The hardest problem in a security operations center is not catching threats. It is the volume. A busy SOC can field thousands of alerts a day, most false, a few real, and an analyst has to tell which is which under a clock that never stops.

The genuine attack gets missed not because no one saw it, but because no one could read fast enough. Software is now taking on that first read, at a scale and speed that changes the math.

The point is not to remove the analyst. It is to replace the endless queue with a short list worth judging.

Where AI actually helps

The work splits into three layers. First, enrichment: the system gathers the context when an alert arrives, without the user and their role, how critical the asset is, recent activity, threat-intelligence reputation, so an analyst is not hunting across tools for the basics.

That context gap stalls more Tier-1 alerts than any shortage of eyes does. Second, triage: judging which alerts are likely noise and which deserve a human, closing or lowering the clear false positives, and escalating the rest with the context already attached.

Third, response: for well-understood, high-confidence cases, running a set action like isolating a host or blocking an indicator. Not every team wants to reach that third layer, and the more damage an action can cause, the more proof the automation owes you.

What this year's winners are building

Most of the volume dies in triage, the call on what is even worth opening, and several winners start there. Radiant Security took the SOC automation award for separating the alerts that need an analyst from the ones that do not, and Command Zero won for an AI-assisted platform that moves an investigation forward without making an analyst chase every log by hand.

Some of the work runs earlier or at a higher volume. AirMDR won for an agentic SOC, AI agents running the routine work that would otherwise eat analyst hours. PRE Security, named one of the year's Most Innovative companies, won for AI-native predictive security operations: using weaker, earlier signals to flag likely trouble first.

Predictive is an easy word to say in this market, and whether it beats a well-written rule comes down to the data.

When something real lands, the race shifts to response. Binalyze was recognized in security automation for gathering forensic evidence and acting on it fast enough to matter mid-incident, and BreachRx won for agentic AI incident response, automating the scramble a breach sets off: the steps, the notifications, the obligations teams usually chase by hand.

ANY.RUN sits closer to analyst acceleration than orchestration, recognized for interactive malware analysis, a safe place to detonate a suspicious file, and watch what it does without a long forensic slog.

Where to keep a human

The hard design choice is where the human stays. High-confidence, low-impact actions, closing a clear false positive, blocking a known-bad hash, can run on their own. Anything disruptive on a critical asset, a domain controller, a production database, broad containment, should wait for a human signature.

And the honest risks cut the other way: a verdict the system cannot explain, a model that drifts as the environment changes, and a confident but wrong call are worse than a slow queue.

The test stays simple: does the tool cut the decisions an analyst has to make, or just add another dashboard?

What to do now

  1. Make sure your data can feed it. AI triage needs real-time access to the telemetry across your SIEM or data lake. If the tool cannot see the data, it cannot read it.
  2. Define acceptable false-positive rates before you automate. Decide what is safe to auto-close, so the machine executes a policy you set rather than inventing one.
  3. Set the human line by impact. Disruptive actions on critical assets wait for a human signature; low-risk, high-confidence ones run on their own.
  4. Demand an audit trail. For every alert it closes, lowers, or escalates, the system should show the signals it used and the policy it applied. A verdict you cannot audit is one you cannot trust.
  5. Measure time saved and load reduced, not alerts seen. Track time to triage and analyst load. If it adds a screen analysts have to check, it has failed.

Let the machine take the first read and the routine response, and keep people on the calls that carry risk. The winners point one way: the machine reads the noise, the human decides what counts.

That makes the volume workable. It does not make it the only design that works.


Part of The Stars Briefing, our editorial series on the trends behind the 2026 Cybersecurity Stars Awards, a program The Hacker News runs. This piece analyzes where the field is moving and uses the winners as examples. It is not a product review. The complete list of 2026 winners is live at awards.thehackernews.com/winners/2026.