IT Brief US - Technology news for CIOs & IT decision-makers
United States
How security leaders should measure AI SOC performance

How security leaders should measure AI SOC performance

Fri, 11th Sep 2026 (Today)
Mitchem Boles
MITCHEM BOLES Field Chief Information Security Officer Intezer

One could argue that the security operations center (SOC) is the most important part of any enterprise organization. SOC analysts work tirelessly to investigate millions of security alerts every year, prevent incidents, and respond to threats that breach defenses. Without this group of security professionals, there's little standing between critical systems and the attackers targeting them. 

Given its importance, it is crucial that we have methods to measure how well the SOC is doing its job. Classic metrics such as mean time to detect (MTTD), mean time to resolve (MTTR), and false-positive and false-negative rates enable security leaders to evaluate performance and identify areas for improvement. But as more organizations embrace the move to AI SOCs,  a model in which AI systems help with alert triage, investigation, and remediation, while human analysts supervise,  we need to consider whether these metrics are enough. There's no difference between a human-led SOC and an AI SOC in terms of desired outcomes, but the journey to those outcomes does differ. A new approach is needed to make sure we're measuring the right things along the way. 

Key metrics for measuring AI SOC effectiveness

Traditional SOC metrics were largely designed to measure operational speed and accuracy: how quickly alerts were triaged, how quickly incidents were resolved, and what real threats were missed. In an AI SOC, those metrics still matter, but they are no longer sufficient on their own. Security leaders also need visibility into how accurately AI systems distinguish real threats from legitimate activity, how reliably they escalate incidents that require human intervention, and how consistently they make decisions.

Several key metrics should be tracked when AI is integrated into the SOC:

  • Coverage: The percentage of alerts that are actually investigated, including low-severity alerts.
  • Escalation Rate: The percentage of alerts that the AI SOC routes back to analysts, which can indicate how effectively AI is handling alerts. 
  • Accuracy: True Positive Accuracy measures AI's ability to correctly identify real threats, and False Positive Accuracy measures AI's ability to correctly dismiss benign alerts as non-threatening.
  • Average Investigation Time: A measure of the time it takes AI to analyse an alert and make a decision. 
  • Average Time to Containment: A measure of the time it takes with AI-powered triage to actually resolve or contain real threats.

These metrics are important to track because they help you ensure your AI-powered SOC is performing as intended. 

From Time-Based to Trust-Based Metrics

Because SOC teams are the line of defence between attackers and critical business resources, shifting more of that security work to AI requires those systems to be at least as reliable as human operators. 

Historically, Tier 1 analysts dismissed a large volume of low-severity alerts as part of their risk-prioritisation strategy. But research shows that about 1% of security incidents stem from low-severity or informational alerts. 

In an AI-powered SOC, much of the Tier 1 work can be shifted to AI agents that correlate multiple alerts, analyze behavior, and more accurately determine which low-severity alerts actually need investigation. Getting to the point where this work is autonomous requires visibility into how well the agents are performing these tasks. 

If an AI agent is dismissing a high number of actual threats or flagging a significant number of alerts that are benign, then that's a clear sign that it needs to be fine-tuned, and that it still requires a high level of human supervision.

A low escalation rate is meaningless if real threats are being dismissed. A 2% escalation rate is not good if it means a significant number of actual threats were incorrectly dismissed before ever being seen by a human. On the other hand, a 10% escalation rate with a higher accuracy rate means analysts are spending additional time reviewing a higher volume of alerts, but fewer real threats are being missed. 

Security teams will need to assess these trade-offs and determine what is acceptable to them based on their available resources and risk tolerance. 

Confidence and trust are key to AI SOC success

The shift to an AI SOC is already underway as companies attempt to meet the scale and speed of AI-powered attacks. The SOCs most likely to succeed in implementing AI will be those with the insights to fine-tune their AI systems until they're performing optimally. 

Tried-and-true SOC metrics continue to be relevant, but on their own, they aren't informative enough to support the future of security operations. Security leaders will need to verify not only how quickly incidents are handled, but also how reliably autonomous systems are making investigative and response decisions.

The future Security Operations Centre will be defined by how confidently organizations can delegate investigation and response to AI systems without increasing operational risk.