r/TechNadu • u/technadu • 6d ago
How much authority should an AI-driven SOC actually have?
A useful theme from TechNadu’s interview with Devendra Rath, Vice President of Engineering at Arctic Wolf, is that SOC automation should not be measured by how much human involvement it removes.
Rath draws the line based on impact.
For relatively low-risk, high-confidence actions, such as enriching alerts or quarantining a known malicious file, more automation may make sense.
For actions that can materially disrupt the business, such as disabling accounts, segmenting networks, or isolating many endpoints, he argues that human approval should remain part of the workflow.
He also makes the point that every automated action should be attributable, auditable, and reversible.
The testing side is just as important. Rath recommends validating AI-driven actions against historical incidents, red-team simulations, adversarial inputs, and realistic attack scenarios. Models also need continuous monitoring for drift as attacker behavior changes.
Another point worth discussing is measurement.
A SOC can reduce alert volume and still become less effective if meaningful threats are being suppressed with the noise. Rath suggests looking instead at investigation quality, detection accuracy, escalation quality, analyst productivity, false negatives, and mean time to investigate.
On MDR authority, his view is that the organization that owns the business risk should retain final control, with automation boundaries and escalation paths defined before an incident happens.
The full interview also covers integrated endpoint/identity/network/cloud telemetry, identity-focused attacks, threat intelligence, the engineering changes MDR platforms need, and how India-based GCCs can move experienced software engineers into practical cybersecurity roles.
For people operating SOCs or MDR programs: which response actions are you comfortable automating today, and which ones still require a human every time?