Why AI is forcing enterprises to rebuild the security operations centre
The security operations centre (SOC) is entering a fundamental transition as artificial intelligence changes both the scale of cyber threats and the way enterprises defend against them. As attackers increasingly use AI to accelerate reconnaissance, identify vulnerabilities and execute attacks, traditional SOC models built around static use cases, predefined playbooks and human-led investigation are coming under pressure.
The response, however, is not to remove humans from the security equation. Instead, organisations are beginning to look at AI as an embedded layer across detection, investigation, decision-making and response, while retaining human oversight for critical actions.
In an exclusive interaction with Express Computer, Vaibhav Dutta, Vice President and Global Head – Cybersecurity Products & Services, Tata Communications, discusses how enterprises need to re-engineer their SOCs for the AI-driven threat landscape, the changing role of security analysts, the convergence of network, cloud and security operations, and the emerging risks around agentic AI.
The traditional SOC is becoming too static
Dutta describes the traditional SOC as a model built around collecting telemetry, feeding it into security analytics platforms, defining use cases, triaging alerts and then using predefined SOAR playbooks to respond. Threat intelligence is typically used to enrich the process.
However, the threat landscape is evolving too quickly for static rules and playbooks to remain sufficient.
“The landscape is not evolving; it is transforming very, very quickly,” says Dutta. “The number of threats which will be received today will get 100-fold higher by leveraging AI. We have already seen the impact of AI and what it is able to discover on zero-day exploits.”
This makes it increasingly difficult for SOC teams to rely on predefined detection and response mechanisms. “We cannot be static; we cannot rely on static use cases. We cannot rely on static playbooks. To fight these AI-generated threats, you need to have the power of AI.”
For Dutta, AI therefore needs to become part of the SOC’s operating model rather than being added as another security tool.
He sees AI playing a role across the SOC, from machine learning-based threat detection and triage to dynamically defining use cases and supporting response through agentic capabilities. Instead of relying entirely on static playbooks, agents can dynamically update response processes and support analysts in making decisions.
The future SOC will be autonomous but human-led
Despite the growing autonomy of security operations, Dutta does not see human analysts disappearing from the SOC. “Definitely, the human analyst will be there, and they will continue to be there. You always want to have a human in the loop,” he asserts.
He says human oversight remains important from both governance and risk-management perspectives. AI can inform decisions, perform triage and support response, but critical actions still require human judgement.
Over time, decisions made by analysts can also become learning inputs for AI systems. If a human makes a particular decision in a given situation and validates it, that decision can help train models and agents for similar circumstances.
This creates a model in which AI increasingly handles operational activity while humans remain responsible for critical decision-making.
Detection will mature before autonomous response
As attackers use AI to automate parts of their operations, Dutta believes enterprises need to become more proactive. However, he does not see anticipation and response as alternatives. “Both are important. Anticipating and being more predictive is also important. But we are living in a situation where you cannot anticipate or predict every outcome.”
AI and machine learning can help enterprises become more proactive, but there will always be attacks and scenarios that organisations cannot predict.
“All said and done, you can achieve a proactiveness of maybe 90%, but still those 10% of the cases need to be where you are defending and reacting.”
Dutta expects AI-based detection to mature first because it represents a lower-risk entry point. Prevention and response require systems to take action, which means those capabilities need to be trained, tested and validated more extensively.
“In detection, at most you will have a false positive or a false negative. You might miss something, or you might alert to something which is not a true positive. Detection, I believe, is the first step, and then comes prevention and response capabilities from a maturity curve.”
Security analysts will move towards threat hunting
As AI takes over repetitive detection, correlation and response activities, Dutta expects the role of the security analyst to move higher up the value chain.
“I feel the analyst role will now start evolving towards threat hunting rather than relying on the detection capabilities, because some of them will be offloaded to AI.”
Analysts will increasingly be responsible for developing hypotheses, assessing whether an environment is susceptible to emerging attack vectors, and drawing lessons from previous simulation exercises.
Human decision-making will remain particularly important at critical stages. “You can’t mimic a human brain. The decision-making process at some vital stages, clear communication as well as escalation, is something which analysts will have to do.”
Dutta also sees AI helping address the industry’s persistent cybersecurity skills shortage. While AI cannot eliminate the gap entirely, it can take over certain tasks and allow security professionals to focus on higher-value investigations.
Network, cloud and security are converging
The changing SOC is also coinciding with the convergence of network, cloud and security operations.
Dutta says the separation between these functions has already started to disappear as enterprises have moved towards cloud-centric environments.
Tata Communications’ position across network, cloud and cybersecurity provides visibility across these layers. With the company routing a significant share of internet traffic, Dutta says network-level intelligence can provide early indicators of attacks and compromises, which can then feed into security operations.
The cloud also becomes important after an attack has occurred, particularly around resilience and recovery. “Most of the time, we only focus on an environment where we need to mitigate the attack. We need to respond to the attack. But in case an attack happens, we need to recover fast as well. The environment has to be resilient.”
This convergence is also changing the role of managed service providers. Dutta expects traditionally separate network, cloud, infrastructure and security operations to increasingly come together under a common automated operating model. “I see managed services operations getting under a single umbrella with a lot of agentic and automation capabilities built on top of it.”
Agentic AI creates a new security problem
While AI can strengthen defence, Dutta warns that agentic AI introduces a fundamentally different risk because agents can access data, interact with systems and make changes on behalf of users.
“The challenges organisations are facing today are, how are you controlling the access to the agents? First of all, how are you limiting what an agent can do and what an agent cannot do?”
This makes agent identity, permissions and governance critical.
Organisations need to establish what an agent is authorised to access, what actions it can perform and how those actions are monitored. Dutta believes conventional guardrails alone will not be sufficient.
“We are talking not just about guardrails; we are not talking about agent gateways. We are talking about end-to-end agentic threat detection and response,” he states.
As a result, organisations that have already begun their AI journeys may need to introduce additional governance and security controls specifically for agents. “Agentic security will become a next chapter of growth for any service provider or any security service provider.”
AI risk management needs to become part of the governance charter
Looking ahead, Dutta identifies two priorities for enterprises moving towards AI-native operations.
The first is to evolve the SOC itself by embedding more AI and agentic capabilities into security operations. The second is to establish AI risk management as a formal part of enterprise governance.
“One is how they evolve their security operations centres and introduce more and more capabilities, embed agents for more and more capabilities and enhance their security operations.”
The second, he says, is equally important.
“How do they introduce AI risk management as a part of their new governance charter? This will become very, very key because we are using AI to fight the threats generated by AI, but there has to be some governance around that AI which you have been using.”
For enterprises, therefore, the cybersecurity roadmap is about redesigning the SOC, redefining human roles and establishing governance around increasingly autonomous systems and not just deploying AI against AI-generated threats.