SOC Design Should Mirror Kahneman's Dual Systems

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Research on more than 25 million enterprise alerts found 98% can be resolved autonomously while only ~2% warrant human review — a ratio the author notes is almost identical to Kahneman's 95%/5% System 1/System 2 split.
- An enterprise receiving 450,000 alerts per year can expect roughly 54 real threats hidden in low-severity alerts that never make it to an analyst's queue because triage capacity runs out.
- Autonomous SOC AI investigates 100% of signals continuously, reaches verdicts at 98% accuracy in under two minutes, and hands human teams only the 2% of cases that warrant attention, with all evidence pre-assembled.
- Frontier AI platforms like Claude, Codex, and Cursor belong in the "slow brain" role — complex case analysis, detection rule engineering, threat hunting — but should receive fully investigated cases, not raw alerts, the author argues.
- Outsourcing alert investigation to MDR providers means the enterprise doesn't own the knowledge layer (detection rules, case history, triage logic) that compounds to make AI copilots more effective, making in-house investigation a prerequisite for the architecture to work.
Why it matters: Security teams are running both failure modes simultaneously — burning human analysts on System 1 triage work and deploying expensive frontier models directly against raw alert streams. The essay argues that owning investigation in-house, rather than outsourcing to MDRs, is now the prerequisite for making AI copilots useful, since the institutional knowledge that makes the slow brain smarter only accumulates inside the enterprise's own instance.




