Security operations centers (SOCs) are at a pivotal point as artificial intelligence (AI) reshapes the landscape of cybersecurity. While discussions persist about AI potentially introducing new types of cyber threats, the immediate shift lies in how AI is making it easier and cheaper for attackers to retry failed attempts. This subtle transformation reflects a significant change in how threats are managed.
AI is enhancing the efficiency of cyberattacks by streamlining processes once considered time-consuming. For example, attackers who previously struggled with privilege escalation can now utilize AI to quickly resolve errors, refine scripts, and attempt new strategies within moments. This advancement does not introduce new capabilities but rather optimizes the existing ones, reducing the time and cost associated with the middle stages of an intrusion.
The Evolving Role of AI in Cyber Threats
The evolution of AI in cybersecurity is evident through recent findings. In early 2025, Google’s Threat Intelligence Group (GTIG) observed state-sponsored entities leveraging AI for tasks such as translation and scripting. By the end of that year, the focus shifted to more sophisticated uses, including malware that interacted with AI models during execution and a thriving underground market for illicit AI tools. In 2026, GTIG identified an AI-assisted exploit of a two-factor authentication bypass, exemplifying how AI supports both discovery and development of exploits.
These developments emphasize AI’s growing integration into attacker workflows, blurring the lines between assistance and direct deployment. While AI’s role in cyber threats continues to be debated, its influence is undeniably steering towards embedding within attacker strategies.
Challenges in SOC Operations and Handoff Efficiency
The efficiency of SOC operations hinges on seamless handoffs between various functions such as threat intelligence, detection engineering, and remediation. However, the current SOC model often suffers from lossy handoffs where critical knowledge is compressed into alerts or tickets, losing valuable context. This issue is exacerbated by the traditional approach of viewing the attack lifecycle as linear, whereas attackers operate in iterative loops, constantly refining their tactics.
Defense mechanisms should ideally mimic this looped approach, yet practical constraints such as queues and handoffs interrupt the process, leading to delays in response. The mean time to acknowledge an alert can be misleading as the actual remediation may take much longer due to these inefficiencies.
Improving SOC Resilience with Stateful Operations
To counter these challenges, adopting a stateful SOC model is crucial. This involves maintaining a shared operational memory that captures environmental, evidence, decision, control, and learning states across workflows. Such a model ensures that every function within the SOC has access to comprehensive and contextual information, thereby enhancing the overall response efficiency.
By treating unknowns as valid data points and capturing comprehensive case details, SOCs can improve their resilience and decision-making processes. This approach not only reduces the burden on individual analysts but also prevents the loss of critical insights post-incident, ensuring that lessons learned contribute to continuous improvement.
In conclusion, the integration of AI into SOC operations offers both challenges and opportunities. As AI continues to compress attack timelines, SOCs must adapt by enhancing their operational memory and efficiency. This evolution will allow them to better manage alerts, reduce decision latency, and ultimately strengthen their cybersecurity posture.
