Why security teams need recommendations – not notifications

Why-security-teams-need-recommendations-not-notifications

Craig Sanderson, Principal Cyber Security Strategist, Infoblox highlights why security teams need recommendations – not notifications.

Security has spent years solving a “visibility” problem.

Organisations have invested in tools capable of collecting, analysing, correlating and storing vast quantities of data about what’s happening across network environments.

For the most part, it’s been successful – perhaps even too successful, because it’s become something of a crutch.

Every login attempt, network connection, device interaction, badge swipe, application request and configuration change can now be monitored, recorded and surfaced for investigation.

On paper, it should be a golden age for defenders.

Never before have organisations possessed such detailed data to understand the operation of their business, or such an extensive ability to detect suspicious behaviour.

But despite this abundance of information, the question that haunts every SOC remains the same: “What do we do now?”

This question highlights a growing and structurally important disconnect within modern security operations.

The industry has become exceptionally good at identifying potential problems.

But identifying a problem and understanding how to respond to it are two very different things.

An alert can tell an analyst that something unusual has happened, but what it can’t do is explain the significance of that finding within the broader context of the organisation.

It can’t determine on its own whether immediate action is required or provide guidance on what should happen next.

As digital environments become larger, more interconnected and shaped by machine-speed activity, the gap between “detection” and “decision” is widening.

Visibility used to mean everything, but in achieving near-perfect visibility, a new set of challenges has emerged.

Visibility is no longer the problem

More information leads to better outcomes.

At least, that has always been the mantra for security teams. If defenders can see more of what’s happening inside their environments, they should be able to identify threats earlier, understand them more clearly and respond more effectively.

That concept has driven years of investment in monitoring technologies across both the digital and physical worlds – but information and understanding are not the same thing.

A modern SOC can possess near-continuous visibility into thousands of assets and still struggle to answer relatively straightforward questions during an incident.

  • Is this activity genuinely suspicious or merely unusual?
  • Is it connected to something already under investigation?
  • Does it represent an immediate threat to operations, or can it wait until tomorrow morning?

Organisations have worked hard to unearth signals, but now they’re left with signal overload. Parsing these signals is even more important as network environments become increasingly complex.

A single event can ripple across multiple systems, teams and environments in ways that are difficult to interpret from any one alert alone.

What appears to be a minor anomaly on its own may prove to be the first visible symptom of a larger problem, while a seemingly critical alert may turn out to be trivial or easy to isolate.

It’s a peculiar and unnatural situation for teams to be in. While they have access to more information, they still spend a portion of their time trying to establish context and join the dots.

They “won” visibility, but need a new set of lenses to understand what they’re seeing.

Human investigation does not scale

Alerts have no intrinsic value on their own.

They offer a key to the door, but tell us nothing about what to do when we get inside and look around.

Long before any decision can be made, somebody has to investigate what happened, determine whether the activity is legitimate, understand the systems involved, assess potential business impact, establish priority and then decide on an appropriate response.

Experienced analysts perform these tasks almost instinctively because they have the benefit of context.

They know the organisation’s environment, can recognise patterns from previous incidents and can distinguish between activity that is unusual and activity that is genuinely dangerous.

That contextual intelligence is where the real value lies – not in the alert itself.

This pattern of using tech to highlight anomalies before handing off to a human expert has been the dominant assumption for years.

But today’s challenge is less about scale than it is about speed, and the nature of the threat is shifting in ways that make the old model untenable.

Frontier AI models have demonstrated the ability to discover previously unknown vulnerabilities at machine speed, chain exploits across complex systems and identify attack paths that would take humans months to uncover.

The same class of capability will eventually reach attackers, compressing the time from discovery to weaponisation from months to minutes.

In that world, a SOC operating on a model of human-driven, alert-by-alert investigation isn’t just inefficient, but incapable of keeping pace.

The data confirms the pressure is already reaching breaking point.

According to the 2025 Pulse of the AI SOC Report, 88% of SOC teams say alert volume has increased in the past year.

Alert fatigue is also cited as a top operational challenge by 76% of security operations teams.

Whilst human expertise will remain indispensable, expertise alone doesn’t create more hours in the day.

And it certainly doesn’t operate at machine speed.

From response to policy

The structural answer to this problem isn’t more analysts doing the same work faster.

It is a redesign of what the SOC analyst’s job is.

Today, too many analysts, including senior ones, spend the majority of their time on tasks that don’t require their expertise. This is the work that AI can and should be doing.

Rather than replacing the analyst, Agentic AI replaces the drudgework that consumes so much of the analyst’s day.

But the more important shift is what this unlocks at the strategic level.

The future of security operations is not an analyst responding to alerts; it is an analyst defining the policies that govern how AI should respond.

The operations team sets the conditions, and AI then monitors continuously for those conditions and executes the policy-defined response – without waiting for a human to work through a queue, gather context and make a decision.

Whilst the direction of travel is clear – the question is how quickly organisations can make the transition.

Recommendations: the new security interface

Security teams don’t actually want alerts – they want context and certainty.

An alert is merely the mechanism by which uncertainty announces itself, arriving on a dashboard with just enough information to create concern and rarely enough context to resolve it.

Every alert immediately triggers a chain of questions.

The alert itself answers none, but hands them over to a human operator and asks them to figure it out.

AI can effectively “create more hours in the day” by taking that burden away.

Rather than presenting analysts with another event to investigate, AI can provide the full context surrounding that event, drawing together information from multiple sources, identifying likely causes, assessing potential impact and recommending courses of action.

Better still, within a policy-driven model, AI doesn’t just recommend – it acts.

An incoming alert for suspicious outbound traffic can be pre-triaged, correlated with known threat intelligence, enriched with identity and asset context, scored for risk and matched against a pre-approved response playbook, all within seconds of detection.

The analyst’s role in this model is elevated.

Instead of being preoccupied with a mountain of alerts, the analyst is focused on orchestrating a security posture operations plan: defining the policies, tuning the response playbooks, reviewing AI-generated summaries of what was handled autonomously and applying expertise to the genuinely novel situations that fall outside the scope of established policy.

That is work worthy of a skilled professional.

Spending half a shift manually collecting data from disparate systems is not.

The urgency is now

The security industry has spent years honing its ability to answer, “What happened?” The next big question is, “What should we do about it, and how should we respond – automatically, at scale and before the window closes?” That urgency is amplified by the emergence of Mythos-class frontier AI models.

As these capabilities eventually reach a broader threat landscape (as history suggests they will) attackers will not need deep expertise to discover exploitable conditions, chain vulnerabilities or identify the fastest path to their objective.

They will ask their AI, and it will oblige.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox