Prophet Security finds 1 in 3 security alerts go uninvestigated as AI use surges
Prophet Security’s new report says 96% of organizations are using or evaluating AI for security operations as alert volumes rise and attackers increasingly use AI. The findings suggest SOC teams are turning to automation to close staffing gaps, reduce investigation times and keep up with incidents that can otherwise escalate into material business risk.
Why it matters: - Security operations centers are under strain from alert overload, AI-powered attacks and analyst shortages. - Prophet Security’s research shows AI is becoming a core SOC tool, not a pilot project, as teams look to investigate more alerts and respond faster. - The findings point to a growing gap between what security teams generate, what they can review and the risk of missing real incidents.
What happened: - Prophet Security released its Second Annual State of AI in Security Operations Report at Black Hat 2026 USA in Las Vegas. - The independent survey, conducted by ViB, included 250 IT and cybersecurity professionals. - The report found that 96% of organizations are already using or evaluating AI for SOC workflows. - Kamal Shah, co-founder and CEO of Prophet Security, said traditional security operations can no longer keep pace with current alert volumes or AI-powered attackers. - Shah said organizations seeing the strongest results are using AI to investigate every alert, reduce response times and shift analysts toward higher-value work.
The details: - 74% of organizations receive more than 50 security alerts per day. - More than one-quarter receive more than 500 alerts daily. - The average security investigation takes about 75 minutes. - Organizations leave an average of 28% of alerts uninvestigated because they do not have enough time or resources. - 60% of respondents said an alert that was never investigated later became a material security incident, including customer data exposure, operational disruption or measurable business risk. - 40% said their organizations have disabled or considered disabling detection rules because they lacked the resources to investigate the alerts those rules generated. - 40% already use AI in day-to-day SOC workflows. - 56% are actively evaluating or piloting AI-powered SOC solutions. - Only 4% have no plans to adopt AI. - Among organizations already using AI in security operations, 72% cut alert investigation time by at least 25%. - 18% cut investigation time by more than 50%. - Common success metrics include faster mean time to respond, better around-the-clock coverage, fewer false positives and faster investigations. - Prophet Security’s Agentic AI SOC Platform autonomously investigates alerts, accelerates incident response, performs continuous threat hunting and optimizes detections across the security operations lifecycle. - More than half of respondents, 56%, said they saw an increase in AI-driven attacks over the past year. - That figure rose to 63% in financial services and 58% in healthcare. - The most common attacks included phishing and social engineering with signs of large language model-generated content, followed by deepfake-enabled fraud and more sophisticated credential attacks. - 57% expect AI to significantly reshape SOC responsibilities without reducing headcount over the next two years. - Another 9% expect security teams to grow. - Teams doing proactive threat hunting weekly or continuously uncovered malicious activity that existing detection tools missed nearly half the time. - Data privacy was the top barrier to broader AI adoption at 44%. - AI transparency followed at 41%. - Nearly half of organizations that tried to build their own AI-powered SOC capabilities abandoned those efforts or replaced them with commercial platforms.
Between the lines: - The report suggests AI is shifting from a convenience layer to an operational necessity in security teams. - The data also shows a practical limit to DIY security AI, with many organizations moving back to commercial platforms after internal efforts proved too difficult to sustain. - The emphasis on privacy and transparency signals that buyers want automation, but not at the expense of control or explainability.
What's next: - Security teams are likely to keep expanding AI use as alert volumes and attacker sophistication rise. - Prophet Security says the full 2026 State of AI in Security Operations report is now available. - The company says its platform is designed to reduce mean time to investigate, mean time to respond and improve team productivity.
The bottom line: - The SOC is being reshaped by AI because manual workflows are failing to keep up with modern alert loads and AI-enabled threats.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
My Health News Nevada
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.