Automation has become one of the major goals of modern SOCs. However, more automation doesn't always mean better work. In fact, trying to automate immature or poorly defined processes can create more problems than benefits.

The SOC Critical Path (SCP) model positions automation as a support element for the entire SOC operational cycle. Its purpose is not to replace the analyst's judgment, but to eliminate repetitive tasks that consume time and delay the response to an incident.

The question, therefore, is not what can be automated, but what is truly worth automating.

Not all SOC work should be automated

An investigation typically combines tasks of very different natures. Some require expertise, analysis, and decision-making. Others are repetitive and always follow the same procedure.

For example:

  • Automatically query information about an IP address, domain, or hash.
  • Obtain data about the affected asset or the user involved.
  • Enrich an alert with information from different sources.
  • Classify certain events according to predefined criteria.
  • Run basic checks before escalating an incident.

All these actions can significantly reduce the time spent on operational tasks without replacing human analysis.

However, decisions such as determining the scope of an incident, assessing its impact, or deciding on the response strategy still require the analyst's judgment.

Where does your team actually spend their time?

Before considering new automations, it can be helpful to answer a simple question:

What tasks do all analysts perform, every day, and always in the same way?

If the answer includes activities such as searching for information on different platforms, gathering data to contextualize an alert, or running repetitive checks, there is likely room to reduce operational workload through automation.

Conversely, if tasks are constantly changing or depend on complex decisions, automating them may add little value and even hinder the team's work.

Automate to reduce noise, not to generate more activity

One of the most common risks is associating automation solely with speed. However, well-designed automation should also contribute to improving the quality of the SOC's work.

Some practices that can help achieve this are:

  • Prioritize the automation of repetitive tasks that are time-consuming and provide little analytical value.
  • Automate the enrichment of alerts so that context is available from the start of the investigation.
  • Regularly review implemented automations to ensure they remain useful and meet the SOC's current needs.
  • Use automation to reduce the volume of manual tasks and facilitate the prioritization of truly relevant alerts, avoiding increased operational noise.

Automation provides its greatest value when it allows analysts to spend less time on mechanical tasks and more time investigating, understanding, and responding to threats.