The transformation gap: people and process in the shift to a modern SOC

Organisations moving from a legacy Security Operations Centre to a modernised, AI-enabled SOC tend to converge quickly on what the end state should look like: AI agents handling first-pass triage, threat profiling and investigation; human analysts concentrated on higher-risk decisions; and detection coverage expanding without a corresponding rise in headcount. This broad objective is increasingly well understood across the industry. Yet the transformation required to achieve it is less understood and more consequential.
In practice, defining the technology end state has become the easier part of the transformation. Capabilities for threat profiling, detection-rule health checks, exposure scoring and investigation are increasingly available as mature, productised services. The harder and more determinative part is redesigning the people and processes around such technologies. This redesign, more than the choice of platform, is what separates transformations that deliver value from those that stall.
The starting point
A recognisable set of characteristics persists across many legacy SOCs. Alert volumes have grown faster than analyst capacity, while investigation quality can vary by shift as processes rely heavily on individual experience rather than documented standards. Detection logic is often built around static playbooks that lag behind evolving adversary behaviour, while scaling to handle greater volume or more assets typically means adding headcount.
The objective
The objective is not simply to introduce AI capabilities, but to establish a different division of labour between agents and analysts. Agents absorb the high-volume, repeatable work of triage, enrichment and investigation, while analysts focus their judgment on validation, escalation, and exceptions. For that division of labour to work, agent actions and human validation need to be documented and explainable, while leadership measures outcomes including response time, escalation consistency, and detection coverage. The result is an operating model in which increased coverage is achieved through how work is organised across agents and analysts, rather than through a corresponding increase in team size.
The transformation itself
The gap between a legacy SOC built around manual, experience-dependent processes and a modernised SOC built around agent-assisted investigation and human validation is closed primarily through changes in role design and operational process, not technology selection.
On the people side, the central design question is what analysts do once agents take on first-pass triage. Framing this purely as headcount reduction tends to undermine adoption before it begins. The model instead repositions analysts around supervision, validation and exception handling: reviewing agent-produced findings, deciding when to escalate, and developing a working understanding of where an agent performs reliably, where its outputs require closer scrutiny, and when human intervention is necessary. This requires a deliberate approach to career development, since entry-level analysts have traditionally built judgement through high-volume manual triage; where that work is automated, organisations need an alternative route for developing equivalent experience.
On the process side, the shift is from static, calendar-reviewed playbooks to continuously tuned, threat-led detection, and from individually variable escalation practices to a documented, consistent standard. Human validation needs to be designed into the workflow from the outset, rather than added retrospectively, for instance, requiring analyst sign-off before an agent-generated finding is escalated. Measurement must change alongside the workflow itself: from counting closed tickets to tracking response time, escalation consistency and automation efficiency, with enough transparency for leadership to understand what agents and analysts each are doing, and why.
What follows from getting this right
The resulting modernised operating model is intended to make SOC performance less dependent on manual workload and individual analyst variation. In a separate engagement, a large transportation and logistics company used four specialised AI agents to increase continuous threat-hunting capacity 10–15 times without an equivalent increase in cost or headcount. Agents handled operational tasks while senior analysts focused on interpretation and judgement.
The wider AI estate
The same operating-model question extends beyond the agents deployed within the SOC itself. As organisations adopt AI more broadly, security teams also need visibility into the agents, models and services operating across the wider estate. In one discovery exercise, a global financial services organisation with more than 2,000 employees was found to have 740% more MCP servers, 800% more AI agents and 600% more LLM providers in production than its existing inventory indicated.
The implication for SOC transformation is straightforward: the principles required to govern agentic security operations, including clear ownership, explainability, appropriate human oversight and continuous measurement, also need to apply to the wider AI estate. IBM's 2026 Cost of a Data Breach research found that one in four malicious breaches were AI-enabled, with those breaches costing an average of $6 million. More than 20% of organisations also reported a breach targeting AI models or applications. AI governance should therefore be treated as part of the same operating-model shift, rather than as a separate activity that follows deployment.
Conclusion
The technology required to build a modernised SOC is increasingly available. What it does not provide on its own is the operating model required to use it effectively. This depends on how organisations redesign roles, standardise processes and establish governance around the new division of labour between humans and agents. The transformation gap, ultimately, is not between old and new technology, but between deploying capable tools and changing the organisation around them.



