EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
Related content
-
Learn how the EY Agentic SOC, built on the CrowdStrike platform, can improve detection and response with real-time cybersecurity.
Read more
Cybersecurity leaders are facing the pressures of a very different threat landscape than even a few months ago. Attackers have adopted AI quickly. They operate faster, scale activity more easily and continuously find new ways to masquerade malicious behavior as normal business activity. Attacks themselves are becoming more complex, moving across identity, cloud, endpoint and other areas of the technology environment, making them harder to detect with traditional security operations. All of this is creating an increasingly difficult reality: the security operations centers (SOCs) that organizations have depended on for years to defend their business are struggling to withstand the speed and complexity of modern threat actors. To combat this new AI threat landscape, more cyber leaders are now exploring a shift to a modern agentic SOC model, often with managed services support, that can introduce greater speed and operational consistency. If this sounds familiar in your organization, there are four important factors to keep in mind as you consider potential changes to your own operating model:
1. Avoid the pitfalls of traditional SOC alert processes
In many traditional SOC environments, analysts now may have to review thousands of alerts every day. Even mature and well-staffed teams can only process a fraction of those. As alert volumes rise, high-risk threats increasingly are becoming buried in the noise, creating new kinds of security challenges:
- Blind spots across the threat landscape
- Delayed response times for important or critical incidents
- Too many false positives that waste time and divert limited resources
- Analyst fatigue and burnout making continued alert management even more challenging
- Inconsistent prioritization of high-severity threats
- Difficulty correlating signals across cloud, identity, endpoint and other domains
As AI helps threat actors find new vulnerabilities in organizations’ environments, along with faster ways to exploit them, the question for cyber leaders now becomes “can our current SOC even keep up?”