When attacks move at machine speed, SOC capacity becomes the constraint
Expert of the InfoSec division
2026.08.27
Recent cybersecurity research points to the same operational challenge from different angles. Mandiant and Verizon show how attacks are evolving, IBM measures their financial impact, while IANS and Artico Search examine the resources security teams have available.
Together, they reveal a growing imbalance: attackers are accelerating faster than SOC teams can expand their capacity.
The attack window keeps shrinking
Mandiant’s M-Trends 2026 shows that access can move between threat actors in less than 30 seconds. What appears to be a low-priority signal can therefore escalate into a serious incident almost immediately.
At the same time, familiar weaknesses remain the main entry points. Exploitation accounted for 32% of known initial infection vectors in Mandiant’s data and 31% in Verizon’s.
Defenders, however, operate on a very different timeline. Verizon found that:
- only 26% of critical CISA KEV vulnerabilities were fully remediated;
- median remediation time reached 43 days;
- organizations faced around 50% more critical vulnerabilities than a year earlier.
Attackers increasingly work in seconds and minutes. Defensive remediation still takes days or weeks.
AI increases the tempo
Generative AI is becoming a force multiplier for targeting, social engineering, vulnerability research and malware development.
IBM reports that AI-driven attacks increased 56% year over year, adding an average of USD 1 million to the cost of a malicious breach.
Yet AI is not replacing traditional attack methods. Exploitable systems, stolen credentials, social engineering and third-party access remain highly effective. AI primarily makes these techniques faster and easier to scale.
SOC capacity cannot grow at the same rate
The defensive side cannot simply compensate by hiring more analysts.
According to IANS and Artico Search, security budget growth slowed to 4% in 2025.
Only 45% of CISOs added headcount, while just 11% considered their security organizations adequately staffed.
The result is a structural SOC problem: telemetry, alerts and attack paths continue to grow while human investigation capacity remains limited.
The important question is therefore no longer only how to automate more tasks, but how to reduce the investigation effort required before an analyst can make a sound decision.

From automation to investigation intelligence
Traditional automation works well for predictable actions. Modern incidents, however, require context to be built across users, hosts, identities, network activity, threat intelligence and historical events.
IBM found that organizations extensively using AI and automation reduced breach lifecycles by 65 days and average breach costs by USD 1.93 million.
The next step is therefore not automation for its own sake, but machine-speed investigation with human-controlled decisions.
Where PULZARIS Analyst AI fits
This is the challenge PULZARIS Analyst AI is designed to address. It takes over repetitive, evidence-heavy investigation work by:
- triaging and analyzing security alerts;
- connecting relevant users, hosts and systems;
- enriching incidents with threat intelligence and internal context;
- evaluating risk and business impact;
- producing analyst-ready findings and recommended actions.
PULZARIS follows a human-in-the-loop model: AI performs the investigative heavy lifting, while analysts validate the findings and retain the final decision.
As attackers increasingly operate at machine speed, the competitive advantage will not come from giving SOC analysts more information. It will come from turning alerts into decision-ready intelligence fast enough for humans to remain in control.
Read the full article on our International subsidiary’s website by clicking on the logo:
