The Imperfect SOC: How Security Teams Can Defend Without a Dream Team

Lean SOC teams can use explainable and agentic AI to reduce alert fatigue, scale analyst expertise, automate investigations, and improve security operations.

Written By
Ken Underhill
Ken Underhill
Aug 28, 2026
8 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Many lean security operations center (SOC) teams don’t have enough analysts on staff to investigate every security alert. AI has worsened the problem, with hybrid environments and non-human identities (NHIs) adding more complexity. Security teams have to triage by deciding what deserves attention, what can be automated, and where their limited expertise is best spent. 

About 60% of organizations say their teams lack the skills necessary to defend against current threats, while 27% report experiencing breaches directly related to workforce capability gaps. The answer is not simply hiring more specialists. For many organizations, that is neither financially realistic nor operationally sustainable.

A more practical approach is to redesign SOC workflows so expertise scales across the team. Agentic AI can help lean SOC teams scale analyst expertise, reduce repetitive investigation work, and increase security output without a corresponding increase in headcount. The focus should be on giving analysts the context and support they need to handle more investigations on their own. 

Key takeaways for lean SOC teams

  • Close expertise gaps: Documented workflows and AI guidance can help when 60% of organizations report security skills gaps.
  • Prioritize real threats: Risk-based context helps when 73% of security teams cite false positives as their top detection challenge.
  • Automate repetitive work: Agentic AI can increase capacity, with 88% of security professionals reporting efficiency gains from AI-assisted workflows.
  • Scale senior expertise: Guided playbooks can reduce bottlenecks as 63% of practitioners report burnout and more than 80% face increased workloads.

Close SOC expertise gaps without adding headcount 

The skills gap becomes a bigger problem when the same senior analysts keep getting pulled into every investigation. 

For example, let’s say there is an alert involving suspicious activity from a cloud account. An experienced analyst knows which AWS CloudTrail events are important to check, what authentication activity looks suspicious from baseline, and what other users, systems, or events need to be checked. A less experienced analyst may spend much longer piecing that together or escalate the case simply because they are unsure what evidence to look at next.

Documented investigation workflows can help close that gap. Rather than expecting analysts to know every investigative path, teams can capture how experienced analysts handle common scenarios such as suspicious authentication, privilege escalation, endpoint compromise, and unusual cloud activity.

AI can take some of that legwork off the analyst by pulling together relevant telemetry and highlighting what deserves a closer look. For lean SOC teams, that can reduce unnecessary escalations and give junior analysts more of what they need to move an investigation forward on their own.

Advertisement

The goal is not to make junior analysts operate like senior analysts or use AI to replace experienced staff, but to make it easier for the team to apply its existing knowledge across more investigations.

SOC managers can start with three practical steps:

  1. Identify the investigations that most often require senior analyst involvement.
  2. Document what experienced analysts look for and what drives their decisions.
  3. Use those workflows to train less experienced analysts and guide future investigations.

Start with the investigations that consume the most senior analyst time. Those are likely to offer the biggest opportunity to reduce bottlenecks without trying to document every possible scenario the SOC could encounter.

Give SOC analysts more context before they investigate 

Alert severity alone does not tell an analyst how much risk an event poses. A high-severity alert on a test system may be less urgent than several lower-severity signals tied to a privileged account accessing production systems. 

The problem is that analysts often have to piece together that context themselves, which takes time and makes it harder to separate real threats from noise. That matters when 73% of security teams cite false positives and alert noise as their top detection challenge. More detections will not improve security if they simply give analysts more alert noise to sort through.

Prioritization should account for the context around an alert, including the user or entity involved, the importance of the affected asset, historical behavior, and related activity. 

When I worked in incident response for a healthcare organization, a few failed electronic health record (EHR) login attempts initially looked like a low-risk event until I noticed the account accessing an unusual number of patient records. We terminated access and investigated, confirming that an unauthorized user had compromised the account while the nurse was on vacation. 

But analysts should not have to manually connect such signals before they can understand the risk. Explainable AI can help correlate related activity and surface the evidence that shows why an investigation deserves priority. 

A high-risk score is only useful if the analysts can see what drove it. They need enough evidence to validate the recommendation and determine what to do next. For lean SOC teams, surfacing that context early can reduce time spent chasing false positives and help less-experienced analysts move cases forward without immediately escalating them. 

Advertisement

When analysts open a case, they should be able to quickly answer three questions:

  • What happened?
  • Why does it matter?
  • What evidence supports the conclusion?

Use agentic AI to automate investigation work, not analyst judgment 

Automation should take repetitive work off an analyst’s plate, not take the analyst out of the decision — humans in the loop will be even more important as SOC teams start using agentic AI for investigations. About 88% percent of cybersecurity professionals report measurable efficiency gains from AI-assisted security workflows, which can give lean teams more investigative capacity without adding analysts.

The best place to start is with work that is repetitive and easy to audit. An AI agent can pull related events, correlate users and assets, check activity against historical behavior, look for similar activity elsewhere in the environment, and summarize what it finds. That gives the analyst a better starting point. Instead of spending the first part of an investigation gathering evidence from multiple sources, they can spend that time determining whether the activity is malicious and what to do about it.

AI agents still need clear guardrails. Evidence collection, enrichment, correlation, and summarization are good candidates for greater automation. Disabling accounts, isolating endpoints, changing cloud configurations, or taking other actions that could disrupt production should generally require analyst approval unless the organization has established clear procedures for automated response.

Teams also need a record of what the AI did. Analysts should be able to see what evidence it reviewed, how it reached a conclusion, and what actions it recommended or performed. Such visibility is increasingly critical when AI is influencing which incidents get investigated first or how the SOC responds.

The goal is not to build a SOC that runs itself but to automate the investigative legwork so analysts have more time to evaluate the evidence and make the decisions that require human judgment.

Turn senior SOC expertise into repeatable investigation workflows 

Many SOCs have knowledge that lives with a handful of experienced analysts. They know which alerts are usually harmless, which combinations of activity deserve a closer look, and when something needs to be escalated.

That becomes a problem when everyone else has to rely on those same analysts to move an investigation forward. It slows investigations, creates inconsistent decisions, and pulls senior staff away from work that actually requires their experience. That dependency can also contribute to cybersecurity burnout by repeatedly pulling experienced analysts into routine escalations. 

Advertisement

The pressure is already showing. At least 63% of security practitioners report some level of burnout, and more than 80% say their workload has increased, making the SOC maturity gap harder for lean teams to address.

One way to reduce that dependency is to capture how experienced analysts actually investigate common incidents. Document what triggers a deeper investigation, which evidence they check, what they use to rule out benign activity, and when they escalate. A useful playbook should help an analyst think through an investigation rather than just telling them which tools to open.

This does not need to become a massive documentation project. Start with investigations that repeatedly end up with senior analysts and capture how they work through them. Then update the playbooks based on what the team learns from future investigations and incidents. 

Agentic AI can make those playbooks more useful during an actual investigation. An agent can follow predefined steps and gather the evidence the playbook calls for. Explainable outputs give the analyst a record of what was checked and why something was flagged. 

For lean teams, the benefit is straightforward. Senior analysts share their approach once instead of walking someone through the same investigation every time, giving junior analysts more independence and senior analysts more time for cases that require their expertise. 

Measure whether SOC automation actually saves analyst time 

Automating more tasks does not necessarily make a SOC more efficient. What matters is whether automation gives analysts time back without sacrificing the quality of investigations. SOC leaders should look at metrics such as time-to-evidence, false-positive rates, detection coverage, escalation accuracy, and how much analyst time goes toward triage versus higher-value security work.

Time-to-evidence is useful because gathering and correlating information can take up a large part of an investigation. Manually correlating 20 to 30 events during a shift can consume five to 10 analyst hours. Recovering even half of that time could give a three-person team roughly 900 analyst hours back each year. That’s time the team can put to better use.

Establish a baseline before introducing automation and then measure what changes. Faster investigations are a good sign, but not if incorrect escalations increase or analysts still spend hours pulling evidence from disconnected systems.

Advertisement

Also look at where the recovered time goes. Saving a few minutes on triage matters more when analysts can put that time toward threat hunting, improving detections, reviewing cloud configurations, tuning noisy rules, or testing incident response plans.

SOC automation should reduce repetitive investigative work and give analysts more time for security work that requires human judgment and experience. 

Build a stronger SOC with the team you have 

Most security teams are not going to have all the people, expertise, or tools they want. The focus should be on getting more out of the resources they already have. Give analysts the context they need to make decisions, automate the repetitive parts of investigations, and capture senior analysts’ knowledge so the rest of the team can use it. Then measure whether those changes are actually reducing false positives, speeding up investigations, and giving analysts their time back.

Explainable and agentic AI can help, especially for lean teams, but analysts still need to understand what the technology is doing and remain in control of critical decisions. AI should make experienced analysts more effective and help less-experienced analysts work more independently, not become another system the SOC has to blindly trust.

A SOC does not need a perfect team to operate effectively. It needs to make better use of the people, knowledge, and time it already has. 

The right mix of repeatable workflows, better context, and carefully applied AI can help analysts spend less time on investigative legwork and more time on the threats that require their attention.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.