Express Computer
Home  »  Security  »  How AI is forcing SOC to move beyond tools towards context-driven defence

How AI is forcing SOC to move beyond tools towards context-driven defence

0 2

The security operations centre is entering a period of fundamental change. For years, organisations have responded to increasingly sophisticated threats by adding another layer of security technology like endpoint, network, email, cloud, identity, XDR, SIEM and managed detection and response. But as artificial intelligence accelerates both the volume and sophistication of attacks, the question is no longer whether enterprises have enough security tools. It is whether those tools can work together quickly enough to provide meaningful context and enable effective response.

For Jason Clark, Senior Vice President, Global Sales Engineering, Sophos, the answer lies in moving away from fragmented security operations towards an integrated model in which data, context and AI work across security control points.

“The answer is not really adding any more tools. It is adding more technology that is integrated and baked into the tools and systems that you already own that share a context layer between all of those control points or systems or even platforms in your environment today,” says Clark.

Tool proliferation is creating SOC fatigue

The pressure on security teams is already becoming visible. Clark says that, based on Sophos’ experience, its investigation caseload has increased significantly since the broader adoption of AI.

“It’s becoming overwhelming for many CISOs and many SOC teams. Just a quick example: based on our experience over the last six months since the broad adoption of AI, our caseload has increased roughly 40%. And we handle roughly 400,000 investigation cases a year,” he says.

The challenge is not simply the number of attacks. Security teams are also dealing with increasingly complex technology environments. Clark points to an average of around 18 tools per SOC, with different technologies often managed by separate teams.

“The tools don’t talk to each other,” he says. “So this spreads context across all of those teams. They’re working off the same shared workbench, if you will, the same data. So they have the same source beginning, middle and ending of an attack lifecycle.”

For Clark, this shared context is becoming more important than adding another individual security capability. An integrated defence model can allow analysts to see an incident across multiple control points rather than investigating isolated alerts.

AI needs to augment the SOC, not simply automate it

The emergence of autonomous security response raises another question: how far should enterprises allow AI to act without human intervention?

Clark believes there is a clear distinction between low-risk activities that can increasingly be automated and incidents where the consequences of a wrong decision could disrupt business operations.

“Our philosophy is always human in the loop at some point,” he points out. “We will let low to medium cases run autonomously, but it is still accountable to the human to manage those agents and manage the end-to-end process.”

He also points to guardrails around AI systems, including restricting internet access where it is not required.

“The majority of the low-end cases will be fully autonomous at some point, I think, across the industry. The ones that could potentially damage and stop business operations and slow a business down will be semi-autonomous. So an analyst will come in and make that final decision.”

For Clark, an incident being described as “resolved” should mean considerably more than detecting and closing an alert. It should involve investigation, understanding the nature and attribution of the threat, identifying the tactics and techniques used, determining the root cause and using the findings to strengthen defences.

More telemetry does not necessarily mean more visibility

Security teams today have access to enormous volumes of telemetry from endpoints, identities, applications and networks. But more data can also create another problem: analysts may struggle to determine what actually matters.

Clark argues that the answer is not reducing visibility but using AI to process that information before it reaches the analyst.

“We can still ingest all that data, but that gets filtered at an AI layer. Before it actually hits the analyst, it’s analysed, it’s run through the contextual models,” he says.

The objective is to allow analysts to receive the information that is most relevant to the decision they need to make, rather than manually working through every signal.

This becomes particularly important as organisations confront a widening gap between the scale of attacks and the available security workforce.

“The value comes from correlating those different signals. So you’re saving money not just in technology, but also in the cost of people’s time and headcount, because we’re in a situation where you can’t hire your way out of this alert fatigue,” Clark adds.

The boundaries between XDR, SIEM and MDR are beginning to blur

Clark also expects the traditional boundaries between security operations technologies to increasingly disappear.

“I do feel that it’s going to have to consolidate,” he says, pointing to the convergence of XDR and SIEM, with MDR also potentially becoming part of the same operating model.

For security analysts, he believes the underlying technologies should increasingly become invisible. “I don’t need 18 tools. I need the outcome.”

The implication is that security teams should not have to think in terms of individual products or acronyms. Instead, security data, detection, investigation, response and compliance should increasingly work together through a common operating layer.

Shadow AI makes visibility the starting point

The rapid adoption of AI is also creating a new security challenge. Employees may be using AI applications and personal accounts even when organisations have not formally approved them, while AI capabilities are increasingly being embedded into existing SaaS applications.

Clark believes organisations therefore need to start with visibility rather than simply attempting to block AI.

From there, enterprises need to establish governance and controls around what AI systems can access and what they are permitted to do.

“Visibility, control and governance are the main components that you’ll need to start with,” he asserts.

The threat landscape is also expanding across three fronts: attackers using AI, attacks against AI systems and vulnerabilities introduced through the AI supply chain. Prompt injection is one example, where an AI system may interpret malicious instructions as legitimate requests.

AI-native means rebuilding around context

Clark is also cautious about the growing use of the term “AI-native” across the cybersecurity industry.

“I don’t think I’ve seen a vendor not use the term ‘AI-native’ these days,” he says. The challenge for customers, he argues, is distinguishing genuinely AI-native architectures from existing security platforms with AI capabilities simply added on top.

For him, the distinction comes down to how deeply AI is integrated into the security architecture and its control points.

“When we talk about native, AI is built to move fast,” he says. “AI is actually ingrained in every single control point that we use.”

He argues that simply acquiring an AI company and bolting its technology onto a legacy platform does not necessarily create an AI-native security architecture. Instead, organisations need to rethink how security systems are built around shared context.

Preparing for the autonomous attack

Looking ahead, Clark believes security leaders need to prepare for a more consequential shift: attacks that can themselves become autonomous.

“Every security leader should be prepared and start preparing themselves and even their executive team for the next attack that they see or even a major breach to be AI-powered. It may be fully autonomous,” he says.

That preparation, he argues, should go beyond conventional security testing. Organisations need to simulate scenarios in which an AI-powered attack operates at the speed and scale that autonomous systems can potentially achieve.

For the SOC, therefore, the next phase of AI adoption is not simply about replacing analysts or adding another layer of automation. It is about creating a security operation in which telemetry is connected, context is shared, routine response can be automated, and human judgement remains accountable where the consequences are highest.

As AI compresses the time available to detect and respond to threats, the competitive advantage for security teams may increasingly come not from how many tools they deploy, but from how effectively those tools can understand the same attack, share context and act as one system.

Leave A Reply

Your email address will not be published.