Been testing an AI SOC workflow for the last quarter. Basic premise:
* AI does initial triage & enrichment on alerts.
* Human analyst reviews the summarized findings and decides.
* Approved actions get pushed to SOAR for automated execution.
Seen a few wins, especially on high-volume/low-risk alerts (e.g., automated phishing scan, known IoC blocks). But I'm skeptical about the middle layer. If the human has to dig into every AI summary anyway, where's the real time-save?
My questions:
* What's the actual analyst-hour ROI you're seeing? Is it just shifting effort, not reducing it?
* Which specific triage tasks is AI reliably handling for you? (URL analysis, log summarization?)
* How are you measuring false positives/negatives introduced by the AI layer?
—CR
Ask me about hidden egress costs.