ZENTARA

Future-Proofing the SOC: Defend Against AI Threats with AI-Assisted Ops

Explore how AI-assisted SOC operations can reduce alert fatigue, prioritise threats, accelerate investigations, and improve response times while keeping human judgement and evidence at the centre.

Zentara Team6 min read
Future-Proofing the SOC: Defend Against AI Threats with AI-Assisted Ops

A SOC team's problem is rarely too little data. It is too much. Thousands of alerts land every day, and when every one of them looks equally urgent, people stop reading them carefully. The alerts that actually matter get buried in the pile. That is alert fatigue, and it is the quiet failure mode behind a lot of missed intrusions.

AI is now pressing on both sides of that problem. It reshapes the threats hitting your SIEM, and it reshapes how fast a team can triage them. That was the subject of Zentara's recent webinar, "Future-Proofing the SOC: Defend Against AI Threats with AI-Assisted Ops.”

The session was a practical, from-the-trenches walk through modern security operations: where AI genuinely helps, where human judgment still has to lead, and how the two fit into a SOC built to hold under pressure. Much of it was shown live inside Odyssey, Zentara's SOC console, against real alerts rather than staged screens. This article covers the same ground.

Cut Through Alert Fatigue

The first job is visibility. Before you alert anyone, you need one picture instead of a wall of separate signals.

That is a data-consolidation problem before it is an AI problem. ZX, Zentara's SIEM layer, pulls signals from IT, OT, and cloud systems into one place in real time, with more than 200 systems it can ingest from out of the box. Instead of an analyst stitching together five consoles, the picture arrives already assembled. From there, the system flags urgent issues to the right person automatically and produces dashboards already mapped to compliance checks like ISO 27001, PCI DSS, and NIST.

The point is sequence. Gather everything into one view first, then decide who needs to act. Triage on a fragmented picture is guesswork, no matter how good the analyst is.

Detection That Ranks What Matters

AI changes how threats get flagged. Not by replacing an analyst's judgment, but by narrowing down what deserves their attention first. It helps separate what is actually risky from what only looks alarming on paper.

Three mechanisms carried this section:

  • Ranks by real risk. Detection looks at how likely and how damaging a threat actually is, rather than assigning a generic severity score that treats every "high" the same.
  • Always watching. Systems are scanned continuously, not once a year like a traditional audit. Blind spots get surfaced and ranked automatically.
  • Double-checked. Every result is verified before it reaches a person, so analysts spend less time chasing false alarms.

The through-line is prioritization. AI is most useful here as a filter that decides what a human should look at first, not as a judge that decides whether a threat is real.

Faster Evidence, Same Rigor

When something goes wrong, investigators lose hours to the slow, repetitive parts of the work before real analysis even begins. Pulling raw logs. Building a timeline by hand, which is slow and easy to get wrong under time pressure. Connecting activity across systems.

This is where AI earns its place in forensics. It speeds up the legwork: gathering evidence automatically, ordering it into a timeline step by step, and suggesting a likely root cause with the supporting proof attached. What it does not do is make the final call. A person still owns the verdict.

The boundary matters because a forensic conclusion has to survive scrutiny. Every AI answer needs proof behind it, not a confident-sounding guess. Speed is only useful if the rigor holds.

Ground the Model in Verified Data

An AI tool is only as trustworthy as what it is allowed to say. The simplest rule that matters: never let it guess when it can check first.

Iqbal framed this as an evidence-first workflow that separates three things clearly:

  • What it knows. Facts pulled straight from the logs and alerts, with nothing invented.
  • What it figured out. The reasoning is visible, so you see why it reached a conclusion, not just the conclusion itself.
  • What is still unclear. Anything unconfirmed is marked as unconfirmed, rather than smoothed over into false certainty.

A person makes the final call, not the model. Zentara Labs is building this evidence-first approach directly into its next generation of investigation tools, still in development, but grounded in the same principle already used in ZX and AVAS.

The live run inside Odyssey made the idea concrete. One click starts an investigation, and every step is visible on screen: done, in progress, or waiting its turn. Nothing gets shown as an answer until all the evidence is actually in. No rushed conclusions, no answer ahead of its proof.

Resilience Is a Response Time

Defending against AI-driven threats is not fundamentally different from defending against any other threat. It just has to happen faster, and more consistently.

The session tied resilience to concrete response times, matched to severity:

  • Critical: 15 minutes. An analyst steps in right away with a plan to contain it.
  • High: 1 hour. The evidence is reviewed and escalated if confirmed.
  • Medium: 4 hours. Queued with full context ready, so no one restarts the investigation from scratch.

Underneath those numbers sits round-the-clock monitoring by certified analysts who actively hunt for threats rather than waiting for alerts to arrive. All of it aligns with standards like ISO 27001, PCI DSS, NIST CSF, and OJK. Resilience, in other words, is not a posture. It is a measured response time you can staff against.

Five Ideas to Take Back to Your SOC

If you take nothing else from the session, take these.

  • Pull everything into one picture before you alert anyone. Triage on a fragmented view is guesswork.
  • Rank threats by how real and how damaging they are, not by a flat severity label.
  • Let AI do the legwork; let people make the final call. AI narrows what a human needs to look at. It does not replace the judgment they apply once they are looking.
  • Every AI answer should come with proof attached. An ungrounded answer is a liability, however confident it sounds.
  • Respond faster to bigger threats, and staff to match. Response time is the real measure of resilience.

Final Thought

AI is reshaping both sides of security operations at once, the attacks coming in and the tools used to answer them. The teams that stay ahead are not the ones that hand the most work to a model. They are the ones that use AI to move faster while keeping every decision traceable to real evidence and a human owner.

Zentara's Cybersecurity teams and Zentara Labs build tools like Odyssey for exactly that kind of environment, where the answer has to hold up under audit and every conclusion traces back to a mechanism, not a guess.

If your team is working through where AI fits in your own security operations, that is a conversation we are glad to have. Talk to our team.

More like this, monthly.

What our teams are seeing in Indonesian threat activity and regulatory movement — written by the people running the SOC.

We use your address to send what you asked for and nothing else. No list is sold or shared. Privacy policy.

Have a security question this raised?

Our engineers answer directly — no qualification call first.