The Future SOC Will Be Built Around Evidence, Not Alerts

REDSAND | THE CTO FIELD NOTES

By Tim Shelton | Founder & CTO, HAWK Network Defense

For years, security operations have been built around alerts.

An alert fires.

An analyst investigates.

A ticket is created.

Context is gathered.

Evidence is reviewed.

Someone determines whether the alert is real.

Someone decides whether action is justified.

That model made sense when the biggest problem in cybersecurity was visibility.

We needed to see more.

More endpoint activity. More network traffic. More identity behavior. More cloud events. More application logs. More threat intelligence.

So we built systems that could collect more signals and generate more alerts.

And they worked.

Many security teams today are not blind.

In fact, they face the opposite problem.

They can see more than they can operationalize.

The challenge is no longer simply detecting suspicious activity.

The challenge is understanding what that activity means fast enough to act.

That is why I think the future Security Operations Center (SOC) will be built around evidence, not alerts.

Because alerts tell analysts where to look.

Evidence helps them decide what to do.

Why Traditional Alert-Driven Security Operations Are Reaching Their Limits

Alert-driven security operations were designed to identify suspicious events and route them to analysts for investigation.

That remains useful.

But generating an alert does not establish whether a threat is consequential or whether containment is justified.

An alert might indicate that a process executed.

Evidence helps determine whether that process is connected to a known attack path or suspicious sequence of activity.

An alert might indicate that a user authenticated from an unusual location.

Evidence helps establish whether that identity accessed sensitive systems, changed privileges, moved data, or initiated additional activity.

An alert might indicate that exploitation was attempted.

Evidence helps establish whether exploitation succeeded, what resources were affected, and whether containment is appropriate.

These distinctions matter because security decisions have consequences.

An unnecessary containment action can disrupt legitimate business operations.

A delayed containment action can allow an attacker to retain access or expand the scope of an incident.

Analysts need sufficient evidence to distinguish between those outcomes.

Alerts create awareness. Evidence creates confidence.

And confidence is what security teams need when decisions have consequences.

What Evidence-Driven Security Operations Actually Mean

An evidence-driven SOC does not eliminate alerts.

It changes their role.

An alert becomes the beginning of an evidence-gathering and decision process rather than the central unit of operational success.

The investigation should establish:

  • What activity occurred

  • Which identity, endpoint, application, or cloud resource was involved

  • What happened before and after the suspicious event

  • Whether related signals support the same conclusion

  • What business function or asset may be affected

  • What threat intelligence is relevant

  • Whether the activity represents a credible threat

  • What response is appropriate

  • What evidence supports that decision

The goal is a defensible determination that the team can act on.

This requires information from multiple systems, but it does not mean collecting every available piece of telemetry.

More data does not automatically mean better evidence.

The important distinction is whether the information helps establish what happened, why it matters, and what the organization should do next.

That is where the architecture of the SOC becomes critical.

How AI Can Accelerate Security Evidence Correlation

I think this is one of the biggest changes AI can bring to security operations.

Not because AI will eliminate alerts.

It will not.

But because AI can help assemble the evidence behind an alert much faster than an analyst manually moving between disconnected systems.

AI can support investigations by helping to:

  • Correlate endpoint telemetry with related activity

  • Retrieve identity and privilege context

  • Examine process lineage

  • Connect cloud and network events

  • Compare suspicious behavior against relevant threat intelligence

  • Build an incident timeline

  • Identify changes in the environment

  • Surface evidence that matters to the investigation

This does not automatically make every AI-generated conclusion reliable.

The underlying data must be accurate, relevant, and available.

The system must also preserve a way to inspect the evidence supporting its determination.

But when implemented correctly, AI-assisted investigation can reduce repetitive evidence collection and help analysts reach supported conclusions sooner.

That changes what analysts spend their time doing.

Instead of spending much of an investigation collecting information, they can focus more of their expertise on evaluating the situation and its consequences.

Is the activity malicious?

Is it spreading?

Which business process is affected?

What authority exists to contain it?

What happens if we wait?

What happens if we act now?

These are the questions that matter.

And they are difficult to answer from an alert alone.

The Most Important SOC Delays Often Occur After Detection

This is where many security operations centers lose time.

Not at detection.

After detection.

The signal appears, but the organization still needs to determine whether that signal represents a meaningful threat.

That requires evidence.

And evidence is often scattered across tools, teams, logs, tickets, workflows, and institutional knowledge.

The attacker does not wait while that evidence is assembled.

They may continue operating while analysts move between tools.

They may exploit delays while teams debate ownership.

They may retain access while an investigation waits for approval.

They may expand their activity while context is still being collected.

The time between receiving an alert and establishing sufficient evidence can become an important source of operational exposure.

That is why reducing investigation friction matters.

Security teams need to move from signal to supported determination without sacrificing the evidence required for sound judgment.

Why Faster Evidence Matters More Than Additional Alerts

I do not think the next generation of SOC platforms will compete only on how many alerts they generate.

They will increasingly need to demonstrate how quickly they can turn signals into supported conclusions.

What happened?

What evidence supports that conclusion?

What is the likely impact?

What action is recommended?

How confident are we in the determination?

What decision must be made?

Those questions establish a more meaningful measure of operational effectiveness than raw alert volume.

The goal is not simply faster information processing.

It is faster progress toward a defensible security decision.

That is the difference between alert-driven and evidence-driven security operations.

AI in the SOC Must Do More Than Summarize Alerts

AI can summarize alerts.

That is useful.

But it is not enough.

The greater opportunity is to help security teams move from signal to evidence to trusted action.

An effective AI-assisted security operating model should reduce the time required to understand a situation.

It should separate relevant context from noise.

It should make the supporting evidence available to the analyst.

It should show why a recommendation is being made.

It should make escalation easier to justify.

It should connect the investigation to the decision that follows.

And it should preserve sufficient information for subsequent review.

This is especially important as automation becomes more capable.

An automated system may identify suspicious behavior and recommend containment.

But the recommendation needs to be supported by evidence that justifies the action.

An analyst or authorized decision-maker needs to understand what is being proposed, what systems are affected, and what potential operational consequences could follow.

Otherwise, faster automation can introduce a different category of risk.

Action without sufficient evidence is dangerous.

But evidence that arrives too late can also be dangerous.

The future SOC must address both problems.

It must move faster.

And it must preserve trust.

Evidence Makes Security Automation Governable

Evidence is more than a requirement for investigation.

It also supports appropriate authorization and accountability.

Evidence helps determine whether an automated response meets established policy conditions.

Evidence allows analysts to evaluate recommendations.

Evidence helps authorized personnel make timely containment decisions.

Evidence allows the organization to reconstruct what happened after an incident.

These relationships become especially important when automation is permitted to execute actions.

A decision should not depend solely on an unsupported model recommendation.

It should be connected to the relevant signals, contextual information, defined authority, and expected outcome.

The system should also preserve an appropriate record of what was decided and what action followed.

A useful operating sequence is:

SIGNAL → EVIDENCE → CONTEXT → DECISION → AUTHORIZED ACTION → VERIFIED OUTCOME

Each stage serves a purpose.

Signal identifies activity requiring attention.

Evidence establishes the supporting facts.

Context explains their technical and business significance.

Decision determines an appropriate response.

Authorized action ensures the response stays within defined boundaries.

Verification establishes whether the intended security condition was achieved.

This is how AI and automation can support faster security operations without sacrificing accountability.

Why Verification Belongs in an Evidence-Driven SOC

An investigation does not end simply because a containment command was issued.

A response system may report that it successfully submitted an endpoint isolation request.

That does not necessarily prove that the endpoint was isolated or that the attacker lost access through other compromised resources.

An identity may be disabled while active sessions remain.

A network block may be applied to one access path while another remains available.

An incident ticket may be closed before the team establishes whether the intended containment condition was achieved.

Verification provides evidence of the outcome.

It should establish whether the action occurred, whether it achieved its intended purpose, and whether additional response is required.

That does not necessarily establish complete eradication or recovery.

But it gives the organization a stronger basis for determining whether the immediate threat has been brought under control.

The same evidence-driven discipline that supports the decision should also support proof that the response worked.

What the Future Evidence-Driven SOC Should Look Like

The SOC of the future will still receive alerts.

It will still use detection technologies, telemetry, threat intelligence, and security analytics.

But alerts should no longer be the center of gravity.

Instead, security operations should be designed to produce supported decisions and effective outcomes.

I see several important characteristics of that operating model.

1. Evidence Is Assembled Earlier

Relevant data from endpoint, identity, cloud, network, and security systems should be connected as early as practical in the investigation.

Analysts should not need to reconstruct every incident manually from disconnected sources.

2. Context Is Relevant to the Decision

Not every available event is useful.

The investigation should focus on information that establishes what happened, what resources are affected, and what consequences may follow.

3. AI Supports Human Judgment

AI should accelerate evidence collection, correlation, and analysis.

Human expertise remains necessary for uncertain, ambiguous, or consequential decisions.

The goal is to use analysts where their judgment creates the greatest value.

4. Decision Authority Is Defined

Security operations should establish which responses can occur automatically, which require approval, and which must be escalated.

Authority should be bounded, technically enforced, and capable of being restricted when conditions change.

5. Actions Are Verified

The system should not treat a completed workflow as proof of successful containment.

Response effectiveness should be supported by evidence showing whether the intended security condition was achieved.

6. Outcomes Matter More Than Activity

The success of the SOC should not be measured only by the number of alerts received, cases opened, or tickets resolved.

It should also be evaluated by how quickly the organization can establish a reliable conclusion, take appropriate action, and verify the result.

These are the capabilities that can make security operations more effective as threats and technology continue to evolve.

The Real Measure of an Evidence-Driven Security Operations Center

Security teams should increasingly measure their ability to progress from suspicious activity to supported action.

Useful operational questions include:

  • How quickly can relevant evidence be assembled?

  • How often do analysts need to retrieve missing context manually?

  • How consistently can investigations establish a defensible conclusion?

  • How much time passes between determination and authorized action?

  • How often do response actions require avoidable handoffs?

  • Can the organization verify containment?

  • Can it reconstruct the evidence and authority behind the decision?

These measurements connect investigation quality with decision velocity and operational readiness.

They also help identify where additional AI capabilities may create meaningful value.

The objective is not to automate every action.

It is to reduce unnecessary delay while maintaining control over consequential decisions.

REDSAND | The CTO Field Notes

The future SOC will not be defined by how many alerts it produces.

It will be defined by how quickly and reliably it can establish what happened, determine what matters, and take appropriate action.

AI can help security teams reach that point by assembling evidence, reducing repetitive investigative work, and making relevant context available earlier.

But the underlying operating model still matters.

Security organizations need trusted evidence, defensible decisions, clear authority, and verified outcomes.

Because attackers are not waiting for the perfect investigation.

They are moving.

And the teams that respond effectively will be the ones capable of acting with confidence while there is still time to change the outcome.

The future SOC will not be built around alerts.

It will be built around evidence.

Tim Shelton

Tim Shelton is the Founder and Chief Technology Officer of HAWK Network Defense, bringing more than two decades of experience in cybersecurity, exploit research, security engineering, and large-scale security analytics. His work focuses on advancing machine-speed security operations, reducing decision latency, and connecting threat detection to authorized action and verified outcomes.

Through REDSAND | THE CTO FIELD NOTES, Tim explores AI security architecture, autonomous agents, runtime controls, and the engineering principles required to build secure, resilient systems.

https://www.hawk.io/about
Previous
Previous

Agentic AI Changes the Control Problem

Next
Next

Your Incident Response Plan May Have a Decision Problem