Skip to main content

EP249 Data First: What Really Makes Your SOC 'AI Ready'?

  • October 27, 2025
  • 0 replies
  • 14 views

chuvakin
Staff
Forum|alt.badge.img+9

Guest:

Topics: 

SIEM and SOC

 

Subscribe at Spotify

Subscribe at Apple Podcasts

Subscribe at YouTube

Topics covered:

  • We often hear about the aspirational idea of an "IronMan suit" for the SOC—a system that empowers analysts to be faster and more effective. What does this ideal future of security operations look like from your perspective, and what are the primary obstacles preventing SOCs from achieving it today?
  • You've also raised a metaphor of AI in the SOC as a "Dr. Jekyll and Mr. Hyde" situation. Could you walk us through what you see as the "Jekyll"—the noble, beneficial promise of AI—and what are the factors that can turn it into the dangerous "Mr. Hyde"?
  • Let's drill down into the heart of the "Mr. Hyde" problem: the data. Many believe that AI can fix a team's messy data, but you've noted that "it's all about the data, duh." What's the story?
  • “AI ready SOC” - What is the foundational work a SOC needs to do to ensure their data is AI-ready, and what happens when they skip this step?  
  • And is there anything we can do to use AI to help with this foundational problem?
  • How do we measure progress towards AI SOC? What gets better at what time? How would we know? 
  • What SOC metrics will show improvement? Will anything get worse?

0 replies

Be the first to reply!