Contents
Get a Personalized Demo
See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

David Melamed is Head of Emerging Technologies at Torq. He joined through Torq’s acquisition of Jit, which he co-founded and has led as CTO since 2020, building agentic security on a production Context Graph. A cloud security veteran with 20+ years of experience, David previously held senior technical roles at Cisco (via the CloudLock acquisition) and MyHeritage.
In The Odyssey, before Odysseus sails a narrow strait on his way home, the witch Circe gives him a brutal instruction: you cannot pass both Scylla and Charybdis unharmed, so stop trying. Charybdis, the whirlpool, can swallow the entire ship. Scylla, the monster on the cliff, will take up to six men. So Odysseus steers close to Scylla and loses the six men, but keeps the ship, choosing the loss he can survive over the loss that ends the voyage. And he chooses it in advance, with his eyes open.
Sheer volume means that no SOC works every alert, so that judgment call is the most advanced thing a security operations center can do. Almost no maturity model measures it.
Your Maturity Model Is Measuring the Wrong Thing
The common consensus is that SOC maturity is not about tools. But then everyone pulls out a maturity model that is, in practice, a tool and capability checklist: Do you have a SIEM? A SOAR? Threat intel feeds, 24/7 staffing, a detection engineering function, a case management system? Check the boxes, climb the ladder.
The problem is that a SOC can check every capability box and still be bad at the only thing that matters: making accurate, explainable decisions, fast. It can own every category of tool and still decide slowly, decide wrong, and never be able to say why. Tool count is muscle. Maturity is metis, the cunning judgment that got Odysseus home when force could not.
Here is the claim the rest of this post defends: A SOC that claims to investigate every alert is not mature. It is drowning, or it is not telling you the truth. The first blog in this series laid out why: the queue outruns the people every day, false positives dominate, and most teams are overwhelmed by the sheer volume. Full coverage is not on the menu, at least not today, and later posts will show how AI starts to change that math. But right now, the queue wins.
So the real question was never whether you leave alerts uninvestigated. You do. The question is whether you choose which ones you do investigate on purpose.
Maturity is Choosing Your Losses on Purpose
To continue my analogy, every SOC already steers past Scylla. The immature one just does it blindfolded.
When the queue is too long and the shift ends, something goes uninvestigated. In most SOCs, that choice is made by accident: whatever the tired analyst did not reach by 2am becomes the accepted loss, decided by exhaustion rather than by risk. Nobody signed off on it. Nobody can defend it. And the team finds out what it deprioritized when it shows up in the breach report.
The mature SOC makes the identical choice deliberately. It decides, by risk, what it will not chase this week, and it writes that decision down. Writing down what you chose not to chase sounds like liability, and counsel will flinch at it. It is the opposite. Undocumented risk acceptance is the liability. A dated, risk-based decision is standard GRC practice, and it is defensible precisely because someone owned it. Same loss, opposite posture. Odysseus did not lose six men by accident. He chose them to save the ship, on the best counsel available, before he entered the water.
This is a concrete, testable difference, not a philosophy. Ask a SOC leader what their team deliberately deprioritized last week and why. A mature team has an answer. An immature team has a backlog it is quietly hoping was not important.
Decision Accuracy: Measuring the SOC as a Decision Engine
If maturity is decision quality, then measure decisions. Four questions do more work than any capability checklist and help measure decision accuracy. Three of them you have seen before. The fourth is the one that separates mature from lucky, and almost no maturity model asks it.
- What did you choose to chase, and does that match your actual risk? This is coverage, but not the vanity version. Risk ranking is itself a decision, made cheaply and provisionally at intake, so the number that matters is not the percentage of all alerts touched; it is the percentage of the classes you rated high-risk going in that actually got adjudicated. How often that intake ranking was wrong is part of the next metric.
- How fast did you decide? Time to decision, the gap between an alert arriving and a verdict someone will stand behind, is the metric post-it almost no one tracks.
- How often were you right? Decision accuracy, measured by how often a closed alert was truly benign and how often an escalation was truly warranted. You cannot compute this on alerts you never opened, so mature teams sample: re-investigate a random slice of the deprioritized queue to estimate how often the deferral was wrong. That sample is the honesty check on the entire model, and it tells you whether speed is helping or just producing faster mistakes.
- What did you consciously choose not to chase, and can you defend it? This is the Scylla metric, and it is the one nearly every maturity model omits. A team that can name its deliberate losses is operating with judgment. A team that cannot is operating on luck.
The uncomfortable part is that the industry measures almost none of this. In the SANS 2025 Detection and Response Survey, more than half of teams do not track mean time to detect or respond at all, and many fall back on raw detection and incident counts, which measure activity, not decisions. Torq’s 2026 AI SOC Leadership Report, surveying 450 security leaders, found the same pattern from the other direction: 80% run disconnected point tools, 80% say that fragmentation creates operational complexity, and 85% would rather have one unified platform. Each tool holds a fragment of the picture, which leaves the analyst as the integration layer, stitching partial truths into something close to a single answer.
Adding tools does not move the number that counts. Counting alerts closed is the security equivalent of counting swings instead of runs. It feels like progress, but it correlates with nothing.
“But choosing not to investigate is how you miss the breach.”
This is the objection a good detection engineer raises immediately, and it is right to raise it. If you bless deprioritization, do you not bless the exact gap an attacker walks through?
No, and the reason is the whole point. You are already deprioritizing, because today’s volume guarantees it.
The risk was never in choosing. It is in choosing blindly. A documented, risk-based decision to defer a class of low-signal alerts is auditable, reviewable, and improvable. You can look back after an incident, ask whether the rule was wrong, and fix it. An accidental gap teaches you nothing, because no one decided it and no one owns it. Deliberate loss is a control. Accidental loss is just exposure with better PR.
And the goal is not to celebrate the losses. It is to shrink them, and this is where the volume math changes. When AI triages every alert automatically, and investigation runs at machine speed, volume stops being the thing that decides what you skip. The analyst is no longer picking which alerts there is time to open. They are setting the bar for what the team is willing to let an automated verdict close, and reviewing what sits above it. The let-go set does not vanish; it becomes a threshold someone chooses. It never reaches zero, and pretending otherwise is how immature SOCs operate. Maturity has never meant having no residue. It means owning the bar that defines it, on purpose. You cannot own a bar you refuse to name.
Where to Start
Do not rebuild your program around a new model this quarter. Do one thing. Pick a single decision metric, time to decision or coverage of what actually matters, and instrument it for one alert type. Then, in your next operational review, ask the fourth question out loud: What did we choose not to chase, and can we defend it? The answer, or the silence, will tell you exactly how mature you really are.
Odysseus reached Ithaca because he was willing to decide which loss to take and to own it. The SOCs that will look mature in three years are the ones learning to do the same now, on purpose, with the receipts to prove it.
Next in this series: What actually changes when reasoning enters the loop, and how agentic investigation shrinks the set of alerts you are forced to let go.




