Who Should Make the First Triage Decision in a Modern SOC?
The average SOC receives nearly 4,000 alerts per day. Two-thirds are never investigated. When speed determines whether a breach is contained or catastrophic, who — or what — should decide what gets looked at first?
- #soc
- #triage
- #ai
- #operations
The average SOC receives nearly 4,000 alerts per day. Two-thirds are never investigated. When speed determines whether a breach is contained or catastrophic, the question of who makes the first triage decision is no longer academic.
The L1 bottleneck
Tier-1 analysts are expensive to hire, hard to retain, and burn out fast. The classic “every alert gets eyes on glass” model never scaled — and the volume keeps climbing.
Three approaches we see in the field
- Pure automation — playbooks dispose of low-confidence alerts. Fast, but blind to subtle signals.
- AI-augmented L1 — an AI co-pilot triages, an analyst confirms. The current sweet spot for most teams.
- AI-led, human-supervised — the AI makes the call, humans audit a sample. Higher leverage, requires confidence in the model.
Where Blacklight sits
Blacklight’s AI-led triage produces a verdict, a confidence score and a reasoning trail — so analysts can either trust it, override it, or train it. The result: more time on the threats that matter, less time clearing inbox noise.
This article is a placeholder ported from blacklightai.com to seed the resource hub.
Related reading
Book a live walkthrough.
Sixty minutes on a pre-loaded, anonymised environment: one real incident handled end to end, mapped to your sector. No connectors or data required from you.