Information securityArtificial intelligence

The human SOC is prehistory: you don't win by reading logs and staring at dashboards

The human SOC is prehistory: you don't win by reading logs and staring at dashboards

I am aware of how harsh the criticism I am about to make is, but recent events leave little room for doubt.

Cybersecurity keeps telling itself a reassuring lie, that there is still time to read an advisory, study a vulnerability, analyze the logs and decide what to do.

That time no longer exists.

Today, while an analyst opens the paper to understand how a vulnerability works, automated systems are already comparing the patch with the earlier code, pinpointing the bug, generating an exploit and distributing it through botnets.

We are no longer talking about days. We are talking about hours, sometimes minutes.

The paradigm has already changed. We are the ones who have fallen behind.

The SOC built on reading logs is finished

A SOC made up of dozens of people watching dashboards, scrolling through alerts and manually correlating events is not a modern model. It is digital archaeology.

When the attack is generated, adapted and executed by machines, it cannot be stopped by a human being reading one line of log at a time.

The problem is not the analysts' competence. It is the speed.

A human cannot compete with systems capable of analyzing thousands of events, testing hypotheses and changing strategy in a few seconds.

The SOC has to become automated and agentic: collecting events, correlating them, investigating, applying mitigations and calling a person only when a decision is truly needed.

The human should not be chasing the logs.

The human should be standing above the system.

Traditional internal auditing is prehistory too

The same goes for the classic model of offensive security.

The white hat's periodic audit, the annual penetration test and the report delivered weeks later photograph an infrastructure that, in the meantime, has already changed.

A manual, occasional check cannot compete with an automated attacker that continuously monitors new patches, new configurations and new exposed surfaces.

Offensive security has to become continuous.

Assets must be tested every day, not once a year. New vulnerabilities must be simulated as soon as they emerge. Configurations must be reassessed at every change.

The traditional penetration test does not disappear, but it stops being the center of the strategy.

It becomes a human check on a process that has to run automatically twenty-four hours a day.

From zero-day to zero-hour

The real transformation is this: the time needed to weaponize a vulnerability has compressed.

A public patch shows what was changed. An automated system can analyze the diff, pinpoint the weak spot and quickly produce a proof of concept.

While the defender is still reading the documentation, the exploit may already have been written, tested and inserted into an automated campaign.

The zero-day is becoming a zero-hour.

And a defense that takes hours to understand what is happening is already a defeated defense.

We no longer need people in front of dashboards

Continuing to hire analysts to add more eyes in front of the monitors does not solve the problem.

Fifty slow people do not become a fast machine.

The new SOC has to be made of automated agents capable of:

  • analyzing events in real time;
  • connecting signals coming from different systems;
  • automatically verifying indicators;
  • applying virtual patching and mitigations;
  • isolating compromised assets;
  • bringing in analysts on the truly critical cases.

This does not eliminate human work. It finally makes it useful.

People must define strategies, assess risk, handle exceptions and take responsibility for decisions. Not spend the day closing repetitive alerts.

The future has already arrived

For years we said that AI would attack infrastructures and other AI would defend them.

It is no longer a prediction.

It is already happening.

Attacks are accelerated by automation, exploits are produced in a few hours and campaigns are adapted faster than a human team can react.

Manual cybersecurity is not destined to become obsolete.

It already is.

The question is not whether the SOC has to change.

The question is how much longer we can afford to pretend the old model still works.

Escrito por Claudio