Five Automation Waves in the SOC and The Pattern the AI Wave Has Not Broken Yet

Five Automation Waves in the SOC

Every wave of security operations automation has promised the same thing: less work and faster response for security teams.

Every wave has delivered genuine innovation. Every wave has also created a new form of operational work that eventually found its way back to the customer.

This isn’t because the technology failed. Each wave solved a real problem. But each also shifted part of the operational burden elsewhere.

That repeating pattern is worth remembering as the industry enters its next phase.

AI is the fifth major wave of SOC automation, and it has the potential to change security operations more profoundly than anything before it. The question is not whether AI will transform the SOC. It already is.

The real question is whether this wave finally breaks the pattern.

At the heart of every automation wave is the same tension:

The vendor sells a capability; the customer buys an outcome.

The gap between the two is where the operational work lives.

A Familiar Cycle

Every major evolution in the SOC has followed a remarkably similar path.

Wave One: Log Collection & SIEM

Centralised security telemetry, correlate events and detect attacks that individual tools would miss.

Detection rules required constant tuning. New applications generated new logs. Environments evolved faster than detection logic could keep pace.

Over time, many SIEMs quietly redefined themselves as compliance-driven log stores with detection features. The detection promise didn’t disappear—it moved to the next wave.

Wave Two: SOAR

Automate repetitive investigation and response. The early phase of overload of alerts and incidents called for automated responses and it defined the era of Playbooks which would orchestrate enrichment, containment and response.

Automation itself required maintenance. APIs changed. Infrastructure evolved. Workflows had to be updated. Playbooks became software projects demanding continuous engineering effort.

Automation reduced operational work. It didn’t eliminate it. The category consolidated rapidly, and SOAR is now largely a capability embedded within broader security platforms rather than a standalone category.

Wave Three: UEBA

Use behavioural analytics to detect attacks that traditional correlation rules missed and others demonstrated genuine value in applying statistical models to security operations.

Behavioural baselines required constant tuning because anomaly is not the same as malicious activity. Operational noise grew alongside the environment, demanding continuous refinement.

The capability survived, but the category largely disappeared as UEBA became another feature within broader security platforms.

Wave Four: MDR

Deliver outcomes instead of technology. Managed Detection and Response gave organisations access to skilled analysts and continuous monitoring without requiring them to build their own SOC.

Customers still validated business context, approved response actions and completed investigations. Fixed-price service models naturally encouraged automated triage and templated escalations.

The vendor delivered detection outputs. The customer often remained responsible for delivering the final operational outcome.

Across four generations of security operations, the pattern remained remarkably consistent.

Why the Pattern Persisted

Three structural reasons explain why.

First, the vendor sells a capability while the customer buys an outcome. Every wave delivered its capability honestly. Every wave also assumed someone would perform the remaining operational work.

Second, every automation layer requires ongoing authoring and maintenance. Rules for SIEM. Playbooks for SOAR. Behavioural baselines for UEBA. Escalation criteria for MDR. Someone has to create, tune and maintain those artefacts over time.

Third, environments evolve faster than automation. Cloud adoption, new identities, SaaS applications and changing attack techniques continually reshape the environment, forcing automation to adapt.

These are not vendor failures. They are structural properties of how security operations are bought and sold.

The AI Wave

Today’s AI-native SOC platforms introduce a fundamentally different capability.

Previous automation waves executed instructions.

AI produces judgement.

Rather than simply following predefined workflows, it can investigate alerts, prioritise competing evidence, generate hypotheses and recommend actions that previously depended on experienced analysts.

That represents a genuine shift in what technology is capable of doing.

But history suggests an important question.

If every previous wave created new operational work, what new work might AI create?

The New Labour Nobody Is Talking About

The answer is unlikely to involve writing detection rules or maintaining playbooks.

Instead, organisations will need to ensure AI systems continue making sound decisions as environments, threats and business priorities evolve.

That means defining organisational context, evaluating investigation quality, validating outputs and ensuring reasoning remains consistent over time.

Regulatory expectations will amplify the challenge. Organisations will increasingly require evidence explaining why decisions were made, how investigations were performed and whether automated actions remain defensible during audits.

These are the operational realities of deploying intelligent systems inside critical security functions.

The important question is not whether this work exists.

It is who performs it.

Will customers build new internal teams to maintain AI reasoning?

Or will vendors absorb that responsibility as part of the managed service?

Breaking the Pattern

The success of every automation wave should be measured not by how much work it automates, but by how much work it permanently removes.

The AI SOC will represent a genuine departure from previous generations only if vendors accept responsibility for more than the automation itself.

That means continuously improving guidance rather than asking customers to maintain it. Monitoring the quality of AI decisions rather than assuming they remain accurate forever. Treating governance, auditability and explainability as core service outcomes rather than optional features. And ensuring human expertise focuses on genuinely complex investigations rather than maintaining another automation platform.

One question: Is AI eliminating the human loop? The short answer is “NO” while AI can be an excellent assistant, it has not yet acquired the status of decision maker especially in security operations. The decisions in security operations are complex and are beyond technology, there are strategic business and cultural angles to them so yes human loop still stays.

What Buyers Should Ask

The most useful questions for an AI SOC vendor are no longer about model size or autonomy percentages.

They are:

  • Who maintains the AI as environments change?
  • Who evaluates the quality of its investigations?
  • Who adapts guidance as threats evolve?
  • Who carries the operational burden over the lifetime of the service?

Those questions reveal far more about the maturity of an AI SOC than any autonomy metric.

A Note on Our Own Position

Nordic SOC is a vendor in this category, and Vokter is our AI SOC. Everything in this article applies to us.

We believe AI should absorb operational complexity rather than create a new generation of specialists to manage it. That philosophy has shaped how Vokter has been designed, from its managed-outcome approach to its emphasis on defensible, explainable investigations.

Whether the industry ultimately breaks the pattern remains to be seen.

If, three years from now, customers are hiring AI SOC engineers to maintain their vendor’s guidance packs and prompts, the pattern held.

If they are not, something genuinely changed.

That may prove to be the real measure of whether AI transformed security operations, or simply repeated history.

About the Author

Harish Shukla, Head of Cyber Security & Managed Security Services at G’SECURE LABS

Harish leads cybersecurity operations across the EU region. With over 17 years of experience in cybersecurity and managed services, he brings deep expertise in security operations, cloud security, compliance frameworks, helping organizations strengthen resilience and achieve measurable security outcomes.

Let’s Talk

    I have read, and consented to the Privacy Policy and Terms of Use.*