
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
What a tenth-year SANS survey of 444 practitioners actually found about AI adoption in the SOC, and why most teams have the tools but not the workflow yet.
Almost every security operations center now has some AI tool running somewhere in its stack. Far fewer have actually figured out how that tool fits into the team's real workflow, and that gap, not AI's raw capability, is the honest story of where SOC work is headed.
AI in the SOC, 2026
The SANS 2026 SOC Survey, now in its tenth year and drawing on 444 security operations practitioners alongside a parallel survey of 69 CISOs and senior executives, found that gap directly: 79% of SOCs use AI tools in some form, but only 36% have built that usage into an actual defined workflow. The survey's own warning is specific, when analysts reach for AI tools informally, without governance or a validation step, the result is confident, well-formatted output that goes unchallenged, which is a worse outcome than no AI at all if a wrong answer looks just as polished as a right one.
Separately from SANS's independent numbers, vendor-sponsored research on analyst sentiment (treat these as directional, not independent) points in a consistent direction: most analysts report AI reducing repetitive triage work and improving investigation accuracy, particularly for daily users of the tooling. That tracks with what MDR providers have been building toward for years, our own explainer on Managed Detection and Response covers how that model already combines detection technology with human analysts who provide judgment a tool alone can't, AI shifts what the technology layer can pre-filter, it doesn't remove the need for that judgment.
One of the more interesting findings in the SANS data has nothing to do with AI capability directly, for the third year running, purpose and growth outrank compensation as the top reasons SOC analysts stay in their roles. Tools that genuinely remove repetitive, low-value triage work (rather than just promising to) speak directly to that retention driver, a SOC where analysts spend their time on judgment calls instead of alert fatigue is a SOC that keeps its experienced people.
An AI tool that pre-filters and enriches alerts still needs someone to decide what to do when it's wrong, and it will be wrong, confidently, on exactly the kind of ambiguous case that most needs a human call. The realistic trajectory is a SOC where analyst time shifts away from repetitive triage and toward the investigation and response decisions that genuinely require context about your specific business, headcount doesn't disappear, the work it's spent on changes.
AI-assisted detection is only as good as the environment it's watching, a tool layered onto noisy defaults and incomplete log coverage just produces confident noise faster. That configuration work, scoping and tuning the detection platform your SOC or MDR provider actually runs on, is the kind of foundational work our Cybersecurity Consulting team does before any AI-assisted tooling gets added on top, not after something's already gone wrong.
Tell us about your environment and goals, we'll help you scope the right engagement.