
03.07.2026
AI in the SOC delivers measurable added value in detection, prioritisation, and alert analysis. At the same time, autonomous decisions without human control remain risky. Sebastian Bittig, Director of Cyber Defence at r-tec as part of the accompio group, explains what is realistically possible today and what companies should pay attention to in an expert interview.
AI in SOCs is already delivering measurable value today, but within clearly defined areas. The fully autonomous Security Operations Centre without humans remains a manufacturer's promise that doesn't hold up in operational reality. Sebastian Bittig, Director of Cyber Defence at r-tec, part of the accompio Group, operates managed SOC services for companies daily and explains what AI can already achieve today, where the limits lie, and how decision-makers can find the right provider.
Sebastian Bittig explains in the full video interview which applications for AI in SOC are already working, where artificial intelligence reaches its limits, and how companies can distinguish marketing promises from real benefits.
A Security Operations Centre, or SOC, monitors a company's IT infrastructure around the clock, detects security incidents, and coordinates the response to them. AI in the SOC denotes the targeted Application of Machine Learning, automated analysis tools and Large Language Models, to support analysts in these tasks.
Today, SOC teams are not limited by a lack of data, but by an overabundance of it. According to PwC, SOCs receive up to 50,000 alerts daily, of which 30 to 40 per cent remain unaddressed. Attacks are becoming faster, more automated, and more targeted. Simultaneously, there is a shortage of qualified personnel: 71 per cent of SOC analysts report burnout, according to PwC.
Classical rule-based systems do not solve this problem because they react statically and only recognise what has been previously defined. AI picks up precisely here, by anomaly-based detection and Context-based prioritisation.
Sebastian Bittig, Director of Cyber Defence, describes four areas from r-tec's daily operational reality where AI functions reliably today:
Machine learning has been detecting attacks for years anomaly-based. This means: a SOC team doesn't need to know what an attack looks like in detail beforehand. The model learns what normal behaviour in an environment means and raises an alarm when something deviates from it. This is a structural advantage over rule-based systems, which only capture known patterns.
In a Managed SOC, a very large number of alarms arrive simultaneously every day. AI can incorporate significantly more context than rule-based systems: Behavioural context, Threat intelligence, Asset criticality and Historical patterns flow into the evaluation simultaneously. The result is a significantly more precise prioritisation that focuses analysts on the truly relevant alarms.
When an analyst receives an alert, they must investigate, assess, and triage it. AI provides a structured approach to this in a short amount of time Summary of the alarm including the relevant context. What previously meant hours of manual research can thus be turned into a well-founded Initial assessment in minutes Compress.
SOC analysts work with many different tools, each with its own query syntax. AI now makes it possible to search in natural language, rather than having to master system-specific query languages. The question „Did user X log in to system Y at a specific time?“ can be asked directly, without needing to know the syntax of the respective SIEM system. This efficiency gain is considerable in daily operations.
The fully autonomous SOC remains a promise. Sebastian Bittig clearly identifies the limit:
„That's the case everywhere where AI is supposed to make completely independent decisions. I cannot use the AI entirely on its own to close alarms independently, as this carries the risk that something will be overlooked.“
— Sebastian Bittig, Director of Cyber Defence at r-tec (part of the accompio Group)
Three borders are particularly relevant:
Even if no errors are detectable in the input data, AI systems can produce incorrect results. A model that works with an incomplete dataset may fill these gaps with plausible-sounding but false conclusions. In the SOC context, this means that AI outputs must be continuously reviewed by analysts. Anyone who uncritically accepts AI results risks a false sense of security.
The reliability of AI systems is significantly dependent on the data on which they operate. Unstructured, incomplete, or data not adapted to one's own environment do not lead to better results, but rather to faster errors. This is precisely where many AI projects in the SOC fail. The system is introduced but not calibrated to the specific infrastructure and threat landscape.
A SOC with unclear responsibilities, missing playbooks, or inadequately qualified personnel will hardly benefit from the deployment of AI. AI amplifies what is already there. Anyone hoping to bridge organisational deficits with technology will be disappointed. The foundation must be sound before AI can unfold its added value.
The greatest success is rarely achieved through the use of a single AI solution.
Even more important is integration into existing processes. AI should supplement existing workflows, not replace them. Companies benefit particularly when clear responsibilities exist and AI is transparent in Analysis-, Escalation- and Decision-making processes is incorporated.
„AI is a tool that provides support, but it certainly does not replace existing SOC processes. AI must be integrated into existing processes. As things stand, we are still a long way from a fully autonomous SOC.“
— Sebastian Bittig, Director of Cyber Defence at r-tec (part of the accompio Group)
Not every solution that advertises AI automatically offers genuine added value. Therefore, before investing, companies should ask the following questions, among others:
For the technical evaluation, the measurement of three metrics is recommended: Accuracy rate How often does the AI make the correct assessment?, Hallucination rate (how often does the model invent information?) and Output latency (how quickly does AI deliver usable results?). Only those who know these key figures can assess the actual added value. Anyone wishing to evaluate AI solutions for the Security Operations Centre should not be guided by marketing promises, but should focus on comprehensible deployment scenarios and measurable added value.
Our services in the area of Cyber Security and AI as a service support companies in classifying suitable solutions and integrating AI meaningfully into existing security processes.

accompio helps organisations to objectively evaluate AI technologies and integrate them seamlessly into existing SOC strategies.
The fundamental change is not about technology, but about people. The job of the SOC analyst is fundamentally changing with AI. In the future, the ability to, AI expenditure should be assessed critically, to interpret complex attack patterns and make decisions that a model alone cannot make. According to PwC, analyst productivity in AI-supported SOCs is increasing by Factor 3 to 5, what does: the same analyst covers more, not that fewer analysts are needed, mean.
The use of AI in SOCs creates an additional area of tension in the DACH region: the more AI operates in SOCs, the more the AI itself becomes a potential attack surface. Attackers are increasingly exploiting AI vulnerabilities to deceive detection systems or deliberately influence models with false data.
For companies in Germany, the regulatory context is also added: NIS-2 and DORA increase the requirements for traceability and transparency in security processes. AI decisions must be verifiably traceable and auditable, which makes black-box approaches structurally problematic. Those who use AI in the SOC must be able to explain how a decision was reached, not only internally but, if necessary, also to supervisory authorities.
Developments in the SOC are clearly heading in one direction: AI agents are being integrated more and more closely into existing products. Many manufacturers have already started this, but the quality of this integration varies greatly. The fully autonomous SOC is a realistic goal for the future, but not a state that will be achieved any time soon. The path towards it is gradual, with increasingly automated sub-areas and simultaneous human control.
Due to the ever-changing threat landscape, the Use of AI in the SOC but already indispensable today. Attackers are increasingly using AI themselves to automate attacks, bypass detection systems, and find new vulnerabilities faster. Those who forgo AI on the defence side are operating at a structural disadvantage.
AI will sustainably transform the Security Operations Centre. It accelerates analyses, reduces manual effort, and supports analysts with increasingly complex attack scenarios. However, the decisive success factor remains the combination of powerful technology, established processes, and experienced security experts. Those who strategically understand AI as a support and not as a panacea can already create real added value for their SOC today. R-tec and accompio support companies in exactly this step.

Sebastian is a security expert and keeps an eye on solutions and trends in Managed SOC Services for companies.
AI in the SOC refers to the supportive use of machine learning and AI tools for tasks such as detection, prioritisation, and summarisation. A fully autonomous SOC would make independent security decisions without human intervention. This is not technically mature today and is operationally too risky, due to the danger of overlooking real threats.
The greatest benefit arises where security teams need to analyse large volumes of events daily. AI helps to prioritise alerts, contextualise security-relevant information, accelerate incident investigations, and automate recurring tasks. This allows analysts to focus more on complex security incidents and strategic decisions.
Not directly. AI does not generate a smaller number of security incidents, but it can help to assess them more efficiently. Modern AI solutions assist in recognising false alarms more quickly, summarising similar incidents, and better prioritising critical events. This reduces the manual effort for security teams, even if the number of incoming alerts often remains the same.
AI works based on existing data and models. It reaches its limits with completely new attack methods, company-specific peculiarities, or strategic security decisions. Misjudgements are also possible, which is why AI results should always be traceable and reviewed by experienced analysts.
Yes, provided that the basic security processes are already in place. Medium-sized companies in particular stand to benefit when AI takes over routine analytical tasks and lightens the workload on existing teams. This requires effective integration into existing processes and a high-quality database.
Yes. Provided that the basic security processes are already established. Small and medium-sized enterprises, in particular, benefit when AI takes over recurring analysis tasks and relieves existing security teams. However, this requires sensible integration into existing processes as well as a high-quality data basis.
Companies should question which functions are truly AI-powered and what concrete added value they deliver in everyday operations. Important criteria include comprehensible decisions, transparent models, integration into existing SOC processes, and measurable improvements in analysis speed, prioritisation, or incident response. General AI promises without robust use cases should be critically assessed.
AI is particularly suitable for the pre-analysis of alerts, enriching security events with contextual information, summarising large volumes of data, assisting with investigations, and creating initial recommendations for action. In contrast, fully autonomous security decisions are currently only sensible in clearly defined and controlled scenarios.
AI continuously improves threat detection and can trigger automated responses to defined events. Nevertheless, there is currently no solution that reliably detects all attacks independently and repels them entirely without human control. A modern Security Operations Centre therefore combines AI support with experienced analysts and established security processes.
In the coming years, AI will continue to gain importance, particularly in analysis, contextualization, and automation. Security analysts will be increasingly supported by intelligent assistants that provide information faster and take over routine tasks. At the same time, human expertise, sound processes, and clear governance remain central prerequisites for an effective Security Operations Center.

Arrange an initial consultation