The transformation gap: people and process in the shift to a modern SOC
Guest blog by Tatjana Radisic, Client Executive at UST #AISecurity
Organisations moving from a legacy Security Operations Centre to a modernised, AI-enabled SOC tend to converge quickly on what the end state should look like: AI agents handling first-pass triage, threat profiling and investigation; human analysts concentrated on higher-risk decisions; and detection coverage expanding without a corresponding rise in headcount. This broad objective is increasingly well understood across the industry. Yet the transformation required to achieve it is less understood and more consequential.
In practice, defining the technology end state has become the easier part of the transformation. Capabilities for threat profiling, detection-rule health checks, exposure scoring and investigation are increasingly available as mature, productised services. The harder and more determinative part is redesigning the people and processes around such technologies. This redesign, more than the choice of platform, is what separates transformations that deliver value from those that stall.
The starting point
A recognisable set of characteristics persists across many legacy SOCs. Alert volumes have grown faster than analyst capacity, while investigation quality can vary by shift as processes rely heavily on individual experience rather than documented standards. Detection logic is often built around static playbooks that lag behind evolving adversary behaviour, while scaling to handle greater volume or more assets typically means adding headcount.
The objective
The objective is not simply to introduce AI capabilities, but to establish a different division of labour between agents and analysts. Agents absorb the high-volume, repeatable work of triage, enrichment and investigation, while analysts focus their judgment on validation, escalation, and exceptions. For that division of labour to work, agent actions and human validation need to be documented and explainable, while leadership measures outcomes including response time, escalation consistency, and detection coverage. The result is an operating model in which increased coverage is achieved through how work is organised across agents and analysts, rather than through a corresponding increase in team size.
The transformation itself
The gap between a legacy SOC built around manual, experience-dependent processes and a modernised SOC built around agent-assisted investigation and human validation is closed primarily through changes in role design and operational process, not technology selection.
On the people side, the central design question is what analysts do once agents take on first-pass triage. Framing this purely as headcount reduction tends to undermine adoption before it begins. The model instead repositions analysts around supervision, validation and exception handling: reviewing agent-produced findings, deciding when to escalate, and developing a working understanding of where an agent performs reliably, where its outputs require closer scrutiny, and when human intervention is necessary. This requires a deliberate approach to career development, since entry-level analysts have traditionally built judgement through high-volume manual triage; where that work is automated, organisations need an alternative route for developing equivalent experience.
On the process side, the shift is from static, calendar-reviewed playbooks to continuously tuned, threat-led detection, and from individually variable escalation practices to a documented, consistent standard. Human validation needs to be designed into the workflow from the outset, rather than added retrospectively, for instance, requiring analyst sign-off before an agent-generated finding is escalated. Measurement must change alongside the workflow itself: from counting closed tickets to tracking response time, escalation consistency and automation efficiency, with enough transparency for leadership to understand what agents and analysts each are doing, and why.
What follows from getting this right
The resulting modernised operating model is intended to make SOC performance less dependent on manual workload and individual analyst variation. In a separate engagement, a large transportation and logistics company used four specialised AI agents to increase continuous threat-hunting capacity 10–15 times without an equivalent increase in cost or headcount. Agents handled operational tasks while senior analysts focused on interpretation and judgement.
The wider AI estate
The same operating-model question extends beyond the agents deployed within the SOC itself. As organisations adopt AI more broadly, security teams also need visibility into the agents, models and services operating across the wider estate. In one discovery exercise, a global financial services organisation with more than 2,000 employees was found to have 740% more MCP servers, 800% more AI agents and 600% more LLM providers in production than its existing inventory indicated.
The implication for SOC transformation is straightforward: the principles required to govern agentic security operations, including clear ownership, explainability, appropriate human oversight and continuous measurement, also need to apply to the wider AI estate. IBM's 2026 Cost of a Data Breach research found that one in four malicious breaches were AI-enabled, with those breaches costing an average of $6 million. More than 20% of organisations also reported a breach targeting AI models or applications. AI governance should therefore be treated as part of the same operating-model shift, rather than as a separate activity that follows deployment.
Conclusion
The technology required to build a modernised SOC is increasingly available. What it does not provide on its own is the operating model required to use it effectively. This depends on how organisations redesign roles, standardise processes and establish governance around the new division of labour between humans and agents. The transformation gap, ultimately, is not between old and new technology, but between deploying capable tools and changing the organisation around them.
Cyber Resilience Programme activities
techUK brings together key players across the cyber security sector to promote leading-edge UK capabilities, build networks and grow the sector. techUK members have the opportunity to network, share ideas and collaborate, enabling the industry as a whole to address common challenges and opportunities together. Visit the programme page here.
Upcoming events
Latest news and insights
Learn more and get involved
Cyber Resilience updates
Sign-up to get the latest updates and opportunities from our Cyber Resilience programme.
Meet the team
Jill Broom
Head of Cyber Resilience, techUK
Jill leads the techUK Cyber Resilience programme, having originally joined techUK in October 2020 as a Programme Manager for the Cyber and Central Government programmes. She is responsible for managing techUK's work across the cyber security ecosystem, bringing industry together with key stakeholders across the public and private sectors. Jill also provides the industry secretariat for the Cyber Growth Partnership, the industry and government conduit for supporting the growth of the sector. A key focus of her work is to strengthen the public–private partnership across cyber to support further development of UK cyber security and resilience policy.
Before joining techUK, Jill worked as a Senior Caseworker for an MP, advocating for local communities, businesses and individuals, so she is particularly committed to techUK’s vision of harnessing the power of technology to improve people’s lives. Jill is also an experienced editorial professional and has delivered copyediting and writing services for public-body and SME clients as well as publishers.
- Email:
- [email protected]
- Website:
- www.techuk.org/
- LinkedIn:
- https://www.linkedin.com/in/jill-broom-19aa824
Read lessmore
Annie Collings
Senior Programme Manager, Cyber Resilience, techUK
Annie is the Programme Manager for Cyber Resilience at techUK. She first joined as the Programme Manager for Cyber Security and Central Government in September 2023.
In her role, Annie supports the Cyber Security SME Forum, engaging regularly with key government and industry stakeholders to advance the growth and development of SMEs in the cyber sector. Annie also coordinates events, engages with policy makers and represents techUK at a number of cyber security events.
Before joining techUK, Annie was an Account Manager at a specialist healthcare agency, where she provided public affairs support to a wide range of medical technology clients. She also gained experience as an intern in both an MP’s constituency office and with the Association of Independent Professionals and the Self-Employed. Annie holds a degree in International Relations from Nottingham Trent University.
- Email:
- [email protected]
- Twitter:
- anniecollings24
- LinkedIn:
- https://www.linkedin.com/in/annie-collings-270150158/
Read lessmore
Olivia Staples
Junior Programme Manager - Cyber Resilience, techUK
Olivia Staples joined techUK in May 2025 as a Junior Programme Manager in the Cyber Resilience team.
She supports the programs mission to promote cyber resilience by engaging key commercial and government stakeholders to shape the cyber resilience policy towards increased security and industry growth. Olivia assists in member engagement, event facilitation and communications support.
Before joining techUK, Olivia gained experience in research, advocacy, and strategic communications across several international organisations. At the Munich Security Conference, she supported stakeholder engagement and contributed to strategic communications. She also worked closely with local and national government stakeholders in Spain and Italy, where she was involved in policy monitoring and advocacy for both public and private sector clients.
Olivia holds an MSc in Political Science (Comparative Politics and Conflict Studies) from the London School of Economics (LSE) and a BA in Spanish and Latin American Studies from University College London (UCL).
Outside of tech, Olivia enjoys volunteering with local charities and learning Norwegian.
- Email:
- [email protected]
Read lessmore
Authors
Tatjana Radisic
Client Executive, UST