Global Pharma Giant Cuts MTTR by 92% with Torq AI SOC

Industry: Pharmaceutical |
Region: Global |
Product: Torq AI SOC Platform |

Case Study Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to detect, prioritize, and respond to threats faster.

Request a Demo

Drowning in Noise, Starving for Signal

This pharmaceutical titan operates one of the world’s most complex security environments, consisting of global operations across 150+ countries, a large analyst team, and a constant flood of security alerts.

Analysts were burning hours on repetitive, low-judgment manual triage across endpoint, email security, and identity alerts. Over half of all cases (51%) came from endpoint and email sources, yet only 19% of those actually contained real threats. The team poured its energy into chasing noise, while the confirmed malicious cases that demanded urgent attention waited in the queue. Real threats can take 25x longer to resolve than false positives. Every minute lost to a low-fidelity alert was a minute not spent on actioning actual risks.

A complicating factor was that the global pharma giant had built a sophisticated homegrown User and Entity Behavior Analytics (UEBA) tool, but it operated in a silo. Analyst triage happened without UEBA risk scores surfaced in context, meaning behavioral signals that the company’s own platform had already computed were not making it into live case decisions.

And as their automation ambitions grew, so did the governance gap. Scaling a workflow library without a formal CI/CD-style promotion process invites production incidents, especially in a regulated pharmaceutical environment where auditability isn’t optional. The approval groups existed, but the pipeline to use them didn’t.

The team was working harder than ever with less to show for it.

Torq is NOT a SOAR. Torq is an AI SOC platform that uses agentic AI and automation to eliminate the weaknesses of legacy SOAR, rendering it obsolete. Torq expands SOC capacity, accelerates throughput, and delivers on end-to-end SecOps threat lifecycle management at scale.


From SOAR to AI SOC That’s Built to Last

This pharmaceutical giant came to Torq with a SOAR replacement on the horizon, a SIEM migration in flight, and a mandate to modernize without rebuilding everything from scratch. Torq delivered on all three fronts, and then some.

The migration mattered most. When this enterprise moved off their current SIEM, they didn’t have to rebuild their automation logic from the ground up. Torq’s platform-agnostic architecture enabled them to swap SIEM integrations with minimal rework, preserving months of automation investment that a less flexible platform would have cost them.

From there, Torq and the customer’s team built three production-ready capabilities that directly addressed the team’s biggest pain points:

Automated alert triage with integrated case management
Torq Auto Triage ingests high-volume alerts from endpoint, email security, identity, and more, enriches them with context, and either routes them to the right analyst queue or, when confidence is high, resolves them autonomously. The mean time to triage (MTTT) is 56 seconds per alert, and noise reduction keeps improving as the model learns from historical cases and analyst feedback.

UEBA integration
Torq connected the homegrown UEBA platform directly into live case management, with no scripting marathons and no professional services engagement. Torq pushes relevant user observables from active cases to the UEBA, pulls behavioral risk scores back, and surfaces them in case context in real time. Analysts now have the company’s own behavioral intelligence in front of them without switching tools.

Reliable automated response with Auto Triage, Torq HyperAgents™, and Socrates
With 98.4% accuracy in identifying malicious activity, Torq Auto Triage used relevant historical cases to learn from precedent and substantially reduce the number of cases requiring human intervention, which often took 25x longer to resolve. Socrates then helped orchestrate the response while also partnering with threat hunters to proactively pinpoint threats before they became incidents. Torq HyperAgents handle global pharma giant’s repetitive investigation, management, and response work, acting like junior staff so human experts can focus on what matters.

“By silencing the noise at the Tier 1 level, our SOC Analysts can spend more time where it makes the greatest impact on our overall security posture.”

Deputy CISO, Global Pharma Giant


AI That Accelerates Judgment, Not Just Tasks

The Torq AI SOC Platform didn’t just replace an outdated approach; it gave the global pharma giant’s team capabilities their previous platform couldn’t have delivered at any price.

Auto Triage stops the alert tsunami before it drowns the SOC
Over 137,000 alerts from 10,000 EDR endpoints alone were hitting the team — a volume no analyst roster can clear manually. Torq Auto Triage sifts through that deluge at machine speed, separating verified risks from noise before anything enters the SOC queue. Only alerts that clear the bar get escalated by automatically creating cases for confirmed threats, so analysts inherit a queue that’s already been pre-filtered for what actually matters.

Torq HyperAgents now do the investigation heavy lifting
The customer put 50 Torq HyperAgents to work alongside their team. These AI agents handle investigation steps, surface enriched context, and guide response automation, all within a unified platform. Torq HyperAgents are now at the center of endpoint and email triage expansion, with approximately 2,300+ analyst hours reallocated from clearing noise to investigating actual risks, all from that use case alone.

Socrates is the agentic orchestrator of the AI SOC
Once Torq HyperAgents pre-qualify a case, Socrates takes over as the primary investigator, working a much cleaner queue because the upstream noise has already been suppressed. As a result, the customer’s 2+ day median MTTR for its confirmed malicious cases across threat, malware, and network categories, which had long defined the cost of operating at global scale, was reduced by 97%.

Integrations that just work
Torq connected to the enterprise’s Microsoft Defender, CrowdStrike EDR, cloud infrastructure, cybersecurity asset management, digital employee experience application, and SIEM/SOAR integration platform — all without custom development or professional services fees.

“The benefit of going with Torq meant we didn’t have to rebuild everything when we changed our SIEM. We could leverage what we’d already built with minor adjustments; that flexibility alone was a massive win.”

Security Architect, Global Pharma Giant


A SOC That Works Smarter

The results tell a story that senior stakeholders had been waiting to hear. With Torq Auto Triage, Torq HyperAgents, Case Management, and Socrates running in tandem, the customer’s SOC transformed from servicing noise into a proactive, high-signal operation.

56 seconds average triage time
Torq Auto Triage averages sub-60-second triage on high-volume EDR alerts, and it keeps improving as the model learns from historical cases and analyst feedback. It has kept a huge amount of noise out of the SOC.

75% of cases closed by automation
This exceeded its FY25 goal by 15 percentage points, a huge accomplishment.

56 seconds average triage time
Torq Auto Triage averages sub-60-second triage on high-volume EDR alerts, and it keeps improving as the model learns from historical cases and analyst feedback. It has kept a huge amount of noise out of the SOC.

92% decrease in MTTR
Torq HyperAgents, Case Management, and Socrates working together drove a 92% reduction in mean time to resolve for cases managed directly by the customer (the ones that didn’t go through the managed service provider). Endpoint, email security, and identity cases that previously required significant manual effort are now investigated and resolved much faster, with human oversight.

35% reduction in duplicate case workload
Of 4,319 cases processed, 35% were flagged as duplicates by Torq’s automation. Instead of analysts re-investigating the same incident from different angles, those 1,517 cases were grouped, linked, and resolved without redundant effort.

6,253 total cases processed
In six months, across the full security stack, Torq processed over 6,000 cases, giving the enterprise’s SOC team the capacity to absorb the case volume growth that followed their managed service provider change without adding headcount.

As Torq HyperAgents expand across endpoint and email triage and Socrates takes on final-mile investigation, analysts see less noise and spend their time on what needs human judgment.

“What Torq gives us isn’t just speed. It’s the ability to finally put analyst attention where it belongs. We’re not chasing time-wasters anymore. We’re building a SOC that scales.”

SOC Lead, Global Pharma Giant

For global pharmaceutical enterprises facing rising alert volumes, budget pressure, and a shifting tech stack, the path forward requires technology that augments the team and expands SOC capacity. This customer used a platform replacement cycle to retire its SOAR, preserve its automation investment through a SIEM migration, and build an AI SOC that learns and keeps getting faster over time. The result is a security operation that does more with the same team.