The purpose of this research, sponsored by Crogl, has two objectives. First is to determine the effectiveness of security operations (SecOps) in preventing, detecting and responding to cybersecurity threats. Second is the use and value of AI in organizations and specifically in the Security Operations Center (SOC). Sponsored by Crogl, Ponemon Institute surveyed 649 IT and IT security practitioners in North America who are knowledgeable about their organizations’ SecOps and SOCs.
As defined in the research, SecOps refers to the integration of security practices and IT operations within an organization to improve overall cyber resilience. It involves teams working together to detect, respond to and mitigate cyber threats. This integration streamlines security efforts, enhances threat detection and improves incident response times.
Human analysts are important as a final line of defense in the AI-powered SOC. Human analysts in AI provide context, critical thinking and strategic oversight. While AI automates tasks, identifies patterns, and flags anomalies, analysts can interpret and validate AI outputs, interpret nuanced data and guide strategic decisions.
Sixty percent of respondents say their organizations have a SOC. Of these respondents, 57 percent have deployed AI in the SOC. Respondents were asked to rate the effectiveness of AI in the SOC in reducing threats from 1 = not effective to 10 = highly effective and the effectiveness of the role of human analysts as the final line of defense in the AI-powered SOC from 1 = not effective to 10 = highly effective.
Fifty-two percent of respondents say human analysts are highly effective as the final line of defense in the AI-powered SOC. As shown in this research, the deployment of AI in the SOC is in the early stage and may explain why only 44 percent of respondents say the AI in the SOC is highly effective in reducing threats.
Summary of research findings on the state of SecOps and AI in the SOC
Most security alerts are not detected and investigated. Security alerts are notifications generated when a system or application detects a potential security threat or suspicious activity. Organizations represented in this research have an average of 4,330 security alerts in one day but only an average of 37 percent are detected and investigated. As a result, only 43 percent of respondents say their organizations are effective or highly effective in identifying and responding to security alerts.
The number of security alerts investigated and resolved is a measure of the effectiveness of the SecOps team. Seventy-three percent of respondents measure the SecOps effectiveness in reducing risks. Because of the challenges in being effective in identifying and responding to security alerts, 79 percent say their organizations measure the number of security alerts investigated and resolved. Other metrics most often used are completion of security training and awareness programs (70 percent), compliance with privacy and security regulations and standards (53 percent) and vulnerability management (67 percent).
Cyberattacks are frequent and most involve malicious insiders and phishing. Organizations experienced an average of 16 cyberattacks in the past 12 months. Most of these attacks involved a malicious insider (50 percent), phishing/social engineering (48 percent) and denial of service (41 percent).
Most organizations have an in-house or a partial in-house SecOps team. Seventy-three percent of respondents say their organizations either have an in-house (42 percent) or partial in-house and partial outsourced (31 percent) SecOps team with an average of 8 staff. Only 27 percent of respondents say their organizations outsource SecOps.
More than half of respondents say SIEMs and Data lakes are considered very or highly effective. Seventy-four percent of respondents say their organizations have a SIEM (35 percent) or multiple SIEM platforms (39 percent). Fifty-nine percent of these respondents say their SIEMs are effective or highly effective in responding to security alerts. Seventy percent of respondents say their organizations have a data lake solution (41 percent) or multiple data lakes (29 percent). Of these respondents, 51 percent say data lakes are effective or highly effective in handling data required for detection, investment and response.
Sixty-two percent of organizations represented in this research have adopted AI. Twenty-one percent have AI embedded in cybersecurity, 18 percent have embedded AI in cybersecurity and business processes and 23 percent are piloting AI in cybersecurity.
Organizations that have adopted AI say new tools to monitor AI for business purposes are being deployed. These tools include self-hosted Large Language Models (LLM) (31 percent of respondents), mix of homegrown and vendor provided LLMs, co-pilot and agentic AI (23 percent of respondents) and SaaS-hosted LLM (23 percent of respondents).
To be successful, visibility into an AI’s system lifecycle that includes its development, training data and deployment is very or highly important. Fifty-seven percent of respondents say visibility into the AI’s lifecycle is critical. Only 36 percent of respondents rate the ability of their organization in detecting if AI tools are introducing new, less visible forms of data leakage as high.
Respondents believe AI documentation and consistency is very important for SecOps. Fifty-eight percent of respondents say AI documentation of SecOps tasks is very or highly important and 63 percent of respondents say consistency in AI’s use for security operations is very or highly important.
Organizations need to take steps to minimize third-party AI risks. Using third-party AI expands an organizations’ risk surface because a vendor’s AI weakness becomes their own. This introduces new challenges beyond standard cybersecurity, requiring deeper due diligence, stronger contracts, and AI-specific governance to protect against significant financial, legal, and reputational damage.
Sixty-one percent of respondents are very or highly concerned about third parties using their security data for enriching its AI service and 59 percent of respondents are very or highly concerned that AI vendors will use their data for derivative purposes.
The following findings are for those organizations that have adopted AI in the SOC.
AI in the SOC can make analysts more efficient and improve collaboration among staff. Sixty percent of respondents say their organizations have a SOC. Of these, 57 percent of respondents say their organizations use AI in the SOC. Use cases include reduction in the complexity of security cases to improve analysts’ efficiency and collaboration (54 percent), automatic generation of documentation for complex automated processes (49 percent) and the use of tools that have AI embedded in them (41 percent).
The primary benefits of an AI-powered SOC are to speed up the time to resolve more alerts faster (67 percent of respondents), free up analyst bandwidth to focus on urgent incidents and strategic projects (57 percent of respondents) and improve the ability to triage, investigate and remediate the majority of Tier-1 and Tier-2 alerts (53 percent of respondents).
SOCs and their teams are effective in preventing, detecting and responding to cyber threats. Sixty percent of respondents say their organizations have a SOC. Of these respondents, 61 percent say the SOC is very or highly effective in its ability to gather evidence, investigate and find the source of threats and 58 percent say the SOC’s team is very or highly effective in the ability to detect and respond to threats.
In the SOC, AI can improve compliance with regulations and the ability to meet compliance mandates. When asked how organizations determine the value of AI in the SOC, 50 percent of respondents say it increases the ability to meet compliance mandates, 46 percent of respondents say it increases the SOC’s team’s ability to detect and respond to threats and 44 percent of respondents say AI decreases the cost of cybersecurity operations.
The most important feature in an AI tool for the SOC is its ability to integrate into existing workflows and data (63 percent). AI integration remains a major hurdle for organizations. Sixty-three percent of respondents say the most important feature when choosing AI tools is the ability to integrate into their existing workflows and data. Forty-seven percent of respondents say AI should be consistent and the output predictable. AI tools should enable organizations to meet compliance requirements with documentation to meet audit requirements.
The biggest barrier to deploying AI tools in the SOC is the difficulty in integrating AI into their processes and workflows (50 percent of respondents). This is followed by data dispersed throughout the organization and hard to normalize for the AI, (49 percent of respondents). Another barrier is regulatory and compliance concerns (37 percent of respondents).
To read the rest of this report, click here to visit Crogl.com
Part 2. Key findings
In this section of the report, we provide an analysis of the research. The complete findings are also presented in the Appendix. The research is organized according to the following topics.
- The challenges SecOps faces in preventing, detecting and responding to cybersecurity threats
- The deployment of AI to improve the IT security posture
- Practices to improve the effectiveness of the SOC including AI
- Best practices of high-performing organizations

