From Agreement to Action: What’s Actually Stopping Us?

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Over the course of this series, I’ve laid out the case for a fundamentally different security operating model — one built around Outcome, Judgment, and Execution layers, where AI handles the execution at machine speed, and humans focus on the decisions that actually need them. I’ve argued that the CISO’s role is changing, that human-centric security no longer scales, and that the org chart needs to reflect where AI fits on the team.

Most of the CISOs I talk to agree with all of it. And yet many of them haven’t moved.

This is the piece I wanted to write most, because it’s the one I’ve lived. The gap between agreement and action is not a new phenomenon in security. But with agentic AI, the cost of that gap is compounding faster than it ever has before.

The Gap Is Not What You Think

When I ask CISOs what’s holding them back, I rarely hear “budget.” I rarely hear “we don’t believe in the technology.” I almost never hear “our board said no.”

What I hear is hesitation. And hesitation, in my experience, is not one thing. It’s a collection of smaller, quieter blockers that don’t show up in a slide deck but absolutely show up in the pace of decision-making.

It sounds like this:

“We’re waiting to see how the market shakes out.”

“We need to finish our current platform migration first.”

“We haven’t figured out who owns this internally.”

“I want to do a proper evaluation, and we just haven’t had the bandwidth.”

None of these are unreasonable on their own. But stacked together, they produce the same outcome as saying no without anyone ever having to say it.

Ownership Is the First Problem

In most organizations I’ve worked with, AI adoption sits in an awkward governance gap. Security wants it, IT has opinions about it, data teams think they should lead it, and the CISO knows they need it but isn’t sure whether it is a security or an enterprise technology initiative, or something else entirely.

When nobody steps forward to own the decision, the decision doesn’t get made. It gets deferred into a working group, studied for another quarter, and revisited at the next offsite.” And six months later, the CISO is still in the same position — agreeing that AI is necessary, attending the same vendor demos, and waiting for something to change.

Here’s what I’ve learned: whichever function grasps the nettle first will benefit most. Security is uniquely positioned to lead AI adoption because we already operate under the conditions that make it essential — relentless alert volume, machine-speed threats, and a structural inability to hire our way out. We don’t need permission from another function to solve our own operational challenges. We need to lead.

If security doesn’t step into that role, someone else will make the decisions for us. And they will optimize for their priorities.

Fear of Getting It Wrong

There’s a second blocker that’s harder to talk about: the fear of making a wrong bet.

CISOs are trained to be risk-averse. It’s in the job description. When the AI SOC vendor market is noisy, fragmented, and moving fast — when every vendor is claiming “agentic” and the analyst landscape is still forming — the safest-feeling move is to wait for the market to mature and let someone else go first.

I understand the instinct. I’ve had it. When I was on the practitioner side, the biggest thing that slowed me down was the lack of a clear framework for distinguishing between what was real and what was marketing. Every vendor had a slide that looked like the future. Very few of them could explain what happened when you actually turned it on.

But here’s the problem with waiting: the threat environment is not waiting with you. AI-augmented attacks are accelerating. The gap between your attack surface and your defense capability is widening every quarter you don’t act. And the accountability question — did you fail to adopt capabilities that would have materially reduced your exposure — is already being asked by boards and insurers. Regulators will follow.

Waiting feels safe. It is not.

The Market Has Shifted

Something has changed in the last 6-9 months: the hesitation is starting to break.

A year ago, at InfoSecurity Europe, the conversations I was having were exploratory. CISOs were curious but cautious. They wanted to understand what “AI SOC” really meant. They were doing research, comparing vendors, and trying to determine whether the category was mature enough to warrant a serious evaluation.

This year, the conversations are different. CISOs are coming in with approved budgets and set timelines. Some are skipping the proof of concept entirely and going straight to purchase — a signal that they understand the problem, they’ve done their homework, and they have organizational momentum behind them. The early majority is moving.

The organizations that acted 12 months ago are now operating at a fundamentally different speed. They have AI handling Tier 1 and Tier 2 triage around the clock. They’ve moved analysts out of repetitive ops and into roles where they apply judgment, not just process volume. They’re measuring outcomes, not activity. And they’re doing it with the same headcount — or less.

The question is no longer whether AI belongs in the SOC. The question is whether you’re going to design this intentionally or scramble to catch up.

What the Smallest Step Looks Like

If you’re a CISO who agrees AI is necessary but hasn’t moved yet, here is the most practical advice I can give: stop trying to solve the whole problem at once.

Pick one category of alerts. Something repeatable, consistent, and high-volume — phishing, maybe, or endpoint detections that follow a predictable pattern. Something where the decision criteria are clear and the risk of an autonomous action is low.

This is exactly where the Torq AI SOC Platform starts. Auto Triage ingests your alerts, filters the noise, and surfaces the cases that actually matter. From there, specialized AI Agents handle the investigation and response (within the guardrails you define), while your analysts focus on the judgment calls that need them. You don’t bolt AI onto your existing workflow. You start with an execution layer and build around it.

Set the guardrails, watch the output, and build confidence in the results. Measure what changes: time saved, accuracy, analyst capacity freed up, and then expand. Carvana is auto-resolving 100% of Tier 1 and Tier 2 cases. That’s what the trajectory looks like when you start with the right platform.

You don’t need a 12-month roadmap, a team reorganization, or buy-in from every stakeholder. You need one use case, one quarter, and the willingness to start.

Everything I’ve written in this series — the Outcome, Judgment, Execution model, the org design shift, the accountability conversation, the case that human-centric security no longer scales — it all becomes real when you take that first step.

The Window Is Closing

I want to end this series where I started: with a direct challenge to every CISO reading this.

You agree. I know you do. The data is clear, the technology is deployable, the market has validated it, and the threat environment demands it. The only thing between agreement and action is a decision.

The organizations that design around this model now will have the agility to operate at machine speed when it matters most. The ones that wait will try to bolt it on mid-crisis and wonder why nothing holds together.

The future of the SOC is humans at the edges and AI in the middle. The only question is whether you design that intentionally or let it happen to you.

Don’t let this be the year you watched from the sidelines.

Keep Reading John White’s CISO to CISO Series

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

How CISOs Should Brief the Board on AI in the SOC

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

John White is the Field CISO for EMEA at Torq. A respected security executive with more than 20 years of leadership experience, John previously served as CISO at Virgin Atlantic, where he led a multi-year transformation deploying the Torq AI SOC Platform to modernize cyber operations. Prior to that, he built and transformed security functions for global organizations, including ASOS, Liberty Global, AEG Europe, and KPMG.

I’ve briefed a lot of boards, and I’ve watched plenty of sharp security leaders lose one. The strategy was sound and the spend was justified, but the room still went quiet in the wrong way because the briefing was built for a SOC standup rather than a boardroom.

Every serious conversation about AI in the SOC eventually reaches the board. Whether it lands depends on two things: a platform that can back the claims, and the language you use to make them. After 20+ years on the practitioner side, here are the four frames I’ve watched directors actually respond to, and the words I’d leave outside the door.

If you’ve followed this series, you know the scenario: More than 100 vendors now claim the “AI SOC,” most stop at triage or bolt chatbots onto legacy systems, and the AI SOC Apocalypse Manifesto laid out how to tell the real platforms from the pretenders. The boardroom is where all of that noise turns into a budget decision. Brief it well, and the platform you chose becomes an obvious yes. Brief it badly, and you hand the room a reason to wait another year, while attackers keep moving at machine speed.

Frame 1: Value and ROI

Boards don’t fund security. They fund business outcomes, and your AI SOC story has to connect to value creation as tightly as it connects to risk. The question in the room is simple: what do we get, and what does it cost?

So give them the all-in numbers, framed as risk-adjusted ROI. In plain terms, that’s three things: 

  1. What the AI SOC delivers (faster containment, more threats handled, capacity recovered without new hires)
  2. What a breach would cost the business if our controls fail
  3. What we spend to close that gap while keeping the business fast

Don’t frame it as money saved. Adding AI agents rarely means cutting analysts, so the honest story is one of incremental returns. For the extra you invest, how much more do you get back in threats handled, time to contain, and work closed within SLA? The capacity you free up gets redeployed into higher-value work, and that redeployment is its own line of value. Measured that way, security spend reads as protection for the bottom line, not a tax on innovation.

The line I’d use: “Here’s the value our AI SOC creates, here’s what a failure would cost us, and here’s what we spend to keep moving fast safely.”

Frame 2: Strategic Focus

Most boards have sat through a dozen AI demos and watched none of them reach production. They know pilot purgatory when they see it, and their patience is thin. Don’t walk in with a menu of experiments. Walk in with a short, ranked list of high-impact commitments tied to what the business already cares about.

In the SOC, that means being honest about where AI earns its keep — autonomous triage and response on the high-volume, time-sensitive work — and where it’s merely table stakes. Governance effort should scale with impact: an agent that can contain a host or disable an account deserves board-level attention; one that drafts a summary doesn’t. Showing the board you’ve drawn that line demonstrates focus rather than FOMO.

The line I’d use: “We’ve pointed AI at the few SOC outcomes that move the needle, and we govern each one in proportion to what it can touch.”

Frame 3: Risk Appetite and Governance

This is the frame that may be the most consequential. AI has crossed a line our governance habits haven’t caught up to: it moved from suggesting to executing. It triggers live workflows, queries production systems, and takes actions that affect the business, sometimes before a human reviews the output. Once a system acts, governance has to graduate from a static PDF policy to active permissioning — who can touch what, under which approvals, with what rollback.

The framing that works in the room is autonomy as a dial, not a switch. You widen it as trust builds: start with low-risk, high-volume processes, verify the outcomes against what a good analyst would have done, and expand layer by layer. That measured, risk-based approach is exactly what boards and auditors want to see.

Give the board the risks in plain language: data leakage, model abuse, integrity failures, model supply-chain exposure, and compliance pressure as rules, such as the EU AI Act’s high-risk requirements, take effect in August 2026. Then show the guardrails are formal: documented as policy, operationalized in the platform so they’re enforced automatically, and reviewed on a set cadence — not a set of good intentions in a Slack channel. 

Expect the board, and later the auditors, to get specific, so have the answers ready: What due diligence did we apply? Have we risk-assessed each process we’ve automated? Do we understand the data involved and the regulatory requirements around it? How do we evidence that what’s in place is working? The point that lands: as autonomy goes up, blast radius goes up, so governance has to scale with it instead of lagging behind.

The line I’d use: “As our AI started taking action, we tightened the guardrails to match: scoped permissions, human approval on high-impact moves, and a rollback for everything it does.”

Frame 4: Accountability and Ownership

The last question is the shortest: Who owns this? Boards want a single accountable owner and unmistakable role clarity across leadership. In nearly every AI incident I’ve tracked, the root cause wasn’t a purely technical failure. It was three executives in a room, each assuming the problem belonged to someone else. When it goes public, that confusion becomes the headline. The story isn’t “the model got it wrong.” It’s “no one was in charge.”

So bring a clean RACI. The business owns outcome and use-case risk acceptance; security owns the controls and monitoring; legal owns regulatory alignment; the AI solution owner sets standards and lifecycle governance; and the board owns oversight and risk appetite. For the SOC specifically, be explicit about who owns an autonomous agent’s actions, who reviews them, and how an escalation reaches this board.

The line I’d use: “Here’s exactly who owns the AI’s decisions, who reviews them, and how an escalation reaches this board.”

The Language to Leave Out

The fastest way to lose the room is to brief the board the way you’d brief your team.

Drop the jargon. “Agentic,” “LLM,” “SOAR,” product names, model names — none of it survives contact with a board, because directors don’t buy architecture; they buy outcomes. Drop the vanity metrics, too. Raw alert volume and integration counts measure how busy you are, not how protected the business is. And go easy on the superlatives. “Fully autonomous” and “revolutionary” invite skepticism faster than they build confidence.

Before any capability comes out of your mouth, translate it into risk, dollars, or defensibility. If it doesn’t map to one of these, it doesn’t belong in the room.

A Briefing That Lands in Three Slides

If you want a board briefing structure you can reuse, this is the one I keep coming back to:

  1. The risk. Machine-speed threats against human-speed response, in business terms.
  2. The move. An AI SOC that reduces exposure, expands capacity, and stays defensible.
  3. The proof. Your own before-and-after numbers — time-to-contain, capacity recovered — and the governance that backs them.

The AI SOC Decision Underneath the Briefing

The board conversation isn’t really about whether to adopt AI in the SOC. Machine-speed threats made that call for most of us already. It’s about which platform earns the risk, capacity, and defensibility story you’ll tell in that room.

This is where the AI SOC Apocalypse Manifesto‘s test follows you into the boardroom: If it can’t take action, it’s not an AI SOC. A triage-only tool can’t honestly promise a board faster containment, because it stops at the verdict and hands the real work back to your team. The same pretenders that look fine in a demo fall apart the moment a director asks, “So what happens after the alert fires?”

A true AI SOC gives you all of these frames at once. It reduces exposure by taking action across the full threat lifecycle. It expands capacity by handling the repetitive work, so your people can focus on judgment. And it stays defensible because every decision is grounded, logged, and reversible. That’s the platform that lets you walk into the boardroom with a story directors say yes to, and it’s the bar this series has held every “AI SOC” up against from the start.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Fal.Con 2026 Recap: CrowdStrike Finds Threats, Torq Finishes Them

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

The Torq team headed back to Vegas for CrowdStrike’s Fal.Con conference this week, and it quickly became clear that the conversation has moved past whether AI belongs in the SOC. This year, everyone wanted to know what happens after a detection fires and who actually closes the case.

That question is the reason Torq and CrowdStrike fit together so well: CrowdStrike finds threats, and the Torq AI SOC Platform finishes them. Here’s what stood out from the week.

The Gap in the Current SOC Model

We said it last year, and it was even more true this year. There are too many alerts, too few analysts, and too many threats slipping through the gap between the two. Detection has never been better. Closure is where teams still drown.

What changed in 2026 is the noise around the fix. The market is now crowded with “AI SOCs” that stop at triage — they summarize an alert, maybe suggest a next step, and hand it back to a human. That is not finishing the job. A CrowdStrike Falcon detection deserves a platform that carries it all the way from alert to closed case, automatically, and that was the bar everyone at Fal.con was measuring against.

What Everyone Was Talking About at Fal.Con 2026

Four themes came up at Torq’s Fal.Con booth.

  1. Finishing the job, not just flagging it: A CrowdStrike Falcon detection flows straight into Torq Auto Triage, then investigation, then response, then a closed case, with prebuilt CrowdStrike steps and no manual handoff in between. Watching an alert close itself is a different demo than watching one get summarized.
  2. Grounding agentic decisions in your SOC’s reality: Beneath Torq’s AI Agents sits the Torq SOC Brain™, the layer that makes autonomy trustworthy: the Context Graph models your environment, Torq Recall draws on your case history from day one, and Torq Reflex learns your team’s judgment over time. It is the difference between a platform that starts every shift from zero and one that remembers.
  3. Turning autonomy into a dial: Socrates orchestrates Torq HyperAgents™ with transparent, auditable reasoning and analysts on the loop. The point that landed: autonomy is a dial you widen as trust builds, not an all-or-nothing switch.
  4. Bridging the SOC and the rest of the stack: Torq sits across CrowdStrike Falcon and other data sources to correlate, act, and manage data across the whole environment, not just one console. For teams running more than one data lake, that was the unlock.

Torq + CrowdStrike: Better Together

The Torq and CrowdStrike partnership runs deep. Torq’s AI SOC platform natively integrates across CrowdStrike Falcon detections, incident response, and vulnerability management with nearly 100 pre-built CrowdStrike steps ready to embed in Torq HyperAgents. There is no manual handoff between CrowdStrike finding a threat and Torq closing the case.  

While Falcon Fusion automates inside the CrowdStrike ecosystem, Torq orchestrates those signals across the entire security stack — spanning identity, cloud, email, and ticketing. A Falcon detection triggers endpoint containment and then coordinates action wherever else it needs to go across the entire SOC.

Above the integration sits Socrates, Torq’s agentic AI SOC orchestrator that reasons through an investigation, plans next steps, and closes nearly 95% of cases automatically. But the entire action plan still runs on Falcon-native data from detection to remediation: 

  • Detection: Falcon Next-Gen SIEM telemetry via CrowdStrike trigger
  • Investigation: Natural language hunting over Falcon telemetry through a Torq NGSIEM query agent
  • Response: Falcon Real Time Response commands executed from inside Torq
  • Vulnerability prioritization: CVEs from Falcon Exposure Management scores against CISA and NIST

Every alert triggered by CrowdStrike is fed into Torq Auto Triage for filtration and prioritization, and every security case gets AI case summaries, agentic investigation, and a full audit trail with explainable reasoning. The agentic decisions are based on the Torq Context Graph, building on Falcon telemetry with a real grounding in what’s true about the entire environment in that moment, and each alert allows the Torq AI SOC Platform to learn over time and produce more accurate responses. 

The Torq and CrowdStrike partnership is the difference between a detection and a defensible outcome, with:

  • 60-second average triage time
  • 60x increased triage velocity
  • 10x faster response
  • 95%+ of Tier 1 work auto-remediated
  • Near-real-time case management on CrowdStrike data

Onstage: What a Unified AI SOC Actually Looks Like

I had 20 minutes on the Fal.Con theater stage this year, and I used them to unpack a finding from Torq’s 2026 AI SOC Leadership Report: 94% of security teams now use AI somewhere in the SOC, the average team runs seven different AI tools, and 85% still say they want something different. 

During the discussion, we talked about the tension in those data points. AI adoption is high, and so is the confidence, but most teams still aren’t satisfied. The reason is that most “AI SOC” tools stop at triage, so teams keep adding another one to cover the next gap until they end up with disconnected solutions that aren’t seeing the full picture, or worse, shelfware. 

The data shows that it all comes down to trust and transparency in AI decisions. CISOs and security leaders need to see why AI reached a decision and how it got to that point before trusting it to actually act on the next one. When we asked those same CISOs what specifically they were looking for, the results were clear:

  • 92%: Continuous learning & adaptation to attack patterns
  • 90%: Explainable AI decisions
  • 89%: End-to-end SecOps: triage to remediation 
  • 89%: Autonomous response actions (e.g., containment, remediation)
  • 86%: Full platform integration

The answer: a unified AI SOC platform.

I walked through what transparent, end-to-end agentic SecOps actually requires — carrying an alert from detection through remediation on one platform — and how enterprises like Carvana, Valvoline, and Kenvue are operationalizing it in production today, using the Torq AI SOC Platform. 

See Torq + CrowdStrike in Action

Detection isn’t the hard part anymore. The advantage is in closing the case at machine speed, with a full audit trail behind every decision. CrowdStrike finds it. Torq finishes it. If we missed you at the booth, we’ll show you what that looks like on your own stack, running on your Falcon data.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

From Alert Factory to Decision Engine

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

More Tools Never Fixed the SOC: The Bottleneck Was Never Visibility

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

David Melamed is Head of Emerging Technologies at Torq. He joined through Torq’s acquisition of Jit, which he co-founded and has led as CTO since 2020, building agentic security on a production Context Graph. A cloud security veteran with 20+ years of experience, David previously held senior technical roles at Cisco (via the CloudLock acquisition) and MyHeritage.

Odysseus left Troy with a fleet and reached Ithaca with nothing, having lost every ship to the sea. While the war was won by force, the journey home was won by wits, and ultimately the fleet barely mattered.

Most security operations centers are still running their SecOps voyage the way Odysseus ran the war: more tools, more force, more signal. It is the wrong instinct, because the SOC bottleneck was never how much you can see. It is how fast you can decide.

You already agree with this. That is the problem.

Of course more tools won’t fix the SOC. Everyone knows that. “Tool sprawl” and “alert fatigue” have been on conference slides for a decade, and no security leader would defend buying their way to maturity out loud.

And yet the same people who nod along will buy another tool the next time a new threat class appears, stand up another console, and still report their program by how many detections fired rather than how many good decisions got made. A claim everyone repeats, but no one acts on, is not a consensus. It is a collective blind spot.

Tools are not the enemy, and a real coverage gap deserves a dedicated tool. The failure is reaching for a purchase when the real constraint is decisions, a move leaders may still knowingly make because a purchase is a single defensible act, and the system rewards visible action over structural change.

The Math Stopped Working

The first symptom is noise. Enterprise SOCs field thousands of alerts a day, and because the average SOC now runs seven AI-powered tools, with 80% of teams relying on disconnected point solutions, the same event often fires as duplicate alerts across several platforms with no shared context. 

Most teams named false positives their single biggest detection challenge, and the rate is rising every year. That is the point, not a footnote. The flood is not raw blindness; teams can see plenty. But they lack the capacity to handle incoming alerts and make decisions fast enough to matter and with enough confidence to close the related case: is the suspicious PowerShell on a finance laptop an intruder or the IT team? Nearly two-thirds (62.5%) say they are simply overwhelmed by the volume of data.

The attacker is not waiting. Verizon’s 2026 Data Breach Investigations Report found that for the first time in 19 years, exploitation of vulnerabilities overtook stolen credentials as the top initial access vector, rising to 31% from 18% the year before, while breaches involving a third party climbed to nearly half of all cases. Verizon’s own read is blunt: the speed at which known vulnerabilities are now weaponized, accelerated by AI, risks a capacity crisis for security teams. The inflow is accelerating faster than any hiring plan can keep up with.

The consequence is not just wasted effort; it is lost coverage. Most analysts spend time manually sorting low-value alerts that should have been filtered upstream, ultimately leading to slow responses: about a third of teams (32.8%) take hours rather than minutes to respond to a threat. Hours are a losing trade against the velocity Verizon just described.

There is an easy answer on the market, and it is the wrong half. Speeding up triage is the win every tool sells, but automation that acts faster without proving when it is right does not remove risk. It simply relocates risk from a slow human to a fast machine no one has taught you to trust. Speed is not the hard problem. Earned trust is.

The Second Symptom Is Human

The other half of the equation is the people, and it is not fixable by hiring, because you cannot hire fast or cheaply enough. 

The ISC2 2025 Cybersecurity Workforce Study, drawn from more than 16,000 practitioners, found that a third of organizations lack the resources to adequately staff their security teams, that skills gaps are now nearly universal, and that 72% of professionals believe cutting security staff materially raises the likelihood of a breach. The talent you do have does not stay: SANS found that 70% of analysts with five years or less of experience leave their roles within three years.

So the loop closes on itself. Volume overwhelms the team, the team burns out and turns over, institutional knowledge walks out the door, and the next analyst inherits an even larger backlog. You cannot hire your way out at the speed or price the math requires. The point is not fewer analysts; it is more decisions per analyst: people spending their hours on judgment calls only a human should make, instead of clearing queues a machine could clear.

You Can See It. You Cannot Assemble It Fast Enough.

It is tempting to call all of this a visibility problem. It is not, and the distinction is the whole point of this series.

Most SOCs are not blind. A great deal of telemetry exists, spread across dozens of consoles. But two things make “we can see it” a false comfort. First, raw data is not always easy to query in the moment, and the context that actually settles a decision often lives entirely outside the security stack. Confirming whether a flagged user is on approved leave means reaching into an HR system. Confirming whether that odd remote login was really an employee can mean pinging them directly. None of that is a detection feed, and none of it is one query away.

Second, even when the evidence is all technically available, someone has to assemble it. An analyst working on one alert pulls evidence from several tools, enriches the indicators, and checks by hand whether this signal connects to something the team has already seen, one pane of glass at a time. 

Torq’s 2026 AI SOC Leadership Report, featuring 450 security leaders, puts a number on that bridging work: Analysts spend 8.6 hours a week validating and reconciling AI outputs across disconnected tools. That isn’t lost time. AI took over the old execution work, and 9 in 10 leaders say it has improved SOC workload. Those 8.6 hours are the new judgment layer.

The catch is where the hours go. Reviewing clear, explainable reasoning is time well spent. Stitching partial answers together across disconnected tools is not. Same 8.6 hours, and the difference is platform design. So a phishing verdict that should take minutes can sit for hours, not because the evidence is missing, but because assembling it is slow.

That is not a gap in what the SOC can see. It is a gap in how fast a human can gather scattered context, some of it outside the security tools, into a single judgment, and how little of that judgment survives the next shift change. Which puts manual correlation squarely on the decision side of the ledger, not the visibility side, and makes it one of the most expensive line items on that side.

The Bag of Winds

Let’s return to the Odyssey for a moment. A day from home, Aeolus gives Odysseus a bag holding every storm wind, so only a fair breeze carries him towards his home in Ithaca. In sight of the shore, his crew opens it, certain it hides treasure. The freed winds blow the ship all the way back out to sea. The gift was real, but it worked only while one condition held; the moment reality stepped outside it, the tool did not just stop helping — it undid the progress already made.

That is the signature of static playbook automation. It executes the steps a human mapped in advance, so it runs beautifully while an incident matches the script and fails the moment one does not — quietly, at the worst time. Automation itself is not the issue here. The problem is that deterministic-only automation, where every branch is pre-mapped by a human, has no answer for anything unmapped. The fix is not less automation; it is automation that can reason rather than replay a fixed script. 

But adaptive automation brings its own failure mode: a confident wrong answer. So the hard part is not the reasoning; it is proving when to trust it. (But that is the focus of a later post; I will get back to it).

Zoom out, and the pattern repeats. SIEM promised that centralizing the logs would surface the answers, and delivered more signal with a search problem. SOAR promised that automating response would let humans step back, and delivered brittle playbooks to maintain. XDR promised cross-domain correlation and delivered real value, but still left a human to decide what each correlated case means. Each added capability downstream of the real SOC bottleneck, so each moved the constraint rather than removing it. Automate the response, and the bottleneck moves to triage. Centralize the logs, and it moves to investigation. The decision was always the part that did not scale.

The SOC Bottleneck Was Never Where You Were Spending

The honest test of any security investment is simple, and you can try it at home: Does it increase the number of correct decisions your team can make in a day, or does it just increase the number of things your team has to decide about? 

Most of what the industry sold did the second while claiming to do the first. The tell is that more than half of teams still do not track mean time to detect or mean time to respond at all. The metric that would actually expose the problem is rarer still: time to decision — the gap between an alert arriving and a verdict someone will stand behind — as well as time to close the loop. Almost no one measures it. This series will argue that this, not visibility, is the binding constraint, and it will try to earn that claim post by post rather than assert it.

This is why buying the next tool out of anxiety can feel less like navigation than like adding one more ship to a fleet the sea will take anyway. The capability accumulates. The stack grows. And the thing that actually determines whether you get home, the capacity to turn scattered evidence into a decision to close, escalate, or contain, at the volume the sea throws at you, barely moves. 

The cheapest first move is not another tool; it is a number: Start measuring time to decision, because you cannot fix a bottleneck you have never put a number on.

Where This Series Goes

Troy fell to force. Ithaca was reached by wits. The rest of this series is all about the wits: how to define maturity by the quality of decisions rather than the size of the arsenal, what changes when reasoning enters the loop, how to let automation act only when it has earned the right, and how to govern it so autonomy strengthens the SOC instead of becoming its next attack surface.

None of that means visibility never matters. Real coverage gaps are real, and sometimes a new tool is the right call. The point is narrower and more useful: for most SOCs, the next unit of value is not another feed of signal; it is the capacity to turn the signal you already have into decisions, faster and more reliably, at scale. That is the voyage. Everything else is just another ship in a fleet the sea is waiting to take.

Next in this series: Why the most mature SOC in your peer group is not the one with the most tools, and how to measure the difference.

For the data behind the shift this series is built on, the 2026 AI SOC Leadership Report captures how 450 security leaders are rethinking tooling, trust, and the decisions that actually move their programs forward.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

How FICO and Other Financial Institutions Run an AI SOC with Torq

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Financial institutions are some of the hardest environments to secure. They hold the data attackers want most, they run payment rails that a breach can freeze, and they answer to the most overlapping set of regulations in any industry. When one is breached, the damage runs past exposed records into systemic risk and lost customer trust.

The average financial-sector data breach reached $5.56 million in 2025, second only to healthcare and well above the $4.44 million global average. The attacks keep climbing. Nation-state groups tripled their pace against the sector and stole more than $2 billion in crypto over the past year. Over a third of financial services incidents now start with social engineering, and confirmed ransomware in the sector rose about 30% from 2024 to 2025, with the first quarter of 2026 up 76% year-over-year. AI is in the mix now too, showing up in 16% of breaches through automated phishing and deepfake impersonation.

The threat is obvious. Keeping up with it is where the traditional SOC model falls short, and where AI-driven financial services SOC automation earns its place.

Why Financial Services SOCs Are Under Pressure

Most financial institutions run more security tools and get more alerts than any team can work through by hand, and the compliance load only adds to it. Analysts wake up to a flood of alerts, interpret them manually, gather context across disconnected systems, and run response steps one tool at a time. That worked until the volume outpaced the team, which in finance it already has.

Slow response is what makes the gap between alerts and capacity expensive. Across industries in 2025, organizations took an average of 241 days to identify and contain a breach, and the ones that ran past the 200-day mark cost $5.01 million on average versus $3.87 million for those caught sooner. For a bank, the longer an attacker goes undetected, the higher the odds of a frozen payment rail or a fraudulent wire.

Plenty of institutions turned to legacy SOAR to close the gap and found it added work instead of removing it. Playbooks pile up, each one tied to a couple of integrations, and the maintenance load lands on the detection engineering team. The platform ends up recording manual effort rather than reducing it. That’s a big part of why 85% of security leaders now say they want a single, unified platform they can trust. AI-driven financial services SOC automation, done right, is how they get there without adding headcount.

What Torq Does Differently

The Torq AI SOC Platform uses agentic AI and Hyperautomation to run the entire threat lifecycle (triage, investigation, response, and remediation) under your team’s direction, with every decision grounded in context, logged, and reversible. For financial institutions, Torq does three things that matter most.

  1. Torq acts across the full lifecycle. Most tools marketed as an “AI SOC” stop at prioritizing an alert and hand the real work back to a human. A true AI SOC carries the alert through to resolution and only escalates to a person when human judgment is needed. In finance, that shortens the time between when an attack starts and when it’s stopped, and it leaves a defensible record of every move.
  2. Compliance and auditability are built in. Financial services operate under PCI DSS, SOX, GLBA, FFIEC guidance, and SEC cybersecurity disclosure rules, with the EU’s Digital Operational Resilience Act (DORA) now fully applicable to financial entities and the EU AI Act’s high-risk requirements taking effect in August 2026. Torq builds audit-ready evidence into every agentic action. Torq HyperAgents™ log their full reasoning chain, and native case management keeps a full chain of custody, so daily operations become a running compliance record instead of a pre-audit scramble.
  3. It layers onto the stack you already run. With more than 400 integrations across tools like CrowdStrike, Microsoft Sentinel, SentinelOne, ServiceNow, and Wiz, Torq unifies response without a rip-and-replace. Where an integration doesn’t exist, teams prompt the Torq Socrates™ Agentic Builder in natural language to quickly build it.

Together, that lets financial institutions automate their most critical, highest-volume work: fraud and wire-transfer defense, phishing triage and containment, ransomware response, and identity and access management, all with the transparency and control a regulated environment demands.

What It Looks Like in Practice: FICO

FICO, the global analytics and financial services company, shows what happens when a financial institution moves to a real AI SOC. Its 24/7 global SOC had been running on a legacy SOAR where 95% of the work inside its playbooks was still done by hand. The team needed integration depth, automation reach, and a real support partnership, and moved to the Torq AI SOC Platform to get all three.

The migration was scoped at 90 days and delivered in about half that time, with more than 100 playbooks moved and consolidated, many collapsing from 10 steps down to a single automation that produced the same output. Today, FICO’s SOC runs on Torq end-to-end, from autonomous phishing investigation to 24/7 monitoring across teams in North America and Asia, with compliance evidence packaged for every workflow.

The results line up with what most financial institutions are after:

  • A 99.4% reduction in MTTR, from more than 150 hours to under an hour in nine months.
  • 75% of cases closed by automation, 15 percentage points past FICO’s internal target, with analyst time concentrated on the cases that need human judgment.
  • Phishing response from about three days to under 30 minutes, as phishing workflow automation went from 60% to 95%.
  • A clean audit record across PCI DSS and country-specific cycles since the migration, with no case where Torq lacked the documentation an auditor asked for.

“When another security leader asks me whether the move from XSOAR to Torq was worth it, I tell them three things. We have the integrations we need, and when we don’t, we build them. We can run our own AI models inside our own workflows. And the support. The Torq team is in our standup every single week.”

– Ernesto Ugalde, Senior Manager of Detection Engineering at FICO

The Takeaway on AI-Driven SOC Automation for Financial Services

Financial institutions everywhere face the same squeeze: machine-speed attacks, rising regulatory pressure, and SOC teams that can’t scale by hiring.

What actually helps is an AI SOC that acts across the full threat lifecycle, works with the stack you already own, and can prove every decision to a regulator or a board. Another point tool or a repackaged SOAR won’t get there. That’s what Torq built, and it’s already running in production across some of the most demanding financial environments.

FICO is one of them, and its results show what that looks like in practice.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Auto Triage with a Brain 

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Most agentic triage solutions hand you a verdict and stop right there. Maybe you get an alert ranking, maybe a severity score, maybe some light investigation, but you, as the analyst, still have to do the cleanup manually. There is still a mountain of evidence that needs to be gathered by hand, and a mountain of cases to dig through on your own. If you’re lucky enough to have cases created for you, great, but you’re still the one logging back into different security solutions to close alerts, tune configurations, and, most importantly, take action. 

Whether you work in an emergency room or in a Fortune 100 enterprise security operations center, triage, by definition, tells you what needs attention. The limitation of a triage-only solution in SecOps is that you won’t have visibility into the overall scope of threats or what your team decided the last time a specific indicator of compromise appeared in your environment. 

That is why enterprise organizations need a complete, end-to-end AI SOC Platform. Want to hear more about what that looks like? Check out:

Clearly, the AI SOC is one of my favorite things to talk about! But today, we are going to take a turn and actually talk about triage. Not your standard, LLM-wrapped chatbot — but true, agentic auto triage with a brain… Torq Auto Triage. 

What Agentic Triage Should Actually Deliver

Here’s the thing about triage: It was always meant to be a compromise. The reason triage exists in the first place is that human analysts don’t have the bandwidth to handle deep investigations into every single alert at enterprise scale, so the triage step was born to differentiate which alerts were worth investigating and which weren’t. 

The problem is that most triage-only tools baked that same compromise into their solutions. They applied agentic AI to the problem (too many alerts) but replicated the same old outcome (prioritizing only the most critical alerts). 

But using AI to solve the problem means we don’t have to accept the same logic. With AI on our side, “triage” now can, and should, go much deeper than surface-level filtering. 

When an alert enters the SOC, the analyst needs a complete picture of what happened, what it means in the context of the organization, and what the right next move is before anyone has to look at it. Sometimes, the move is still to flag it as a false positive and remove it from the queue. Other times, the correct flow is immediate escalation to a Tier 3 analyst or incident responder for critical action. 

But between the obvious false positives and the critical escalations lies a bulk of ambiguous alerts that require investigation to resolve. And that middle ground is where Torq Auto Triage shines. 

How Torq Auto Triage Works

Torq Auto Triage applies organizational context, threat intelligence, and security case history to every single alert it receives, delivering increasingly accurate verdicts and suppressing noise. It is fully integrated with any of the near-limitless security solutions found in your SOC and, most importantly, into the Torq AI SOC Platform to drive deeper investigation, containment, and remediation actions. 

Mean time to triage is 60 seconds, and customers running Torq Auto Triage report a 97% reduction in EDR alert noise and a 60x improvement in triage velocity. 

Every alert that Torq Auto Triage ingests is normalized to the Open Cybersecurity Schema Framework (OCSF), with observables such as IPs, domains, file hashes, and user identities extracted immediately upon arrival. It then enriches each alert with OSINT and commercial threat intelligence, as well as your organization’s historical case data, before any verdict is even made. This is completely out of the box, meaning there are no manual enrichment playbooks or workflows to maintain. 

From there, Torq Auto Triage weighs the observables and attack stage against your SOC’s history of similar activity — using Torq Recall to drive exact, deterministic observable matching and Torq Reflex to align with your SOC’s actual historical judgment calls — before coming to a verdict, all in under 60 seconds. 

Each verdict includes a severity score, MITRE ATT&CK mapping, full agentic reasoning logs, and recommended next steps. To ensure VIP users are always treated as critical, regardless of what probability models and agentic reasoning might say, deterministic guardrails created by your team are always running in parallel and baked directly into Torq Auto Triage. 

The Verdict Is Just the Beginning

Once a verdict is made with Torq Auto Triage, there are a few paths forward in the Torq platform. True positives automatically become cases in Torq Case Management, with all the evidence, context, and next steps already assembled. The verdict is immediately encoded in the Torq Context Graph, visible for reference in both the Torq Auto Triage alert and the case itself. This means that, regardless of whether the case is assigned to a human analyst or handled by Torq HyperAgents™, neither starts from scratch. 

Non-malicious findings do not become cases, but are similarly logged and stored for future reference. And every alert is auditable and reviewable by a human, so every confirmation or correction can become an intelligence signal that trains Torq Auto Triage — powered by the Torq SOC Brain — to continuously learn over time and improve accuracy with each alert. 

The Accuracy Curve

Most agentic triage solutions perform roughly the same way on day 100 as they do on day 1,000, because every alert is treated as if it’s the first time the system has seen it. Analyst corrections from last week don’t change the way a verdict is made this week, because that institutional knowledge is buried in closed tickets across disparate security tools. 

Torq Auto Triage is different because of the Torq SOC Brain™, the learning and memory layer built into every Torq AI SOC Platform. Every analyst confirmation and verdict redirection feeds back into a dedicated, per-tenant model that continuously trains on your human intelligence. The Torq SOC Brain, and in turn, Torq Auto Triage, accumulates your SOC team’s judgment over time and gets more accurate with each case your analysts work on. 

The Torq SOC Brain is made up of three underlying technologies:

  1. Torq Recall: Retrieves relevant historical cases using deterministic matching on security observables, ranks them by relevance, then analyzes how past analysts’ decisions should influence the current verdict.
  2. Torq Reflex: Learns your organization’s unique approach to risk, evidence, and decision-making while continuously training on your team’s confirmed verdicts to improve accuracy over time.
  3. Torq Retrospect: Imports resolved incidents from existing security tools, making years of organizational knowledge immediately available and informing accurate verdict decisions starting on day zero.

As a result, Torq Auto Triage accuracy scores improve from roughly 94% to 99% in a matter of weeks, so the longer it runs, the more it becomes your own SOC intelligence model. 

Torq Auto Triage is The Front Door, The AI SOC is What’s Behind It

Torq’s agentic Auto Triage delivers its full value when verdicts flow directly into the Torq AI SOC Platform — intelligent case management, containment agents, and autonomous incident response. 

The investigations are more precise because the triage verdict was accurate and documented in the Torq Context Graph. The response is faster because Socrates and Torq HyperAgents have the full scope of the threat and the historical justification to back it up. The agentic decisions are validated and trusted because they all trace back to the same learning powered by the Torq SOC Brain.  

Triage solutions that filter false positives and escalate everything else are stuck in their old ways. Torq Auto Triage takes it further — with every alert garnering the attention it deserves, every verdict improving the system over time, and every case fully ready for the escalation, containment, or response that comes next. 

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

How A Leading Museum Automated Its Security Operations with Torq

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

The organization at the center of this story is one of the most visited cultural institutions in the world, dedicated to preserving history and educating the public.

Protecting that mission — and the digital infrastructure behind it — falls to a lean security team responsible for everything: SSO integrations, email, endpoints, servers, applications, websites, and micro-segmentation across the entire organization.

It’s a wide surface for any security team to cover. It’s an even wider one when your institution’s global profile and cultural significance make you a target. Geopolitical tensions have driven an increase in cyberattacks against the institution, demanding a security posture well beyond what the team could deliver manually.

This is the story of how that team went from fully manual operations to automated threat blocking, identity lifecycle management, and endpoint response.

When Every Security Action Depends on a Human, Nothing Moves Fast Enough

Before the Torq AI SOC Platform, the security team’s day-to-day was what you’d expect from an operation running without automation: reviewing logs by hand, writing custom scripts, pulling reports, working through spreadsheets. Every step required someone to touch it.

That meant threat response moved at human speed. A device querying a malicious URL would get flagged, but by the time an analyst reviewed it, confirmed it, and took action, a week had passed. A week of known, unresolved exposure.

The team initially looked at Torq for security playbooks to automate detection and response workflows that consume analyst time. Two things made it the right fit: it was faster to build in than native tooling, and the whole team could use it without specialized coding skills. For a security operation where everyone covers everything, that accessibility was a requirement.

Migrating to Okta: The Problem Torq Solved in Hours

The museum undertook a major overhaul of its identity infrastructure, migrating from Active Directory–sourced accounts to Okta as the primary identity provider. It’s the kind of migration that touches every user, every application, and every access workflow in the organization.

The problems surfaced almost immediately. When users didn’t respond to Okta’s verification prompts within the predefined time window, their accounts were automatically flagged, and email access was locked. For a museum with staff across departments — curators, educators, researchers, operations — lockouts stalled work, frustrated employees, and generated a cascading queue of support requests.

The obvious fix was to build an automated workflow in Okta itself. But Okta Workflows is its own ecosystem, time-intensive to implement, and creates a knowledge gap for the team. Torq offered a faster path. Through a straightforward API call, the team built a workflow that automatically detects locked-out users and clears the flags, allowing accounts to be onboarded without manual intervention.

That migration fix opened a bigger door. The team discovered that Torq could do things with Okta data that the native dashboard couldn’t. They started pulling error logs through Torq and running analysis to surface root causes, not just the symptoms the dashboard displayed. What started as a migration fix became an ongoing operational layer on top of their identity infrastructure, giving the team better visibility into their identity environment than the identity provider itself.

Security Automation That Grew into Something Bigger

The team started with security automation and quickly found that Torq’s platform could absorb manual work across security and IT operations alike. What began as a handful of security playbooks has grown into a library of automated workflows spanning threat response, identity management, endpoint security, and infrastructure monitoring.

Automated Threat Blocking

The team’s very first workflow is still one of the most impactful. The museum’s network monitoring tool continuously watches for suspicious outbound connections. When a device is flagged for querying a potentially malicious URL, Torq automatically sends the indicator to VirusTotal for cross-referencing against dozens of antivirus engines. More than four positive hits? Blocked immediately, without a human in the middle.

Before Torq, an analyst had to review the flag, look up the URL, make a judgment call, and take action. Now it runs in seconds.

Endpoint Enrichment and Response

When SentinelOne detects a suspicious event on an endpoint, the alert triggers a Torq micro-playbook that automatically enriches the event. Torq pulls the relevant indicators — hashes, IPs, domains — and queries them against VirusTotal and other threat intelligence sources. Based on the results, the playbook either documents the event as benign or executes a blocking action, without requiring an analyst to manually copy indicators between tools.

Baseline Scanning and Configuration Monitoring

Tools get deployed with specific security baselines: hardened configurations, required settings, expected states. Over time, those baselines drift. A setting gets changed during troubleshooting and is never reverted. An update overwrites a configuration. A new deployment doesn’t match the standard.

The team uses Torq to scan their tool stack and flag discrepancies against defined baselines. Instead of manually auditing on a schedule — or discovering drift after an incident — Torq surfaces gaps proactively.

Automatic Reboot for Critical Updates 

Patching is one of the most basic security hygiene practices and one of the easiest to let slip. A critical update lands, but the reboot requires coordination: confirm the asset is clear, schedule a window, and follow up. For a lean team, that coordination competes with every other task on the list.

The team built a Torq workflow that monitors for assets with pending critical updates and triggers an automatic nightly reboot. Patches are applied on schedule, every time, without manual follow-up.

Stale Asset and Duplicate Cleanup 

Every tech stack accumulates clutter. Devices get decommissioned but never removed. Endpoints are reimaged, creating duplicates. Orphaned records pile up. Each one is a blind spot — an asset that shows as managed when it isn’t, or a duplicate that skews reporting and wastes license seats.

Torq continuously scans the team’s tech stack, identifies stale or duplicate assets, and cleans them up. What used to be a periodic manual audit is now a continuous hygiene function.

Automatic Re-Enablement of Disabled Agents 

A disabled security agent is an unmonitored endpoint. The disable might be intentional (for troubleshooting), accidental (due to a bad update), or the first sign of compromise. The longer it stays disabled, the bigger the gap.

Torq monitors disabled agents and automatically re-enables them. The team is notified immediately — if the disable was legitimate, they know. If it wasn’t, the gap would be closed before it could be exploited.

The Impact

  • Threat response moved from days to seconds. Malicious activity that used to sit in a queue waiting for human action is now caught and blocked the moment it’s confirmed.
  • Routine bottlenecks disappeared. Okta onboarding issues that required tickets, callbacks, and meetings are resolved automatically. Endpoint events that waited for manual enrichment are handled in the background. The team focuses on work that requires human judgment, not work that was waiting for someone to get to it.
  • Security hygiene runs continuously. Critical updates are applied overnight. Stale assets are cleaned up. Disabled agents are re-enabled. The team doesn’t have to remember to do these things; they just happen.
  • The platform expanded beyond security. The team came to Torq for SOC automation. The fact that it’s now embedded across multiple operations says something about how much manual work was hiding in plain sight across the organization.

“Using Torq, we have the ability to retrieve data from multiple applications and mirror human action in an automated way. That saves time, and where we really need to save time is on the action side. Instead of waiting a week to block a bad IP address, Torq lets us do it almost instantaneously. It’s a major risk reduction.”

– Michael Trofi, CISO

Defending History Requires Modern Defense

The museum exists to preserve history and make sure the world never forgets. That mission draws millions of visitors, powers a global digital presence, and makes the institution a target.

The security team didn’t automate because it checked a box. They automated because the mission was too important to protect at human speed. The automation this team built is the foundation the AI SOC is built on: the shift from human-speed operations to machine-speed defense. The threats keep evolving, and so does the team.

This major museum’s team is proof of what the data shows: lean SOCs that deploy the right automation get ahead. See how 450 security leaders are thinking about AI, automation, and the future of security operations.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Black Hat 2026: AI SOC with a Brain, Tattoos, and Hot Dogs

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Torq rolled into Black Hat 2026 with a 20-foot inflatable skeleton, free tattoos, hot dogs, the Wizard of Oz, and a live news desk. That’s a lot of conversation starters right there. 

But the real talking point was Torq’s AI SOC demo: in-production AI SOC capabilities that reason with organizational context, learn from analyst decisions, get smarter with every case the platform handles, and take action across the full threat lifecycle.

Here’s what really happened in Vegas.

Pre-Show Buzz: Torq SOC Brain™ and a SACR AI SOC Innovator

Days before Black Hat, Torq unveiled Torq SOC Brain™, the self-learning layer of the Torq AI SOC Platform. The SOC Brain brings together Recall, Reflex, and Retrospect to help Torq reason from past cases, learn from analyst decisions, and apply that judgment to future triage and investigations.

The launch drew coverage from SiliconANGLE, Channel Insider, MSSP Alert, and more.

“The end goal is to shift as much as possible of a cognitive load required to investigate incoming security alerts.”

Leonid Belkind, Torq CTO and Co-Founder in Channel Insider

Torq also entered Black Hat with fresh analyst recognition: Software Analyst Cyber Research named Torq a leading Innovator in its AI SOC Market Report, as an “as an AI SOC operating layer that can ingest alerts, classify triage outcomes, construct cases, assign work to Socrates, and route remediation through deterministic or agentic workflows depending on the use case.”

Then we took it to Vegas.

The AI SOC Demo

Torq’s demo stations stayed busy as attendees saw hands-on how Torq moves from alerts through investigation and response with context and agentic reasoning built in. Here’s what landed most:

  • Torq Context Graph drew a strong reaction. It’s a live model of your environment (identities, assets, policies, and the reasoning behind past decisions) so every verdict is grounded in the full picture, not a single alert in isolation. The blast-radius and pivot-point views hit hardest, showing how far one compromised identity could reach and why organizational context changes what an alert actually means.
  • Torq Auto Triage classifies every alert as false positive, benign, or malicious with explainable reasoning, turning real threats into cases automatically and cutting noise before an analyst engages. The most common question was what it weighs to reach a call, and showing that reasoning is the difference between a black box and a platform a SOC will trust to act.
  • Recall and Reflex were where the conversation moved past triage. Recall brings your own case history to every new alert, and Reflex learns your team’s judgment, so the platform gets more accurate the longer it runs instead of resetting to zero each shift.
  • Torq Socrates lets teams prompt workflows. Describe the outcome you want in plain language, and Socrates plans, builds, and orchestrates the automation across your stack, deciding what runs agentically versus deterministically and coordinating the right HyperAgents to carry it out.

On Stage: Context, Memory, and Learning in the AI SOC

John White, Field CISO EMEA, and Rick Bosworth, Sr. Director of Product Marketing, took the stage to go a level deeper on why those capabilities matter. Together, the Context Graph, Recall, and Reflex form the Torq SOC Brain, the layer beneath the agents that lets the platform reason about your environment, remember your decisions, and learn your team’s judgment.

John and Rick kept coming back to two points:

  1. First, autonomy is a dial you widen as trust builds, not an all-or-nothing switch.
  2. Second, every customer’s SOC Brain stays isolated, so what one team’s platform learns is never shared with another.

They also shared advice on how best to get started with an AI SOC platform: Pick the repeatable Tier 1 work that eats the most analyst time, prove it out, then expand. On timing, they were blunt. Waiting is its own risk when attacks already move at machine speed.

TTVN, Live from Las Vegas

Our Junior Media Intern Trevor has traded in his TorqTV van for a news desk.

Trevor and Tony went live from the TTVN desk with boots-on-the-ground Black Hat coverage of the week’s biggest stories: Skelly, Torq Dogs, real (yes, real, actual, permanent) tattoos and piercings, Channimals in the Wild, AMP’d partner highlights, and an exclusive Wizard of Oz screening at the Sphere, co-hosted by Snyk.

Didn’t Catch Us in Vegas?

The hot dogs were tasty. The tattoos were permanent. But the bigger story was what Torq showed in the booth and on stage: an AI SOC platform that reasons on your environment, remembers your decisions, and learns your team’s judgment across the full threat lifecycle.

Missed the Torq demo at Black Hat, or want a closer look without the show-floor crowd? Watch our live Auto Triage demo webinar.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO

Torq Named a Leading Innovator in SACR 2026 AI SOC Market Report

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Software Analyst Cyber Research (SACR) just published its 2026 AI SOC Market Report, offering an independent assessment of vendors competing in what has rapidly become the most consequential category in enterprise security. Torq features prominently, and the report’s framing is worth unpacking because it illuminates what makes the AI SOC category hard to evaluate and why Torq’s approach is consequential.

Torq’s AI SOC: From Alert Triage Through Remediation

SACR’s most pointed observation about Torq is definitional. The firm writes:

“Torq is best understood less as a conventional SOAR vendor with AI features and more as an AI SOC operating layer that can ingest alerts, classify triage outcomes, construct cases, assign work to Socrates, and route remediation through deterministic or agentic workflows depending on the use case.”

That distinction matters. Much of what gets marketed as AI SOC today amounts to copilot functionality that surfaces recommendations and draft summaries, and stops at basic triage that simply moves the bottleneck down the SOC line by an increment. SACR cuts through that framing: 

“Torq is trying to own high-volume alert triage and response closure, not simply accelerate analyst review.”

Owning closure requires a different architecture than assisting analysts. It requires accurate alert classification at scale, a context layer deep enough to support trustworthy, autonomous verdicts, case management that carries investigations forward, and response automation that can act, not just advise. But let’s circle back and dwell a bit on the first phase: autonomous alert triage.

Auto Triage: Context Is the Differentiator

Torq Auto Triage classifies incoming alerts as false positive, benign, or malicious, enriches them with threat intelligence and business context, and routes them accordingly, all before a human analyst is involved. True positives become cases automatically. False positives are fed back into the per-tenant AI model.

SACR called out the quality of Torq’s context layer directly: 

“Torq is not treating alerts as isolated artifacts. It is building a context pipeline around entities, access history, business role, device state, SaaS activity, and related evidence before determining whether an alert should be closed, escalated, or remediated.”

Three underlying capabilities power that context pipeline.

  1. Torq Reflex is a per-tenant ML model trained continuously on your team’s confirmed verdicts.
  2. Torq Recall retrieves the most relevant prior cases from your environment’s history and applies an LLM to determine how those precedents apply to the current alert.
  3. Torq Context Graph provides the unified substrate both depend on: a continuously updated map of identities, assets, networks, policies, and analyst decisions, normalized across your entire security stack.

The results speak volumes. On average, large enterprises achieve a mean time to triage (MTTT) of 1 minute, a 60x improvement over manual triage. A global biotech titan cites a 97% reduction in noise entering the SOC; imagine how much better their security analysts can focus. A well-known financial services enterprise achieved 99% faster threat triage after deploying Torq.

Case Management: The Operating Unit

When Auto Triage surfaces a true positive, it flows directly into Torq Case Management, where analysts inherit the full verdict, enrichment context, and proposed next steps. They do not reconstruct context from scratch.

From within the case interface, analysts collaborate with Torq Socrates™, trigger automated response actions, and track investigation continuity across shift handoffs. Each confirmed verdict and analyst correction flows back into Reflex as a training signal, compounding accuracy over time. 

This is the mechanism behind what SACR identifies as Torq’s stronger-than-expected investigation story: the platform captures and encodes analyst judgment, rather than relying on individual expertise to repeat the same reasoning shift after shift. The machine clears the noise. The analysts focus on the highest priority items.

Socrates: Reasoning and Orchestration

Torq Socrates is the agentic reasoning and orchestration layer at the center of the platform. It can be used interactively by analysts, embedded in investigation templates, or assigned cases autonomously. Once on a case, Socrates plans investigations, delegates tasks to specialized Torq HyperAgents™, and coordinates response actions across the security stack.

SACR characterizes Socrates as “the reasoning and planning layer that decides how much work should be agentic, how much should be deterministic, and where the human should approve or intervene.” As SACR notes, “autonomy is a dial, not a binary switch,” and Torq’s model lets security organizations operationalize that dial gradually: starting with triage and recommendation, moving into human-approved action, and eventually automating higher-confidence alert classes.

One Torq customer on PeerSpot describes the cumulative impact: Torq handles a large volume of their alerts autonomously, fundamentally changing the burden placed on their security team.

Hyperautomation: Execution Depth

Torq Hyperautomation is the execution layer that connects AI decisions to real action, supporting both agentic and deterministic workflows across the full security stack. SACR identifies this automation heritage as a structural advantage: 

“Compared with AI SOC point solutions, Torq’s advantage is the ability to connect AI decisioning to actual workflow execution.”

That advantage compounds. The same platform that classifies an alert, builds the case, and assigns it to Socrates is the platform that executes containment and remediation at machine speed. Customers have measured a 94% reduction in mean time to respond (MTTR), a metric that requires the full chain, not just faster triage at the front end.

What SACR’s Assessment Means for Buyers

SACR closes its Torq vendor profile with a synthesis that applies beyond Torq specifically: 

“Autonomous SOC value will be measured by closed-loop operating capability rather than AI summarization.” 

Verdict quality matters. But a verdict quality that does not connect to case construction, investigation, response, and organizational learning is an incomplete story. Torq’s architecture is designed around that full loop.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO