01

Manual investigation does not scale

Modern organisations generate signals across identities, endpoints, email, cloud, SaaS, networks, vulnerability platforms and third-party services. Analysts must correlate them quickly, meet strict SLAs and communicate meaningful outcomes.

When the same evidence searches, enrichment, timelines, ticket updates and documentation are performed manually, investigations become inconsistent and too dependent on a small number of senior analysts.

02

Use case: contextual identity investigation

An unusual sign-in can indicate compromise, but it can also reflect legitimate travel, a known device or an established token pattern. A mature workflow collects sign-in history, authentication, Conditional Access, device, IP, application and post-authentication activity before recommending disruptive action.

The purpose of AI is not to make a dramatic decision faster. It is to make a better-informed decision faster.

03

Use case: a trusted sender can still be compromised

A legitimate domain, valid authentication and previous communication do not prove an email is safe. The SOC should correlate message infrastructure, URLs, clicks, sign-ins, inbox rules, OAuth activity, endpoints and related messages into one investigation timeline.

Automated investigation should assemble the attack story; the analyst should validate the conclusion and approve high-impact remediation.

04

Use case: monitor the automation itself

A Sentinel incident may exist while a downstream case never reaches the responsible team because credentials expired, a workflow failed or a platform was unavailable. Resilient designs need state tracking, correlation identifiers, idempotency, retries, health monitoring, recovery queues and explicit escalation.

Automation that cannot report its own failure becomes operational risk.

05

Use case: handle planned activity with context

Penetration tests, migrations and maintenance can create security noise. The right response is not blind closure or disabling detections. Record the approved window, sources, accounts, tools, scope and owners, then apply time-limited classification and investigation logic while keeping genuinely suspicious activity visible.

06

The modern operating model

  • Analysts provide context, validation, accountability and high-impact decisions.
  • Automation handles predictable enrichment, case creation, notifications and SLA monitoring.
  • Specialised AI agents perform adaptive investigation, evidence correlation and structured recommendations.
  • Human approval remains mandatory where an action could materially affect people, production systems or business operations.

07

A seven-phase SOC transformation blueprint

  • Standardise playbooks, evidence, closure reasons, escalation and approvals.
  • Integrate SIEM, XDR, identity, email, endpoint, intelligence and case management.
  • Automate repetitive collection, enrichment, ticketing and monitoring.
  • Improve detection quality, correlation and coverage.
  • Introduce explainable AI-assisted investigations.
  • Enable controlled remediation with proportionate approvals.
  • Measure security and business outcomes, not deployment activity.

08

What a modern SOC should deliver

A modern SOC should produce consistent investigations, faster evidence collection, better risk assessments, governed remediation, reliable integrations, measurable SLA performance and continuous detection improvement.

Organisations do not necessarily need more tools. They need their existing tools, data, processes and people to work together more intelligently.

References

Primary sources