
Security Operations Centres (SOCs) have reached a tipping point. While organisations continue to invest heavily in cybersecurity technologies, many are finding that adding more tools alone is no longer improving security outcomes. Instead, security teams are grappling with an ever-growing volume of alerts, increasingly sophisticated attacks, and a persistent shortage of skilled cybersecurity professionals.
The challenge is no longer visibility but it’s velocity.
According to IBM’s Cost of a Data Breach Report, organisations take an average of more than 250 days to identify and contain a breach, while Verizon’s 2025 Data Breach Investigations Report (DBIR) found that attackers continue to compromise systems in minutes, leaving defenders with increasingly narrow response windows. At the same time, ISC²’s Cybersecurity Workforce Study estimates a global cybersecurity workforce gap of more than four million professionals, making it increasingly difficult for SOC teams to keep pace with growing demand.
For today’s security leaders, the question is no longer whether artificial intelligence belongs in the SOC. It is whether organisations can continue to operate effectively without it.
From Security Automation to Autonomous Security Operations
Security automation has been part of SOC operations for years. Playbooks can isolate endpoints, create tickets, block malicious IP addresses and execute predefined workflows. While valuable, these automations remain deterministic, they perform only the actions they have been explicitly programmed to execute.
AI agents represent the next evolution.
Rather than simply automating repetitive tasks, agentic AI can investigate alerts independently, correlate telemetry across multiple security platforms, retrieve contextual information, identify likely attack paths and recommend appropriate response actions all within seconds. Instead of analysing a single alert in isolation, AI agents evaluate an incident as part of a broader attack narrative.
This shift fundamentally changes the role of the SOC.
Industry analysts increasingly view AI agents as force multipliers rather than standalone security tools. By reducing manual investigation time and eliminating repetitive triage activities, organisations can significantly improve analyst productivity while shortening response times across increasingly complex environments.
Why Enterprises Are Investing in AI-Powered SOCs
Enterprise adoption of AI within cybersecurity is accelerating because the business case is becoming increasingly compelling.
Modern organisations generate millions of security events every day. Security analysts spend a significant portion of their time investigating alerts that ultimately prove to be false positives or low-priority events. Every unnecessary investigation consumes valuable time that could otherwise be spent responding to genuine threats.
AI agents help address this imbalance by filtering noise, enriching alerts with contextual intelligence and escalating only incidents that require human expertise.
This trend is already becoming reality.
In 2025, BT Group became the first UK telecommunications company to join Anthropic’s Project Glasswing, an initiative exploring how AI agents can accelerate threat investigations and reduce repetitive workloads within Security Operations Centres. Rather than replacing security professionals, the programme aims to augment analyst capabilities by allowing AI to perform initial investigations while experienced responders focus on strategic decisions and complex incidents.
The initiative reflects a broader industry shift. Organisations are beginning to view AI not as another security product, but as an operational capability that improves resilience, reduces response times and enables security teams to scale without proportionally increasing headcount.
Human Judgement Remains the Critical Decision Layer
Despite rapid advances in generative AI and autonomous agents, today’s SOC still requires experienced human oversight.
Cybersecurity is rarely black and white.
An unusual login may indicate credential theft or simply an employee travelling internationally. An unexpected database query could signal malicious activity or an authorised maintenance task. Understanding business context, assessing operational risk and making high-impact response decisions remain uniquely human responsibilities.
For this reason, the future SOC is unlikely to be fully autonomous.
Instead, organisations are moving towards a collaborative operating model in which AI performs continuous investigation, enrichment and prioritisation, while security analysts provide contextual judgement, conduct threat hunting, validate recommendations and lead incident response.
The objective is not to remove humans from security operations.
It is to enable them to spend less time searching for problems and more time solving them.
Autonomous Security Starts with Trusted Data
The success of any AI agent ultimately depends on the quality of the data it can access.
Incomplete telemetry, fragmented security tools, inconsistent logging and poor data governance significantly reduce the effectiveness of AI-driven investigations. Even the most advanced models cannot produce reliable outcomes when operating on incomplete or inaccurate information.
As enterprises expand their AI capabilities, resilient infrastructure becomes a strategic requirement rather than a technical consideration.
Accurate telemetry, secure storage, integrated security platforms and strong governance frameworks provide the trusted foundation that enables AI agents to make reliable decisions at machine speed. Organisations that invest in these foundations today will be better positioned to adopt increasingly autonomous security operations tomorrow.
Preparing for the Next Generation of Security Operations
AI agents are rapidly redefining what modern Security Operations Centres can achieve. They offer the potential to accelerate investigations, reduce alert fatigue and enable security teams to respond to threats with unprecedented speed and consistency.
However, technology alone is not enough.
Successful autonomous security operations require high-quality data, resilient infrastructure, well-governed AI adoption and experienced security professionals who can provide strategic oversight where it matters most.
At Open Storage Solutions, we closely monitor how emerging technologies such as agentic AI are reshaping enterprise cybersecurity. By helping organisations strengthen their data foundations, improve infrastructure resilience and understand the practical implications of AI-driven security operations, we enable businesses to prepare confidently for the future.
The next generation of Security Operations Centres will not be defined by AI replacing analysts. It will be defined by organisations that successfully combine intelligent automation, trusted data and human expertise to build faster, more resilient cyber defence.
Add your first comment to this post