On-Demand Webinar

Agentic SecOps Part 1: The SOC Math Problem Hiring Can't Solve

Agentic SecOps
July 21, 2026 6:00 AM
CST
Online
On-Demand Webinar

Agentic SecOps Part 1: The SOC Math Problem Hiring Can't Solve

Detection Strategies

You can't hire your way to scale

Every SOC we talk to has the same math problem.

Security data is growing between 35 to 50% a year at most enterprises. Every new cloud account, SaaS app, identity provider, and endpoint adds another stream. More data means more detections, and more detections mean more alerts. The average SOC now fields around 960 alerts a day, and more than 3,000 at organizations over 20,000 employees. Headcount, meanwhile, is flat. Sometimes it shrinks.

Put those two curves on the same chart, and the story tells itself. One line compounds, the other is flat. The space between them is where every SOC is quietly losing ground. The usual response is to treat that gap as a hiring problem. It isn't, and the most interesting evidence for that comes from the group that spent a decade telling everyone it was.

Security data and alerts compound 35 to 50% a year while SOC headcount stays flat

The industry stopped counting bodies

For years, the standard framing was a talent shortage: not enough people to fill the seats. The single most cited statistic in security was ISC2's global "workforce gap," which climbed past four million unfilled roles.

But here's what changed, and most people missed it. In its 2024 and 2025 studies, ISC2 stopped publishing that number. Not because the shortage was solved, but because the 16,000-plus professionals they surveyed told them headcount was no longer the point. Skills were. In 2025, 59 percent of teams reported critical or significant skills gaps, up from 44 percent the year before. Ninety-five percent reported at least one. Nearly nine in ten had suffered a security incident they trace directly to those gaps.

Read that shift carefully, because it reframes the whole problem. The bottleneck was never the number of people. It's that the expertise that makes a SOC effective, the judgment your best analyst carries, doesn't scale by hiring. You can double the team and still not reproduce the one person who knows what "normal" looks like in your environment.

The modern SOC automated triage by ignoring it

If you want to see what running short on that expertise actually looks like, follow the alerts.

Roughly 46% of the alerts a SOC receives are false positives. Around 62% are never actioned, and close to 40% are never investigated at all. That's not a workflow. It's triage by neglect. The modern SOC has, in effect, already automated its triage by ignoring most of the queue and hoping the one alert that mattered wasn't in the pile it skipped.

And the people doing the work feel it. Seventy-one percent of SOC analysts report burnout, almost half describe themselves as "very burned out," and about 70% of analysts with five years of experience or less leave the field within three years. The expertise you can't hire fast enough is also the expertise walking out the door, and taking its context with it.

The industry already tried to solve this problem, twice

The first attempt to remedy these challenges was the SIEM: centralize the data, run detections in one place. It worked, but then the bill came. At around 100 GB a day, a SIEM runs about $150,000 a year in licensing, and enterprises ingesting terabytes a day now spend into the millions, with costs climbing 30% to 100% year over year as data grows. So teams started dropping sources to control spend, and "centralize everything" stopped being true.

The second attempt was SOAR: automate the response with playbooks. In practice, traditional SOARs top out around 30 to 40% of Tier-1 alerts. Playbooks are brittle. They encode a fixed sequence of steps, break whenever a vendor changes an API, and demand constant maintenance most teams can't sustain. They handle the predictable cases and fall apart on the messy ones, which are exactly the ones that need judgment.

So teams did the next best thing. They wrote runbooks, they built playbooks, and they documented processes so newer analysts could follow the steps a senior one already knew. But that's still manual work. A human still has to read the alert, open half a dozen tabs, check the sender, pull the headers, look up the URL, cross-reference the user's recent logins, then decide. The runbook tells you what to do, but it doesn't do it. Both of the last two attempts made the same mistake in different forms: they moved the data, or they scripted the steps. Neither captured the thing that actually does the work.

What actually doesn't scale

Here's the real problem: the thing that doesn't scale is judgment. Your best analyst's reasoning, how they triage a phishing alert, how they tune a noisy rule, how they run down a compromised account, lives in one head and is available one shift at a time. Documentation and scripts didn't fix that, and hiring can't.

The fix isn't another tool bolted onto the SOC. It's a different operating model entirely: Agentic SecOps. Agentic SecOps means a SOC where the workflows your best people have already figured out don't live in a wiki page. They can run themselves, on your data, under your rules, with a human approving the calls that matter.

That's a completely different question than "which AI copilot should I buy." A copilot waits for someone to ask it something. It's faster typing, not fewer decisions. Agentic SecOps doesn't wait. It watches, acts within the boundaries you set, and hands you the decision only when a decision is needed.

And to be clear, this isn't about replacing analysts. It's about automating the work itself, so every SOC workflow runs the way your best analysts would run it, in the background, all the time. That's the only version of "scale" that survives the math this piece opened with: data compounding, headcount flat. Every SOC workflow, automated, so you can scale your SOC and keep your stack.

The SOC we've all come to know was built for a world with less data and more time. That world is gone, and the last two attempts to automate it only treated the symptom instead of the bottleneck. Over the next three posts, we'll get more specific about why buying more data makes visibility worse, why most "AI for the SOC" can't be trusted to act, and what a workflow built for Agentic SecOps looks like end to end, the same one we'll run live at Black Hat.

Stay tuned for part two of our Agentic SecOps series, where we'll dig into the data visiblity gap.

Get the Latest Resources

Leave Your Data Where You Want: Detect Across Snowflake

Demo Series
Leave Your Data Where You Want: Detect Across Snowflake
Watch

MonteAI: Your Detection Engineering & Threat Hunting Co-Pilot

Demo Series
MonteAI: Your Detection Engineering & Threat Hunting Co-Pilot
Watch
White Paper

Agentic SecOps Part 1: The SOC Math Problem Hiring Can't Solve

Agentic SecOps
July 21, 2026

Agentic SecOps Part 1: The SOC Math Problem Hiring Can't Solve

Agentic SecOps
No items found.

You can't hire your way to scale

Every SOC we talk to has the same math problem.

Security data is growing between 35 to 50% a year at most enterprises. Every new cloud account, SaaS app, identity provider, and endpoint adds another stream. More data means more detections, and more detections mean more alerts. The average SOC now fields around 960 alerts a day, and more than 3,000 at organizations over 20,000 employees. Headcount, meanwhile, is flat. Sometimes it shrinks.

Put those two curves on the same chart, and the story tells itself. One line compounds, the other is flat. The space between them is where every SOC is quietly losing ground. The usual response is to treat that gap as a hiring problem. It isn't, and the most interesting evidence for that comes from the group that spent a decade telling everyone it was.

Security data and alerts compound 35 to 50% a year while SOC headcount stays flat

The industry stopped counting bodies

For years, the standard framing was a talent shortage: not enough people to fill the seats. The single most cited statistic in security was ISC2's global "workforce gap," which climbed past four million unfilled roles.

But here's what changed, and most people missed it. In its 2024 and 2025 studies, ISC2 stopped publishing that number. Not because the shortage was solved, but because the 16,000-plus professionals they surveyed told them headcount was no longer the point. Skills were. In 2025, 59 percent of teams reported critical or significant skills gaps, up from 44 percent the year before. Ninety-five percent reported at least one. Nearly nine in ten had suffered a security incident they trace directly to those gaps.

Read that shift carefully, because it reframes the whole problem. The bottleneck was never the number of people. It's that the expertise that makes a SOC effective, the judgment your best analyst carries, doesn't scale by hiring. You can double the team and still not reproduce the one person who knows what "normal" looks like in your environment.

The modern SOC automated triage by ignoring it

If you want to see what running short on that expertise actually looks like, follow the alerts.

Roughly 46% of the alerts a SOC receives are false positives. Around 62% are never actioned, and close to 40% are never investigated at all. That's not a workflow. It's triage by neglect. The modern SOC has, in effect, already automated its triage by ignoring most of the queue and hoping the one alert that mattered wasn't in the pile it skipped.

And the people doing the work feel it. Seventy-one percent of SOC analysts report burnout, almost half describe themselves as "very burned out," and about 70% of analysts with five years of experience or less leave the field within three years. The expertise you can't hire fast enough is also the expertise walking out the door, and taking its context with it.

The industry already tried to solve this problem, twice

The first attempt to remedy these challenges was the SIEM: centralize the data, run detections in one place. It worked, but then the bill came. At around 100 GB a day, a SIEM runs about $150,000 a year in licensing, and enterprises ingesting terabytes a day now spend into the millions, with costs climbing 30% to 100% year over year as data grows. So teams started dropping sources to control spend, and "centralize everything" stopped being true.

The second attempt was SOAR: automate the response with playbooks. In practice, traditional SOARs top out around 30 to 40% of Tier-1 alerts. Playbooks are brittle. They encode a fixed sequence of steps, break whenever a vendor changes an API, and demand constant maintenance most teams can't sustain. They handle the predictable cases and fall apart on the messy ones, which are exactly the ones that need judgment.

So teams did the next best thing. They wrote runbooks, they built playbooks, and they documented processes so newer analysts could follow the steps a senior one already knew. But that's still manual work. A human still has to read the alert, open half a dozen tabs, check the sender, pull the headers, look up the URL, cross-reference the user's recent logins, then decide. The runbook tells you what to do, but it doesn't do it. Both of the last two attempts made the same mistake in different forms: they moved the data, or they scripted the steps. Neither captured the thing that actually does the work.

What actually doesn't scale

Here's the real problem: the thing that doesn't scale is judgment. Your best analyst's reasoning, how they triage a phishing alert, how they tune a noisy rule, how they run down a compromised account, lives in one head and is available one shift at a time. Documentation and scripts didn't fix that, and hiring can't.

The fix isn't another tool bolted onto the SOC. It's a different operating model entirely: Agentic SecOps. Agentic SecOps means a SOC where the workflows your best people have already figured out don't live in a wiki page. They can run themselves, on your data, under your rules, with a human approving the calls that matter.

That's a completely different question than "which AI copilot should I buy." A copilot waits for someone to ask it something. It's faster typing, not fewer decisions. Agentic SecOps doesn't wait. It watches, acts within the boundaries you set, and hands you the decision only when a decision is needed.

And to be clear, this isn't about replacing analysts. It's about automating the work itself, so every SOC workflow runs the way your best analysts would run it, in the background, all the time. That's the only version of "scale" that survives the math this piece opened with: data compounding, headcount flat. Every SOC workflow, automated, so you can scale your SOC and keep your stack.

The SOC we've all come to know was built for a world with less data and more time. That world is gone, and the last two attempts to automate it only treated the symptom instead of the bottleneck. Over the next three posts, we'll get more specific about why buying more data makes visibility worse, why most "AI for the SOC" can't be trusted to act, and what a workflow built for Agentic SecOps looks like end to end, the same one we'll run live at Black Hat.

Stay tuned for part two of our Agentic SecOps series, where we'll dig into the data visiblity gap.

Resources

No items found.

Build Detection You Want,
Where You Want

Build Detection You Want,
Where You Want

July 21, 2026

Agentic SecOps Part 1: The SOC Math Problem Hiring Can't Solve

Agentic SecOps

Resources

No items found.

Build Detection You Want,
Where You Want

Build Detection You Want,
Where You Want

Product Vision
|
July 21, 2026
|
4 min read

Agentic SecOps Part 1: The SOC Math Problem Hiring Can't Solve

This is some text inside of a div block.

| Author

Data compounds, headcount doesn't. Why the SOC's scaling problem was never a hiring problem, and what Agentic SecOps changes. Part 1 of the series.

You can't hire your way to scale

Every SOC we talk to has the same math problem.

Security data is growing between 35 to 50% a year at most enterprises. Every new cloud account, SaaS app, identity provider, and endpoint adds another stream. More data means more detections, and more detections mean more alerts. The average SOC now fields around 960 alerts a day, and more than 3,000 at organizations over 20,000 employees. Headcount, meanwhile, is flat. Sometimes it shrinks.

Put those two curves on the same chart, and the story tells itself. One line compounds, the other is flat. The space between them is where every SOC is quietly losing ground. The usual response is to treat that gap as a hiring problem. It isn't, and the most interesting evidence for that comes from the group that spent a decade telling everyone it was.

Security data and alerts compound 35 to 50% a year while SOC headcount stays flat

The industry stopped counting bodies

For years, the standard framing was a talent shortage: not enough people to fill the seats. The single most cited statistic in security was ISC2's global "workforce gap," which climbed past four million unfilled roles.

But here's what changed, and most people missed it. In its 2024 and 2025 studies, ISC2 stopped publishing that number. Not because the shortage was solved, but because the 16,000-plus professionals they surveyed told them headcount was no longer the point. Skills were. In 2025, 59 percent of teams reported critical or significant skills gaps, up from 44 percent the year before. Ninety-five percent reported at least one. Nearly nine in ten had suffered a security incident they trace directly to those gaps.

Read that shift carefully, because it reframes the whole problem. The bottleneck was never the number of people. It's that the expertise that makes a SOC effective, the judgment your best analyst carries, doesn't scale by hiring. You can double the team and still not reproduce the one person who knows what "normal" looks like in your environment.

The modern SOC automated triage by ignoring it

If you want to see what running short on that expertise actually looks like, follow the alerts.

Roughly 46% of the alerts a SOC receives are false positives. Around 62% are never actioned, and close to 40% are never investigated at all. That's not a workflow. It's triage by neglect. The modern SOC has, in effect, already automated its triage by ignoring most of the queue and hoping the one alert that mattered wasn't in the pile it skipped.

And the people doing the work feel it. Seventy-one percent of SOC analysts report burnout, almost half describe themselves as "very burned out," and about 70% of analysts with five years of experience or less leave the field within three years. The expertise you can't hire fast enough is also the expertise walking out the door, and taking its context with it.

The industry already tried to solve this problem, twice

The first attempt to remedy these challenges was the SIEM: centralize the data, run detections in one place. It worked, but then the bill came. At around 100 GB a day, a SIEM runs about $150,000 a year in licensing, and enterprises ingesting terabytes a day now spend into the millions, with costs climbing 30% to 100% year over year as data grows. So teams started dropping sources to control spend, and "centralize everything" stopped being true.

The second attempt was SOAR: automate the response with playbooks. In practice, traditional SOARs top out around 30 to 40% of Tier-1 alerts. Playbooks are brittle. They encode a fixed sequence of steps, break whenever a vendor changes an API, and demand constant maintenance most teams can't sustain. They handle the predictable cases and fall apart on the messy ones, which are exactly the ones that need judgment.

So teams did the next best thing. They wrote runbooks, they built playbooks, and they documented processes so newer analysts could follow the steps a senior one already knew. But that's still manual work. A human still has to read the alert, open half a dozen tabs, check the sender, pull the headers, look up the URL, cross-reference the user's recent logins, then decide. The runbook tells you what to do, but it doesn't do it. Both of the last two attempts made the same mistake in different forms: they moved the data, or they scripted the steps. Neither captured the thing that actually does the work.

What actually doesn't scale

Here's the real problem: the thing that doesn't scale is judgment. Your best analyst's reasoning, how they triage a phishing alert, how they tune a noisy rule, how they run down a compromised account, lives in one head and is available one shift at a time. Documentation and scripts didn't fix that, and hiring can't.

The fix isn't another tool bolted onto the SOC. It's a different operating model entirely: Agentic SecOps. Agentic SecOps means a SOC where the workflows your best people have already figured out don't live in a wiki page. They can run themselves, on your data, under your rules, with a human approving the calls that matter.

That's a completely different question than "which AI copilot should I buy." A copilot waits for someone to ask it something. It's faster typing, not fewer decisions. Agentic SecOps doesn't wait. It watches, acts within the boundaries you set, and hands you the decision only when a decision is needed.

And to be clear, this isn't about replacing analysts. It's about automating the work itself, so every SOC workflow runs the way your best analysts would run it, in the background, all the time. That's the only version of "scale" that survives the math this piece opened with: data compounding, headcount flat. Every SOC workflow, automated, so you can scale your SOC and keep your stack.

The SOC we've all come to know was built for a world with less data and more time. That world is gone, and the last two attempts to automate it only treated the symptom instead of the bottleneck. Over the next three posts, we'll get more specific about why buying more data makes visibility worse, why most "AI for the SOC" can't be trusted to act, and what a workflow built for Agentic SecOps looks like end to end, the same one we'll run live at Black Hat.

Stay tuned for part two of our Agentic SecOps series, where we'll dig into the data visiblity gap.

Resources

No items found.