IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Why the SOC needs to be re-engineered for AI

Why the SOC needs to be re-engineered for AI

Thu, 17th Sep 2026 (Today)
Simon Chassar
SIMON CHASSAR Chief Operating Officer e2e-assure

Concerns over frontier models running amok have reached fever pitch with Anthropic revealing its Claude model has accessed third party systems without authorisation four times now. The Trump administration has also vetoed the testing of Anthropic's latest model - Claude Mythos 5.1 - by the UK-based AI Security Institute (AISI) which is the first time the organisation has been denied access, fuelling concerns over AI sovereignty.

What this all points to is the need to increase our ability to defend against AI. It's this need that saw GCHQ Director, Anne Keast-Butler declare that the UK would be develop an AI Cyber Shield, "a new national cyber defence capability that will hardwire cutting-edge agentic AI into machine-speed cyber defence". But what's less clear is how that capability will be delivered.

While AI-assisted Security Operations Centres (SOC) exist today, they still follow the same process as their predecessors in that they are alert-led. An event occurs, triggering an alert, and a case is created for the analyst to investigate. AI is used purely to expedite the process by assisting with triage, enrichment, summarisation, correlation and recommendations. But it acts after the fact, so is basically playing catch-up, because by the time that alert is triggered, the events that produced it have already happened. All of that is captured in the raw telemetry that comprises the chain of causation, but bizarrely AI is being used at the end of that process, not at the beginning when that data is created.

Putting AI first

It is, of course, possible to correct this but it requires the re-engineering of the SOC to ensure AI reasoning happens closer to the event stream. This isn't just about AI-enabling the SOC; it's about completely changing how it functions, so behavioural detection is run continuously, not just when an alert is triggered, and detection engineering also happens earlier in the process, allowing rules to express patterns on the stream as well as against those stored. Yet changing where and how these functions kick-in can be transformative because now the SOC can perform continuous as opposed to point-in-time threat hunting. That is a game changer as it effectively equips the SOC to become a zero-day detection engine, capable of applying live or new threat intelligence immediately as detection rules. Consequently, the risk posed by emerging threats can be eliminated and incidents can be prevented, providing predictive threat detection for the first time.

But putting AI front and central also provides additional benefits. For instance, those detections can be reviewed by a council of AI models, each of which is focused on one element of threat detection and response. Collectively, they provide a coherent interpretation of events that gives weight to any remediation advice. But they may well also disagree and that too can be useful as it allows the human analyst to see exactly where and why those dissenting opinions have arisen and to make an informed judgement.

Of course, those industries most in need of this form of AI threat detection are those deemed of national importance. Highly regulated industries such as finance or manufacturing or those deemed critical national infrastructure (CNI) such as data centres and utilities providers will no doubt be the first to benefit from the Cyber Shield initiative. They stand to benefit if the SOC is re-engineered in two key ways.

Local and large AI 

Firstly, they can reduce their dependency on foreign AI models or cloud infrastructure by deploying a layered AI architecture that separates sensitive operational reasoning from broader intelligence and research capability. A local model layer handles environment-specific detection and analysis, a security intelligence layer aggregates and correlates threat data at scale, and a frontier model layer is used for non-sensitive enrichment and broader analytical tasks. This structure ensures that sensitive data remains contained while still enabling advanced AI capability where appropriate, supporting both compliance and performance requirements. 

If dedicated local large language models (LLMs) specific to the organisation are deployed and trained on each organisation's specific environment, they can provide accurate, context-aware reasoning that reflects that estate. As inference occurs within that controlled infrastructure, the organisation retains full sovereignty over sensitive security data and reduces reliance on external cloud AI services. In effect, by keeping models local, these organisations ensure their defensive capability remains regardless of external circumstances.

Digital twinning with AI

Secondly, a dedicated AI capability can be used to stand-up a continuously maintained digital twin of the environment. Using passive discovery across IT and operational technology (OT) systems, this digital twin can enable safe attack simulation, risk identification before exploitation and immutable preservation of analytical integrity. This is particularly valuable within CNI environments where live testing is often impractical due to downtime or where it carries unacceptable operational risk.

Keeping sensitive operational knowledge within customer-controlled environments has to be a prime consideration when looking to roll-out the Cyber Shield. This will help tp reduce exposure to external disruption and ensure these organisations maintain visibility and cyber defence capability even during major incidents, connectivity outages or wider infrastructure disruption.

Re-engineering the SOC to fully utilise AI in these ways is therefore not just advisable, its advantageous. But it's also vital if we are to make the Cyber Shield a reality and improve our ability to defend against AI invaders, to reduce our dependency on foreign models and to provide CNI and other industries with the benefits a sovereign AI environment can confer.