirteen percent extend that to medium-risk actions, and another 13% restrict AI to read-only triage.

None of the respondents said they give AI full, unsupervised autonomy. 

Privacy and transparency are holding some teams back

Regulatory concerns around data privacy and LLM training are the most commonly cited barrier to adopting or expanding AI in the SOC, at 44%. 

Explainability and transparency are another concern, cited by 41%. Cost followed at 36%, with integration into existing tools and workflows at 35%. 

Around a third also have concerns about accuracy and the effect on their teams. Thirty-two percent worry that AI will not match human-led investigations, while the same percentage are concerned that analysts could lose skills over time. 30% reported resistance within the team or concerns about AI replacing people. Just 2% reported no significant concerns.

Time saved in triage could go into threat hunting

Almost half of respondents already hunt for threats at least weekly. Twenty-six percent have a continuous, dedicated hunting function, and 23% conduct hunts every week. Another 28% hunt monthly, 17% less often, and 5% never do. 

There is evidence that those hunts are finding things existing detection tools miss. Thirty-eight percent of respondents said a proactive threat hunt had uncovered malicious activity that their detection tools had failed to catch. A third said it had not, and 25% were unsure. 

Frequency made a considerable difference. Among teams that never conduct threat hunts, 8% had uncovered activity missed by their detection tools. That rose to 38% among monthly hunters and 49% among teams hunting weekly or more. 

For most respondents, the expected result of bringing more AI into the SOC is not a smaller security team.

Fifty-seven percent expect SOC roles to change without any reduction in headcount over the next two years. Nine percent expect headcount to increase, while 27% anticipate either a modest or significant reduction. 

The likely shift is away from some of the triage and investigation work that currently consumes analysts’ time. Threat hunting, incident response, detection engineering, and adversary simulation are among the areas where that time could go instead.

Methodology

The research was conducted by third-party research firm ViB and covered 250 IT and cybersecurity professionals. Respondents included security operations, incident response, threat detection, and broader security roles. The sample was weighted toward North America, which accounted for 86% of respondents, with 12% in EMEA and 2% in Asia-Pacific. Prophet notes that the findings are self-reported and should be read in the context of the survey demographics.

Prophet notes that the findings are self-reported and should be read in the context of the survey demographics.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    A reverse image search platform exposed more than 9 million facial images
  • Kirsten Doyle
    Post-DEF CON phishing campaign delivered AMOS and NetSupport malware
  • Kirsten Doyle
    AI agents taking unsanctioned action during cyber testing
  • Kirsten Doyle
    Expert panel: AI is writing the code. Who is defending it?

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Verizon DBIR 2026: What the experts are saying 

May 21, 202614 Mins Read

Online Safety Act failing to deliver “step change” for children, report warns

May 11, 20264 Mins Read

The quiet revolt: what the world happiness report 2026 tells security professionals

April 7, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}