More Tools Never Fixed the SOC: The Bottleneck Was Never Visibility

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

David Melamed is Head of Emerging Technologies at Torq. He joined through Torq’s acquisition of Jit, which he co-founded and has led as CTO since 2020, building agentic security on a production Context Graph. A cloud security veteran with 20+ years of experience, David previously held senior technical roles at Cisco (via the CloudLock acquisition) and MyHeritage.

Odysseus left Troy with a fleet and reached Ithaca with nothing, having lost every ship to the sea. While the war was won by force, the journey home was won by wits, and ultimately the fleet barely mattered.

Most security operations centers are still running their SecOps voyage the way Odysseus ran the war: more tools, more force, more signal. It is the wrong instinct, because the SOC bottleneck was never how much you can see. It is how fast you can decide.

You already agree with this. That is the problem.

Of course more tools won’t fix the SOC. Everyone knows that. “Tool sprawl” and “alert fatigue” have been on conference slides for a decade, and no security leader would defend buying their way to maturity out loud.

And yet the same people who nod along will buy another tool the next time a new threat class appears, stand up another console, and still report their program by how many detections fired rather than how many good decisions got made. A claim everyone repeats, but no one acts on, is not a consensus. It is a collective blind spot.

Tools are not the enemy, and a real coverage gap deserves a dedicated tool. The failure is reaching for a purchase when the real constraint is decisions, a move leaders may still knowingly make because a purchase is a single defensible act, and the system rewards visible action over structural change.

The Math Stopped Working

The first symptom is noise. Enterprise SOCs field thousands of alerts a day, and because the average SOC now runs seven AI-powered tools, with 80% of teams relying on disconnected point solutions, the same event often fires as duplicate alerts across several platforms with no shared context. 

Most teams named false positives their single biggest detection challenge, and the rate is rising every year. That is the point, not a footnote. The flood is not raw blindness; teams can see plenty. But they lack the capacity to handle incoming alerts and make decisions fast enough to matter and with enough confidence to close the related case: is the suspicious PowerShell on a finance laptop an intruder or the IT team? Nearly two-thirds (62.5%) say they are simply overwhelmed by the volume of data.

The attacker is not waiting. Verizon’s 2026 Data Breach Investigations Report found that for the first time in 19 years, exploitation of vulnerabilities overtook stolen credentials as the top initial access vector, rising to 31% from 18% the year before, while breaches involving a third party climbed to nearly half of all cases. Verizon’s own read is blunt: the speed at which known vulnerabilities are now weaponized, accelerated by AI, risks a capacity crisis for security teams. The inflow is accelerating faster than any hiring plan can keep up with.

The consequence is not just wasted effort; it is lost coverage. Most analysts spend time manually sorting low-value alerts that should have been filtered upstream, ultimately leading to slow responses: about a third of teams (32.8%) take hours rather than minutes to respond to a threat. Hours are a losing trade against the velocity Verizon just described.

There is an easy answer on the market, and it is the wrong half. Speeding up triage is the win every tool sells, but automation that acts faster without proving when it is right does not remove risk. It simply relocates risk from a slow human to a fast machine no one has taught you to trust. Speed is not the hard problem. Earned trust is.

The Second Symptom Is Human

The other half of the equation is the people, and it is not fixable by hiring, because you cannot hire fast or cheaply enough. 

The ISC2 2025 Cybersecurity Workforce Study, drawn from more than 16,000 practitioners, found that a third of organizations lack the resources to adequately staff their security teams, that skills gaps are now nearly universal, and that 72% of professionals believe cutting security staff materially raises the likelihood of a breach. The talent you do have does not stay: SANS found that 70% of analysts with five years or less of experience leave their roles within three years.

So the loop closes on itself. Volume overwhelms the team, the team burns out and turns over, institutional knowledge walks out the door, and the next analyst inherits an even larger backlog. You cannot hire your way out at the speed or price the math requires. The point is not fewer analysts; it is more decisions per analyst:  people spending their hours on judgment calls only a human should make, instead of clearing queues a machine could clear.

You Can See It. You Cannot Assemble It Fast Enough.

It is tempting to call all of this a visibility problem. It is not, and the distinction is the whole point of this series.

Most SOCs are not blind. A great deal of telemetry exists, spread across dozens of consoles. But two things make “we can see it” a false comfort. First, raw data is not always easy to query in the moment, and the context that actually settles a decision often lives entirely outside the security stack. Confirming whether a flagged user is on approved leave means reaching into an HR system. Confirming whether that odd remote login was really an employee can mean pinging them directly. None of that is a detection feed, and none of it is one query away.

Second, even when the evidence is all technically available, someone has to assemble it. An analyst working on one alert pulls evidence from several tools, enriches the indicators, and checks by hand whether this signal connects to something the team has already seen, one pane of glass at a time. 

Torq’s 2026 AI SOC Leadership Report, featuring 450 security leaders, puts a number on that bridging work: Analysts spend 8.6 hours a week validating and reconciling AI outputs across disconnected tools. And the understanding they build is fragile, lost again at every shift change, when context does not survive the handoff between teams. So a phishing verdict that should take minutes can sit for hours, not because the evidence is missing, but because assembling it is slow.

That is not a gap in what the SOC can see. It is a gap in how fast a human can gather scattered context, some of it outside the security tools, into a single judgment, and how little of that judgment survives the next shift change. Which puts manual correlation squarely on the decision side of the ledger, not the visibility side, and makes it one of the most expensive line items on that side.

The Bag of Winds

Let’s return to the Odyssey for a moment. A day from home, Aeolus gives Odysseus a bag holding every storm wind, so only a fair breeze carries him towards his home in Ithaca. In sight of the shore, his crew opens it, certain it hides treasure. The freed winds blow the ship all the way back out to sea. The gift was real, but it worked only while one condition held; the moment reality stepped outside it, the tool did not just stop helping — it undid the progress already made.

That is the signature of static playbook automation. It executes the steps a human mapped in advance, so it runs beautifully while an incident matches the script and fails the moment one does not — quietly, at the worst time. Automation itself is not the issue here here. The problem is that deterministic-only automation, where every branch is pre-mapped by a human, has no answer for anything unmapped. The fix is not less automation; it is automation that can reason rather than replay a fixed script. 

But adaptive automation brings its own failure mode: a confident wrong answer. So the hard part is not the reasoning; it is proving when to trust it. (But that is the focus of a later post; I will get back to it).

Zoom out, and the pattern repeats. SIEM promised that centralizing the logs would surface the answers, and delivered more signal with a search problem. SOAR promised that automating response would let humans step back, and delivered brittle playbooks to maintain. XDR promised cross-domain correlation and delivered real value, but still left a human to decide what each correlated case means. Each added capability downstream of the real SOC bottleneck, so each moved the constraint rather than removing it. Automate the response, and the bottleneck moves to triage. Centralize the logs, and it moves to investigation. The decision was always the part that did not scale.

The SOC Bottleneck Was Never Where You Were Spending

The honest test of any security investment is simple, and you can try it at home: Does it increase the number of correct decisions your team can make in a day, or does it just increase the number of things your team has to decide about? 

Most of what the industry sold did the second while claiming to do the first. The tell is that more than half of teams still do not track mean time to detect or mean time to respond at all. The metric that would actually expose the problem is rarer still: time to decision — the gap between an alert arriving and a verdict someone will stand behind — as well as time to close the loop. Almost no one measures it. This series will argue that this, not visibility, is the binding constraint, and it will try to earn that claim post by post rather than assert it.

This is why buying the next tool out of anxiety can feel less like navigation than like adding one more ship to a fleet the sea will take anyway. The capability accumulates. The stack grows. And the thing that actually determines whether you get home, the capacity to turn scattered evidence into a decision to close, escalate, or contain, at the volume the sea throws at you, barely moves. 

The cheapest first move is not another tool; it is a number: Start measuring time to decision, because you cannot fix a bottleneck you have never put a number on.

Where This Series Goes

Troy fell to force. Ithaca was reached by wits. The rest of this series is all about the wits: how to define maturity by the quality of decisions rather than the size of the arsenal, what changes when reasoning enters the loop, how to let automation act only when it has earned the right, and how to govern it so autonomy strengthens the SOC instead of becoming its next attack surface.

None of that means visibility never matters. Real coverage gaps are real, and sometimes a new tool is the right call. The point is narrower and more useful: for most SOCs, the next unit of value is not another feed of signal; it is the capacity to turn the signal you already have into decisions, faster and more reliably, at scale. That is the voyage. Everything else is just another ship in a fleet the sea is waiting to take.

Next in this series: Why the most mature SOC in your peer group is not the one with the most tools, and how to measure the difference.

For the data behind the shift this series is built on, the 2026 AI SOC Leadership Report captures how 450 security leaders are rethinking tooling, trust, and the decisions that actually move their programs forward.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO