Intezer: Pair Claude With an AI SOC, Not Use It Alone

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- AI platforms like Claude, Codex, and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work, with the SOC conversation shifting from "whether" AI belongs to "where" each AI fits.
- Intezer outlines a three-layer architecture: existing security tools at the bottom, an autonomous AI SOC investigating every alert in the middle, and AI platforms like Claude at the top where analysts collaborate on higher-value work.
- AI platforms like Claude face a "tokenomics" problem when used for round-the-clock alert triage — an organization would pay for tens of thousands of AI conversations daily, most of which would conclude the alert is benign.
- MDR-reliant organizations hit a structural barrier: managed detection and response providers typically own the investigation workflow, case management, and enriched telemetry, leaving AI platforms like Claude without the raw data needed to reason over alerts independently.
- An analysis of more than 25 million security alerts processed in 2025 found that nearly 1% of confirmed incidents originated from low-severity or informational alerts, undercutting the common practice of investigating only the highest-severity signals.
- Intezer Co-Founder and CEO Itai Tevet and CMO Lital Asher-Dotan are hosting a webinar to walk through where AI platforms and an autonomous AI SOC complement each other in real security operations.
Why it matters: Security leaders evaluating AI spending face a concrete cost trap: routing every alert through a large language model means tens of thousands of daily AI conversations, most of which resolve as benign. The proposed alternative — an autonomous AI SOC handling triage while platforms like Claude help analysts — reframes the buying decision from tool selection to layered architecture, and the 25-million-alert finding makes the case that skipping low-severity alerts carries measurable incident risk.
Ask SkimNews




