AI in the SOC: where it helps, where it hurts, and where the marketing ends
AI in the SOC supports analysts, who remain responsible for their work. The real value lies in alert triage, correlation across data sources, summarising forensic raw data and suggesting response steps. AI causes harm through unattended auto-response without analyst sign-off and hallucinated links in reports. Assuming an AI module can replace a detection-engineering process also creates risk. ANOMAL uses AI where its output is deterministically verifiable and keeps the analyst as decision-maker.
Scope: defence side, not attack side
This page covers how SOC teams use AI defensively. AI-driven cyber attacks describes how attackers use AI for phishing in flawless German, voice clones and LLM-generated malware. For operational SOC integration, see SOC as a Service Switzerland. For detection metrics, see MTTD and MTTR.
Where AI helps in the SOC
| Use case | What AI contributes | Analyst control |
|---|---|---|
| Alert triage | Enrichment with context (asset, user, historical alerts), priority suggestion. | Analyst confirms classification, no auto-closure without sign-off. |
| Cross-source correlation | Ties EDR, identity, NDR and email signals into a case hypothesis. | Analyst checks causality; the AI output is treated as a hypothesis, not fact. |
| Raw-data summarisation | Summarises PowerShell history, process trees or email headers in plain text. | The analyst validates against source data; the summary serves as a working aid and has no evidential status. |
| Response suggestions | Suggests playbook steps (session invalidation, isolation, IOC sweep). | Analyst executes or declines; critical actions remain manually approved. |
| Reporting | Drafts initial incident reports and customer communication. | Analyst checks numbers and statements; no report goes out without human sign-off. |
Where AI hurts in the SOC
- Unattended auto-response: an AI module that locks accounts or isolates endpoints without analyst sign-off causes business impact when it misclassifies activity. Deterministic playbooks for clearly defined signals are acceptable. Free-form AI actions are unacceptable.
- Hallucinations in reports: LLMs invent plausible but wrong causal links (attacker group, CVE reference, timeline). Analysts must verify every causal statement against raw data.
- Substitute for detection engineering: AI improves triage. Curated detection rules, a use-case catalogue and coverage reviews remain necessary.
- Data leakage into external models: customer raw data must not flow into third-party LLMs without a contractual basis. SOC providers must document model selection and data storage.
- Trust drift: analysts who accept AI output uncritically produce misjudgements that are harder to correct than classical false positives.
How ANOMAL uses AI
ANOMAL combines deterministic automation, AI assistance and our analysts. Deterministic playbooks handle clearly defined, recurring cases (password reset on impossible travel, session invalidation on token anomalies). AI assistance accelerates triage, correlation and report drafting. Analysts decide on anything with business impact or regulatory reach. This division is deliberately conservative, because in the Swiss context (revFADP, FINMA, ISG), traceability outranks speed.
A supervisor (FINMA, the National Cyber Security Centre (NCSC), FDPIC) may review an incident's decision trail. That trail must link every security-relevant action to a responsible person. Pure AI decisions without analyst signature create compliance risks. See [SOC and FINMA requirements](/en/soc/soc-finma-requirements) and [SOC and ISG reporting](/en/soc/soc-isg-24h-reporting).
Governance questions for every SOC provider
- Which models do you use, where do you host them, and do you use customer data for training?
- Which actions can AI trigger autonomously, and which require analyst sign-off?
- How do you detect and correct hallucinations in reports before customers see them?
- How do you document the decision trail when AI has influenced a triage classification?
- Is there a kill-switch to disable AI components per customer without interrupting SOC operations?
These questions belong in every SOC RFP. For an evaluation grid, see SOC provider comparison.
How to measure AI value in the SOC
- MTTA (mean time to acknowledge): drops when AI triage prepares context.
- MTTD and MTTR: drop through faster correlation, see MTTD and MTTR.
- Analyst focus time: the share of the shift spent on complex cases rises, and the share spent on noise falls.
- Report turnaround: time from incident end to customer-approved report drops.
- False-positive rate: should not rise; if it does, AI triage is over-tuned.
Frequently asked questions
Does AI replace the SOC analyst?
AI does not replace the SOC analyst. AI relieves the analyst on triage, correlation and summarisation. Humans retain control of decisions with business or compliance impact. In the Swiss regulatory environment (revFADP, FINMA, ISG), traceability to a responsible person is mandatory.
Does AI hallucinate in incident reports?
Yes, this is a real risk. LLMs invent plausible but wrong causal links (wrong attacker groups, fabricated CVE references). Analysts must verify every causal statement against raw data before a report goes to the customer.
May a SOC send our raw data to external LLMs?
A SOC may do so only with a contractual basis, clear data storage commitments and revFADP (revised Federal Act on Data Protection) compliance. Those commitments must cover region, retention and exclusion from training use. For regulated customers (banking, healthcare), choosing a locally hosted or EU-hosted model is effectively mandatory. See [revFADP and SOC](/en/soc/revdsg-and-soc).
What is the difference between automation and AI in the SOC?
Automation follows deterministic rules (if signal A and B, then action X). It is auditable and reproducible. AI proposes based on probability; the output is not deterministic. A good SOC uses both, with a clear separation.
How do I tell marketing AI from the real thing?
Ask four questions. Which actions run autonomously? How do you detect hallucinations? Where does the data reside? What does analyst sign-off look like in the ticket? A provider who answers concretely has embedded AI operationally. A provider offering only slogans is selling a label.
Related terms
- Hyper Automation Hyper Automation is the consistent, end-to-end automation of all recurring tasks in a Security Operations Center.
- Human-in-the-loop Human-in-the-loop means that a person makes the most critical decisions within an automated process.
- SOAR Security Orchestration, Automation and Response (SOAR) platforms help a SOC to automate procedures and connect tools together.
- Detection as Code Detection as Code manages detection rules like software: versioned, tested, reviewed and deployed automatically.