Security teams are turning to AI as they struggle to investigate the volume of alerts coming into the SOC, according to new research from Prophet Security.
The State of AI in Security Operations 2026 report surveyed 250 IT and cybersecurity professionals. Forty percent said AI is already part of their day-to-day SOC workflow, and 56% are evaluating or piloting it. Only 4% have no current plans to use AI.
Among teams already using AI, 72% said it had cut alert investigation time by at least 25%. For 18%, the reduction was more than half.
However, the research also found that building AI for the SOC in-house has had mixed results. Most AI users have tried it, but nearly half of those projects have since been abandoned, replaced, or failed to reach production.
SOCs are leaving alerts untouched
The median organization receives around 100 alerts a day. At the larger end of the survey, volumes pushed the average close to 1,000. Overall, 74% of organizations receive at least 50 alerts a day, and 27% receive 500 or more.
A thorough investigation takes around 75 minutes on average, although the median is closer to 45 minutes. Nearly two-thirds of respondents said their mean time to investigate was at least 30 minutes.
Then there is the wait before an investigation starts. Alert dwell time averaged 55 minutes, with a median of around 23 minutes. From the moment an alert fires to the end of the investigation, the average alert is waiting or being worked for more than two hours.
Alert volume and noise was the most common SOC challenge, selected by 43% of respondents. Slow triage and investigation followed at 41%, and keeping up with new threats at 39%. Analyst burnout or turnover was an issue for 35%, and 34% reported gaps in 24/7 coverage.
Some alerts never make it to an analyst. On average, organizations estimated that 28% of their alerts go uninvestigated, with a median of 22%. More than a third, 39%, leave at least 30% untouched.
That does not mean those alerts were harmless. Sixty percent of respondents said an alert they had ignored or never investigated had later proved material, putting customer data, system availability, or business operations at risk. For 34%, that had happened three or more times in the previous year.
The problem was more pronounced in bigger organizations. Among those with at least 5,000 employees, 46% had experienced three or more such incidents, compared with 13% of the smallest organizations surveyed.
Fourteen percent also admitted turning off a detection rule because they did not have the resources to investigate the alerts it produced. Another 26% said it was possible they had done so.
AI is moving up the security agenda
The workload inside the SOC is increasing as security teams contend with AI on the attacker side too. Fifty-six percent of respondents said they had seen an increase in AI-driven attacks over the past 12 months.
Of those who had encountered AI-powered attacks, 64% had seen phishing or social engineering with signs of LLM-generated content. Fourteen percent reported deepfake voice or video used for business email compromise or fraud, while 11% had seen account takeover or credential abuse at an unusual scale or level of sophistication.
Ten percent had encountered malware that appeared to be AI-generated, and 4% reported reconnaissance at an unusual scale.
Those pressures have put AI near the top of security leaders’ priorities from two directions. Securing AI systems and models was a top-three priority for 56% of respondents, while 53% named using AI to improve security operations. Data security followed at 47%, and cloud security at 45%.
For organizations considering an AI SOC, the main reasons are faster response and better coverage. Seventy-three percent want to lower mean time to respond, 71% want to improve detection coverage, and 56% want to handle more with the team they already have. Reducing analyst burnout and turnover was cited by 37%. Replacing an MSSP or MDR came much further down the list at 20%.
Investigation times are coming down
Among current AI users, 54% said average investigation times had fallen by between 25% and 50%. For another 18%, they had fallen by more than half. Twenty-one percent reported a reduction of less than 25%, while 7% saw no meaningful change.
Across those respondents, the average reduction was roughly one-third. With an investigation taking about 75 minutes on average, that equates to around 25 minutes saved per alert.
Teams are measuring the impact in other ways, too. Sixty-one percent use mean time to respond, 52% look at 24/7 coverage across all severities, and 46% track the number of false positives reaching human reviewers. Mean time to investigate is used by 41%.
In-house AI builds have had mixed results
Building rather than buying has been a common route into AI for security operations.
Among organizations already using AI, 72% have attempted to build internal AI or LLM-based tooling for SOC workflows. But teams that went down this route did not report a meaningful speed advantage over AI users as a whole.
Seventy-three percent of organizations that attempted an internal build reported investigation-time reductions of at least 25%. Across all AI users, the figure was 72%.
Many of the projects did not last. Of the organizations that attempted an internal build, 46% have since deprecated it, replaced it with a commercial product, or failed to get it into production. Fifty-four percent are still using what they built.
Across the entire group of AI users, one-third have a failed or abandoned internal build behind them.
Humans are still checking AI’s work
Organizations are also putting limits on how much responsibility they hand over to AI.
Thirty percent of AI users said their tool reaches the same verdict as an experienced analyst at least 90% of the time. Forty-four percent put agreement between 70% and 89%, and 22% between 50% and 69%. Four percent do not measure agreement.
Human review remains part of the process for most teams, with over half (57%) saying they check every AI verdict before an alert is closed.
Forty percent also have a senior analyst spot-check a sample of verdicts, while 32% test AI decisions against labeled benchmarks or red-team exercises. Nineteen percent use vendor-reported accuracy figures, and 5% have no formal validation process.
The same caution applies to automated action. Forty-four percent allow AI to recommend an action for a human to carry out, while 30% allow it to execute low-risk actions automatically. Thirteen percent extend that to medium-risk actions, and another 13% restrict AI to read-only triage.
None of the respondents said they give AI full, unsupervised autonomy.
Privacy and transparency are holding some teams back
Regulatory concerns around data privacy and LLM training are the most commonly cited barrier to adopting or expanding AI in the SOC, at 44%.
Explainability and transparency are another concern, cited by 41%. Cost followed at 36%, with integration into existing tools and workflows at 35%.
Around a third also have concerns about accuracy and the effect on their teams. Thirty-two percent worry that AI will not match human-led investigations, while the same percentage are concerned that analysts could lose skills over time. 30% reported resistance within the team or concerns about AI replacing people. Just 2% reported no significant concerns.
Time saved in triage could go into threat hunting
Almost half of respondents already hunt for threats at least weekly. Twenty-six percent have a continuous, dedicated hunting function, and 23% conduct hunts every week. Another 28% hunt monthly, 17% less often, and 5% never do.
There is evidence that those hunts are finding things existing detection tools miss. Thirty-eight percent of respondents said a proactive threat hunt had uncovered malicious activity that their detection tools had failed to catch. A third said it had not, and 25% were unsure.
Frequency made a considerable difference. Among teams that never conduct threat hunts, 8% had uncovered activity missed by their detection tools. That rose to 38% among monthly hunters and 49% among teams hunting weekly or more.
For most respondents, the expected result of bringing more AI into the SOC is not a smaller security team.
Fifty-seven percent expect SOC roles to change without any reduction in headcount over the next two years. Nine percent expect headcount to increase, while 27% anticipate either a modest or significant reduction.
The likely shift is away from some of the triage and investigation work that currently consumes analysts’ time. Threat hunting, incident response, detection engineering, and adversary simulation are among the areas where that time could go instead.
Methodology
The research was conducted by third-party research firm ViB and covered 250 IT and cybersecurity professionals. Respondents included security operations, incident response, threat detection, and broader security roles. The sample was weighted toward North America, which accounted for 86% of respondents, with 12% in EMEA and 2% in Asia-Pacific. Prophet notes that the findings are self-reported and should be read in the context of the survey demographics.
Prophet notes that the findings are self-reported and should be read in the context of the survey demographics.
Information Security Buzz News Editor
Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.
The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.


