All insights
AI for Security

Rebuilding the SOC for an AI-Speed Adversary

Attackers compressed breakout time to minutes and deleted the cost of expertise. You cannot defend a machine-speed adversary at human speed.

Paul FalorJune 21, 20268 min read

The arithmetic of the security operations center has inverted, and most defenders have not noticed yet.

Start with the attacker's clock. CrowdStrike's 2026 Global Threat Report puts the average eCrime breakout time, the gap between an initial foothold and lateral movement, at 29 minutes, with the fastest observed at 27 seconds. A few years ago that number was measured in hours. Mandiant found the average time to exploit a vulnerability after disclosure collapsed to five days, down from sixty-three a few years earlier, with most exploited vulnerabilities being zero-days. Ransomware now lands within a day of initial access in more than half of incidents.

Now the defender's clock. Mandiant's M-Trends reports a global median dwell time around eleven days, and IBM's 2025 breach data shows a mean time to identify and contain of 241 days. That 241 figure is celebrated as a nine-year low. Hold the two clocks side by side. The adversary moves in minutes. We respond in months. This is not a tuning problem. It is a structural mismatch, and you cannot close a structural mismatch with overtime.

The defenders are already underwater

The mismatch is worse because the human capacity to fix it does not exist. ISC2's workforce study put the global cybersecurity gap at 4.76 million unfilled roles against a workforce that grew by roughly 0.1% in a year. In its 2025 study, ISC2 reported that 95% of organizations face at least one security skills gap and that 88% suffered a significant security event they attribute to that shortage. The single most in-demand skill they identified was AI.

The analysts we do have are drowning. Industry state-of-the-SOC research consistently describes thousands of alerts a day, roughly half of them false positives, and a large fraction never investigated at all. The human cost follows. Tines' Voice of the SOC found 63% of analysts reporting burnout and more than half saying they were likely to change jobs within the year. You cannot out-hire this. You cannot out-suffer it either.

AI did not invent new attacks. It deleted the cost of expertise.

This is the part that should reframe the conversation. When Microsoft and OpenAI jointly disrupted five nation-state groups misusing large language models in early 2024, their notable finding was that they had not yet seen particularly novel AI-enabled attack techniques. The tradecraft was familiar. What changed was the economics of who can run it.

AI-generated phishing, per Microsoft's 2025 Digital Defense Report, achieves a 54% click-through rate against 12% for manually written lures, and the report estimates AI can make a phishing campaign up to fifty times more profitable. CrowdStrike logged a 442% surge in voice phishing between the first and second halves of 2024. Engineering firm Arup lost 25.6 million dollars to a single deepfake video call in which the CFO and the colleagues on screen were all AI-generated. Deloitte projects that generative-AI-enabled fraud losses in the US will reach 40 billion dollars by 2027.

Then came the threshold moments. Anthropic disclosed a case of "vibe hacking" in which one low-skilled criminal used an AI coding agent to run an extortion campaign against at least seventeen organizations in a single month. Google's threat intelligence group documented the first malware seen querying a large language model mid-execution to generate its own commands. And in late 2025 Anthropic reported disrupting what it described as the first AI-orchestrated cyber-espionage campaign, in which the model executed an estimated 80 to 90% of the tactical operations against roughly thirty targets, with human operators stepping in at only a handful of decision points.

The real disruption is not a new weapon. It is the collapse of the skill barrier. Assume every adversary now operates near the capability ceiling rather than the floor.

The rebuild: AI owns scale, humans own consequence

The case for AI in defense is no longer a slide in a deck. It is measured. CrowdStrike reports that its agentic triage agrees with expert human triage more than 98% of the time and saves customers an average of more than forty hours of manual work per week. Microsoft's randomized controlled trials found that Security Copilot made newer analysts markedly more accurate and roughly a quarter faster. Google's Big Sleep agent became the first AI to find a previously unknown, exploitable memory-safety vulnerability in widely used real-world software, and it has since found real CVEs. The productivity case is settled.

The part the vendors undersell is that autonomy is itself a new attack surface. Automation bias leads people to over-trust machine output. Dense, multi-step agent action traces become effectively uninterpretable. An agent that can take a production server offline to contain a threat can also cause the outage it was meant to prevent. The goal is not to automate fastest. It is to engineer the trust boundary deliberately.

So the rebuild I advocate is human-on-the-loop rather than human-out-of-the-loop. Let AI own the work that scales and exhausts people: triage, enrichment, correlation, first-pass investigation, the relentless winnowing of those thousands of daily alerts. Reserve for humans the work that requires judgment and carries consequence: irreversible remediation, attribution calls, and anything that touches production or customers. The boundary between those two zones is the single most important design decision in a modern SOC.

Where to start

Three moves, in order. First, instrument your real numbers: breakout-time exposure, mean time to respond, and the ratio of alerts to actual investigations. You cannot rebuild what you have not measured, and the gap is almost always wider than leadership believes. Second, point AI at your highest-volume, lowest-judgment workflows first, because triage and enrichment give you the fastest relief and the safest failure modes. Third, before you automate any consequential action, write down the trust boundary explicitly: what the machine may do alone, what requires a human, and how a person can see and reverse what the machine did.

The organizations that win the next phase will not be the ones that automate the most. They will be the ones that restored symmetry of speed against the adversary while keeping human judgment exactly where it belongs.

Sources

  1. 1.CrowdStrike: 2026 Global Threat Report
  2. 2.Mandiant: Time-to-Exploit Trends
  3. 3.Mandiant: M-Trends 2025
  4. 4.IBM: Cost of a Data Breach Report 2025
  5. 5.ISC2: 2024 Cybersecurity Workforce Study
  6. 6.Tines: Voice of the SOC 2023
  7. 7.Microsoft: Digital Defense Report 2025
  8. 8.Fortune: Arup $25.6M deepfake fraud
  9. 9.Deloitte: Generative AI and the fraud landscape
  10. 10.Anthropic: Detecting and countering misuse of AI (Aug 2025)
  11. 11.Anthropic: Disrupting AI espionage (Nov 2025)
  12. 12.Google: From Naptime to Big Sleep
  13. 13.CrowdStrike: Charlotte AI agentic detection triage
  14. 14.Microsoft & OpenAI: Staying ahead of threat actors in the age of AI

More perspectives

Discuss this with Paul