Loading...
Loading...

Alankrit argues that most SOC teams' current metrics reflect workload management more than they reflect the security protection they're delivering. That gap is now the story.
For decades, the Security Operations Center has run on a hidden constraint. On paper, the SOC looks like a defensive funnel. Functionally, it's a bottleneck. That's the definition of a fixed capacity SOC: an operation capped by the number of human hours in a day and the cognitive limits of the analysts who fill them.
When threat growth was linear, the model was expensive but livable. You hired more analysts to match volume. That world is gone. Attack surfaces exploded. Telemetry exploded. When both grow exponentially and headcount grows arithmetically, a fixed capacity SOC turns into a liability. Security leaders end up making a trade every board deck skips over: ignore most of the signal so the team can survive the shift.
The most damaging casualty of the fixed capacity SOC is the truth about our detection metrics. We were taught that a low False Positive Rate is the mark of a mature program.
It isn't. It's a coping mechanism.
Bringing AI into SOC workflows surfaced something uncomfortable. False Positive Rates were never really about detection accuracy. They were about human capacity. Traditional FPR doesn't measure how well you find threats. It measures what your analysts can process without burning out.
Take the standard tuning cycle. A detection rule ships. It fires 500 alerts a day. The SOC manager checks the roster, realizes the team can handle 50, and tunes the rule "down." We call it "reducing noise." What we're really doing is capping alert volume to protect analyst capacity at the expense of threat sensitivity.
We knowingly miss real threats because our people can't process everything the sensors surface, not because the detection logic is flawed. A "well-tuned" 2% FP rate is a graveyard of threats we chose not to see so the team could get through the week. That's alert overload dressed up as engineering discipline.
Inside a fixed capacity SOC, Mean Time to Respond and Mean Time to Investigate lose their meaning. They become vanity metrics that hide the risk of everything the team never touched.
"We are knowingly missing real threats because the analysts simply cannot process everything the detection could surface, not because the detection logic is flawed."
If your team ignores 90% of the telemetry so they can investigate the remaining 10% quickly, your MTTR looks great. You might report a 30-minute response time to the board. But that number is disconnected from your actual risk. It only measures the speed at which you processed the arbitrary slice of data you let into the queue.
In a fixed capacity model:
Neither one measures security.
This fragile equilibrium is now breaking. AI-generated attacks are landing on enterprise networks, mimicking legitimate behavior so precisely that simple rules can't separate "normal" from "malicious" anymore.
When adversaries use AI, they push volume and variance up at the same time. Signals blur. If you try to tune a fixed capacity SOC against AI-driven attacks, you'll tune out the attack itself. The rule that would have flagged the intrusion looked too noisy on Monday morning, so it never fired on Thursday night.
That's the SOC bottleneck at its most dangerous. It isn't that the team is slow. It's that the detection strategy itself is being drafted around what a fatigued analyst can withstand.
Every CISO I've spoken to this year has floated the same fix: hire more analysts. The market answers back. Attrition is high, seniors are scarce, and by the time a new hire is productive, the alert volume has moved again. Adding people to a fixed capacity SOC doesn't rebuild the model. It postpones the collapse.
SOC scaling has to come from a different axis. Not more hours in the day. More reasoning per alert. That is the shift AI SOC capacity is meant to deliver: every alert investigated, every signal followed, without the ceiling that forces the tuning trade in the first place.
Enough capacity means the detection rule that fires 500 alerts a day gets 500 investigations that day. It means MTTR and FPR go back to being real measurements instead of survival stats. It means the CISO can answer "did we catch it?" with evidence, not with the confidence interval of a burned-out roster.
Simbian's AI SOC Agent is built for that shift. Every alert triaged. Every investigation reasoned end to end. Every finding auditable. Self-improving, not self-driving: humans keep containment authority and escalation calls, and the Agent takes the volume so the team can take the judgment.
If your metrics still look clean because the queue is short, ask which alerts you decided not to see. That's the number that matters.
Read the full ebook → Security for Winners: The Art of Using AI to Secure Your Company and Get Yourself Promoted