Stop Building a 2003 SOC with AI: A Modern People & Process Framework (Part 1)
One particular aspect of an agentic or AI-powered SOC (but NOT “humanless SOC”) has bothered me over the last few months: specifically, the people and process side of such a SOC. If you recall my blog posts (part 1, part 2 and this video) about AI SOC readiness, I hinted at certain elements of a traditional process stack and legacy personnel profiles (both technical and leadership) that make AI adoption inside SOC incredibly difficult.
So we (me and Augusto Barros @ Prophet Security) want to create a modernized people and process framework for a SOC powered by AI and intelligent agents. Otherwise, what I am observing is a lot of “robotic horse pulls a buggy” kind of operations — where everything is kept exactly the same as it was in 2003, but “AI SOC” tools are simply tacked on to perform some of the tasks.

I believe that people and process components must change far more dramatically, and such changes are a critical requirement for achieving “step change” SOC with AI capabilities. Simply adding AI tools and Ai agents to a 2003-style SOC will produce, at best, marginal results. Things would get better, but not better enough to counter the feared “bad guy with AI.”
The SOAR Analogy
The analogy I want to use here is SOAR adoption from 10+ years ago. Back then, organizations simply shifted a few processes — or even just specific tasks — to a machine, and then kept the rest of their operations exactly the same. Because of that, I observed a lot of SOAR tools being used strictly for alert enrichment or for dealing with one specific, isolated type of alert, like phishing. To follow this analogy to the present day, I now frequently see an “AI SOC” being utilized only for EDR alerts or only for phishing alerts (wow, what a coincidence!)
A First-Principles Approach
What I really want to build is a first-principles approach to the specific personnel, skills, processes, and practices required to run a true agentic SOC in the late 2020s.
Now, if you prefer incremental change, that is OK, I won’t judge. However, you must be aware that the same principles caused organizations to struggle with cloud adoption. People often hear that “lift and shift” is bad. Most consultants will tell you that “lift and shift” is fine as a first step, but you eventually need to modernize and take more steps. Unfortunately, many organizations never make that second step. The same risk applies to the AI SOC. 2003 SOC + AI = somewhat better 2003 SOC.
BTW, many artifacts of the modern, engineering-powered SOC — which we covered in our now-famous ASO (Autonomic Security Operations) paper back in 2021s — apply here as well. In fact, if you recall, one of our core principles was: Humans build machines; machines do the work.
In the context of an agentic SOC, that evolves into:

Today, humans build the machines with the help of other machines, and then the machines do the heavy lifting.
So, our questions so far:
- What do humans do in an agentic SOC?
- What do entry-level humans do?
- What SOC processes stay the same despite AI?
- What SOC processes can just go and vanish (triage)?
- What processes get handed to machines?
- Are there new processes for humans?
- What is the new human role for validation?
- How do we check AI quality without fully redoing the work?
- How SOC metrics must change due to AI and agents? (some ideas)
- What do humans and machines do jointly? What does it mean, practically?
- How to HITL in a SOC without breaking the humans or machines?
- What is the effective mechanism for the human-to-AI feedback loop so that corrections actually improve future SOC performance?
- Is “fully automated” detection engineering a realistic goal, or does the dependency on local, inconsistent environment context make it inherently a hybrid human-machine effort?
- What do humans do before SOC (TI) and after SOC (IR)?
- What is the first step to move from a legacy SOC to an agentic SOC?
- Can we run legacy and agentic SOC structures in parallel during transition, or does this duplication create operational friction?
- Is it easier to move from a modern non-AI SOC (aka “SOCless D&R”) to an AI SOC?
Looking Ahead
This blog post is just the first part of the series. My goal here is simply to collect the right questions we need to be asking, but I promise we will provide concrete answers in upcoming posts. This research is being undertaken together with my former colleague, Augusto Barros, now at Prophet Security
Related blogs:
- Beyond “Is Your SOC AI Ready?” Plan the Journey!
- Simple to Ask: Is Your SOC AI Ready? Not Simple to Answer!
- WTH is Modern SOC, Part 1
- Baby ASO: A Minimal Viable Transformation for Your SOC
- Beware: Clown-grade SOCs Still Abound
- EP264 Measuring Your (Agentic) SOC: Two Security Leaders Walk into a Podcast
- New Paper: “Future of the SOC: Evolution or Optimization — Choose Your Path” (Paper 4 of 4.5)
- The Gravity of Process: Why New Tech Never Fixes Broken Process and Can AI Change It?
Stop Building a 2003 SOC with AI: A Modern People & Process Framework (Part 1) was originally published in Anton on Security on Medium, where people are continuing the conversation by highlighting and responding to this story.