From Agreement to Action: What’s Actually Stopping Us?

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

Over the course of this series, I’ve laid out the case for a fundamentally different security operating model — one built around Outcome, Judgment, and Execution layers, where AI handles the execution at machine speed, and humans focus on the decisions that actually need them. I’ve argued that the CISO’s role is changing, that human-centric security no longer scales, and that the org chart needs to reflect where AI fits on the team.

Most of the CISOs I talk to agree with all of it. And yet many of them haven’t moved.

This is the piece I wanted to write most, because it’s the one I’ve lived. The gap between agreement and action is not a new phenomenon in security. But with agentic AI, the cost of that gap is compounding faster than it ever has before.

The Gap Is Not What You Think

When I ask CISOs what’s holding them back, I rarely hear “budget.” I rarely hear “we don’t believe in the technology.” I almost never hear “our board said no.”

What I hear is hesitation. And hesitation, in my experience, is not one thing. It’s a collection of smaller, quieter blockers that don’t show up in a slide deck but absolutely show up in the pace of decision-making.

It sounds like this:

“We’re waiting to see how the market shakes out.”

“We need to finish our current platform migration first.”

“We haven’t figured out who owns this internally.”

“I want to do a proper evaluation, and we just haven’t had the bandwidth.”

None of these are unreasonable on their own. But stacked together, they produce the same outcome as saying no without anyone ever having to say it.

Ownership Is the First Problem

In most organizations I’ve worked with, AI adoption sits in an awkward governance gap. Security wants it, IT has opinions about it, data teams think they should lead it, and the CISO knows they need it but isn’t sure whether it is a security or an enterprise technology initiative, or something else entirely.

When nobody steps forward to own the decision, the decision doesn’t get made. It gets deferred into a working group, studied for another quarter, and revisited at the next offsite.” And six months later, the CISO is still in the same position — agreeing that AI is necessary, attending the same vendor demos, and waiting for something to change.

Here’s what I’ve learned: whichever function grasps the nettle first will benefit most. Security is uniquely positioned to lead AI adoption because we already operate under the conditions that make it essential — relentless alert volume, machine-speed threats, and a structural inability to hire our way out. We don’t need permission from another function to solve our own operational challenges. We need to lead.

If security doesn’t step into that role, someone else will make the decisions for us. And they will optimize for their priorities.

Fear of Getting It Wrong

There’s a second blocker that’s harder to talk about: the fear of making a wrong bet.

CISOs are trained to be risk-averse. It’s in the job description. When the AI SOC vendor market is noisy, fragmented, and moving fast — when every vendor is claiming “agentic” and the analyst landscape is still forming — the safest-feeling move is to wait for the market to mature and let someone else go first.

I understand the instinct. I’ve had it. When I was on the practitioner side, the biggest thing that slowed me down was the lack of a clear framework for distinguishing between what was real and what was marketing. Every vendor had a slide that looked like the future. Very few of them could explain what happened when you actually turned it on.

But here’s the problem with waiting: the threat environment is not waiting with you. AI-augmented attacks are accelerating. The gap between your attack surface and your defense capability is widening every quarter you don’t act. And the accountability question — did you fail to adopt capabilities that would have materially reduced your exposure — is already being asked by boards and insurers. Regulators will follow.

Waiting feels safe. It is not.

The Market Has Shifted

Something has changed in the last 6-9 months: the hesitation is starting to break.

A year ago, at InfoSecurity Europe, the conversations I was having were exploratory. CISOs were curious but cautious. They wanted to understand what “AI SOC” really meant. They were doing research, comparing vendors, and trying to determine whether the category was mature enough to warrant a serious evaluation.

This year, the conversations are different. CISOs are coming in with approved budgets and set timelines. Some are skipping the proof of concept entirely and going straight to purchase — a signal that they understand the problem, they’ve done their homework, and they have organizational momentum behind them. The early majority is moving.

The organizations that acted 12 months ago are now operating at a fundamentally different speed. They have AI handling Tier 1 and Tier 2 triage around the clock. They’ve moved analysts out of repetitive ops and into roles where they apply judgment, not just process volume. They’re measuring outcomes, not activity. And they’re doing it with the same headcount — or less.

The question is no longer whether AI belongs in the SOC. The question is whether you’re going to design this intentionally or scramble to catch up.

What the Smallest Step Looks Like

If you’re a CISO who agrees AI is necessary but hasn’t moved yet, here is the most practical advice I can give: stop trying to solve the whole problem at once.

Pick one category of alerts. Something repeatable, consistent, and high-volume — phishing, maybe, or endpoint detections that follow a predictable pattern. Something where the decision criteria are clear and the risk of an autonomous action is low.

This is exactly where the Torq AI SOC Platform starts. Auto Triage ingests your alerts, filters the noise, and surfaces the cases that actually matter. From there, specialized AI Agents handle the investigation and response (within the guardrails you define), while your analysts focus on the judgment calls that need them. You don’t bolt AI onto your existing workflow. You start with an execution layer and build around it.

Set the guardrails, watch the output, and build confidence in the results. Measure what changes: time saved, accuracy, analyst capacity freed up, and then expand. Carvana is auto-resolving 100% of Tier 1 and Tier 2 cases. That’s what the trajectory looks like when you start with the right platform.

You don’t need a 12-month roadmap, a team reorganization, or buy-in from every stakeholder. You need one use case, one quarter, and the willingness to start.

Everything I’ve written in this series — the Outcome, Judgment, Execution model, the org design shift, the accountability conversation, the case that human-centric security no longer scales — it all becomes real when you take that first step.

The Window Is Closing

I want to end this series where I started: with a direct challenge to every CISO reading this.

You agree. I know you do. The data is clear, the technology is deployable, the market has validated it, and the threat environment demands it. The only thing between agreement and action is a decision.

The organizations that design around this model now will have the agility to operate at machine speed when it matters most. The ones that wait will try to bolt it on mid-crisis and wonder why nothing holds together.

The future of the SOC is humans at the edges and AI in the middle. The only question is whether you design that intentionally or let it happen to you.

Don’t let this be the year you watched from the sidelines.

Keep Reading John White’s CISO to CISO Series

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO