The Future of SOC: AhnLab’s Vision for the AI-Native SOC Era
From 610,000 to 1.14 million per month, the volume of threat event tickets handled by AhnLab's SOC nearly doubled in just over a year. Alerts are surging, but security staffing remains limited. With manual security operations alone no longer able to keep pace, AhnLab is looking to AI for the answer. The company is advancing an AI-Powered SOC in which AI and analysts work side by side, while charting a path toward an AI-Native SOC where AI agents drive the entire security operations lifecycle, from detection to response.
From 610,000 to 1.14 Million: The Tipping Point Facing the SOC
Threat event ticket volume at AhnLab's SOC (Security Operations Center) stood at approximately 610,000 in January 2025. Just over a year later, in May 2026, it surpassed 1.14 million.
An 87.66% increase over such a short period signals two major shifts. Attackers are leveraging AI and automation tools to dramatically increase the volume and speed of their operations, while increasingly complex enterprise IT infrastructures are generating more alerts than human analysts can realistically process.
For defenders operating in the SOC, this is a clear indication that conventional security operations have reached a tipping point and can no longer keep pace with today's rapidly evolving threat landscape.
Figure 1. AhnLab SOC Threat Event Ticket Trends (Jan. 2025–May 2026)
Why the Legacy SOC Can No Longer Keep Up
Traditionally, SOC analysts manually reviewed tens of thousands of low-level alerts generated each day by individual security solutions. Even if analyzing a single alert takes only five minutes, processing 30,000 alerts per day inevitably creates operational delays.
With more than 95% of threat analysis performed manually, analysts had limited time available for in-depth forensic investigations or proactive threat hunting. Analyst capacity was exhausted, while genuinely high-risk events risked being buried in overwhelming volumes of alerts.
Legacy environments also relied heavily on signature- and rule-based detection, limiting their ability to identify anomalous activity and previously unknown zero-day threats. In addition, network security appliances, EDR, and other security solutions often operated in silos, making cross-domain correlation and contextual threat analysis difficult.
AI-Powered SOC: A Collaboration Model Between AI and Analysts
The AI-Powered SOC was introduced to overcome these limitations.
It represents a transitional model designed to put AI directly into the hands of analysts. Existing systems remain in place, while AI takes over alert triage, including true-positive and false-positive classification, as well as initial analysis, which traditionally consumed a significant portion of analysts' time.
Where analysts previously had to examine every alert individually, an AI-Powered SOC filters and consolidates tens of thousands of non-actionable alerts into a smaller number of high-priority incidents.
AI performs initial detection and classification while automating repetitive tasks through playbooks, allowing analysts to focus on in-depth investigation of critical events and final decision-making.
As a result, response times that previously ranged from several hours to several days can be reduced to tens of minutes or a few hours.
AI-Native SOC: The Future AhnLab Is Building
Beyond the AI-Powered SOC, AhnLab's ultimate vision is the AI-Native SOC.
This model goes beyond AI simply assisting analysts. Multiple autonomous AI agents, each specialized in detection, investigation, analysis, or response, communicate and collaborate with one another to proactively execute the entire security operations lifecycle.
Moving beyond reliance on manual analysis, the AI-Native SOC enables threats to be investigated through natural-language interactions while AI continuously learns and evolves defensive rules, creating a truly autonomous SOC model.
At this stage, an Agentic Mesh environment emerges, in which multiple autonomous AI agents with specialized roles interact and coordinate activities from detection through response.
Human intervention is minimized as AI applies autonomous reasoning to proactively hunt for threats, enabling the SOC to evolve toward a more autonomous operating model with response times potentially reduced to seconds or minutes.
The role of the analyst evolves as well. Analysts move from directly investigating individual events to reviewing AI-generated analysis summaries and making decisions, and ultimately to serving as architects who oversee AI systems and design customized response scenarios.
Figure 2. Evolution of the AhnLab SOC: Legacy SOC → AI-Powered SOC → AI-Native SOC
AhnLab AI SOC Service: Security Context Combined with Operational Expertise
Built on AhnLab AI PLUS, its proprietary AI platform, AhnLab is developing SOC-specific AI agents and applying AI technology to real-world managed security operations.
One of the greatest strengths of AhnLab AI SOC lies in the combination of the extensive security context accumulated through more than 30 years as an integrated cybersecurity company and more than 20 years of SOC operational expertise.
This strength is particularly evident in the noise reduction process.
AI agents filter non-actionable alerts from billions of security events, identify critical threats that require prioritized investigation, and structure the findings according to a TDIR (Threat Detection, Investigation, and Response) framework before delivering them to analysts.
Alerts with a high likelihood of representing or leading to an actual security incident are escalated and managed as incidents. Customers then receive incident reports that incorporate both AI-generated findings and analysis performed by SOC analysts.
This enables customers to quickly identify the incidents that genuinely require action from within massive volumes of security alerts.
Figure 3. Key Strengths of AhnLab AI SOC
AhnLab AI SOC: Technology, Process, and People Combined
A reliable AI SOC service requires three core pillars, Technology, Process, and People, to work together seamlessly.
AhnLab AI SOC is likewise designed around the fundamental operating framework of a traditional SOC, with technology, security processes, and analysts tightly integrated.
In the Technology domain, AhnLab Sefinity and AhnLab XDR collect high-volume logs generated across a wide range of security systems and process events in conjunction with AhnLab AI PLUS.
In the Process domain, SOAR playbooks automate repetitive tasks and establish standardized response procedures.
In the People domain, L1 and L2 analysts, along with specialized security analysts, perform in-depth investigations and provide final validation and approval.
By tightly integrating technology, processes, and human expertise, AhnLab provides operational stability while continuing to build an advanced security operations framework that evolves from the conventional SOC toward the AI-Native SOC.
Figure 4. AI SOC Operating Framework: Technology, Process, People
A Blueprint for the AI-Native SOC
The previous sections describe the AI-Powered SOC that AhnLab is currently advancing. AhnLab's ultimate vision, however, is the AI-Native SOC.
In legacy network security monitoring environments, playbooks were capable of processing approximately 85% of standardized events, but analysts still had to devote significant resources to the remaining 15%.
MDR services, meanwhile, depended heavily on analyst expertise, with security events requiring extensive manual analysis.
At the AI-Powered stage, automation extends into the 15% of workflows that previously required analyst intervention. In MDR environments, AI-driven triage can also filter out events that fall within normal operational baselines, enabling analysts to focus on critical threats and high-risk events.
AhnLab's next step goes further.
In an AI-Native SOC environment, AI, workflows, and analysts converge into a unified Human-in-the-Loop ecosystem.
The scope of automated response expands, telemetry coverage increases significantly, and Agentic AI evolves to execute customized response scenarios tailored to each customer's business environment.
Beyond the SOC: Toward an AI-Powered Unified Security Platform
At the center of this vision is AhnLab's proprietary AI platform, AhnLab AI PLUS, which serves as the intelligence engine behind the AI-Native SOC.
AI-Native Operations span AI-Triage, AI-Insight, and AI-Investigation, ultimately evolving toward an AI Decision Intelligence stage in which AI autonomously accumulates knowledge and determines workflows.
At this stage, AI takes the lead across investigation, analysis, and response.
AI effectively operates as a SOC analyst, performing comprehensive analysis, generating reports, and carrying out initial response actions.
Customers can use the Portal Assistant to handle tasks such as basic technical support inquiries, security event searches, and report generation. SOC analysts, meanwhile, focus on incident investigation, security operations support, and working alongside AI as part of the overall security operations process.
In other words, AhnLab AI SOC is not simply an outsourced service that monitors customer alerts and passes them along.
Its goal is to deliver an AI-powered unified security platform that provides integrated protection and security operations across the customer's entire infrastructure.
Figure 5. AhnLab AI-Native SOC
The Future of the SOC, as Envisioned by AhnLab
As cyber threats continue to expand in both volume and sophistication, manual response by security professionals has already reached its practical limits.
Through AI SOC, AhnLab aims to eliminate noise from overwhelming alert volumes and enable security teams to move beyond the role of alert handlers and focus instead on becoming security architects who establish enterprise security standards and response frameworks.
To achieve this vision, AhnLab will continue building on its AI technologies and more than 20 years of SOC operational expertise, advancing the AI-Powered SOC where AI and analysts collaborate and ultimately realizing the AI-Native SOC where AI takes the lead from detection through response.
Through this evolution, AhnLab will continue advancing toward an AI-powered unified security platform.
See How AI Agents Analyze Security Events in the SOC
Watch AI agents from AhnLab AI PLUS analyze security events and assess their impact in a SOC environment.
→ Watch the AhnLab AI PLUS Demo- AhnLab