decryptingtech

Technology. Business models. Market debates.

Browse this section

Security Operations

Security Operations is where cyber telemetry becomes action. The function collects signals across the enterprise, detects suspicious behaviour, investigates incidents and coordinates containment and recovery. Its value is not the volume of data stored or alerts generated, but the speed and accuracy with which it can identify a real attack and change the outcome.

Summary

The modern security operations centre is converging around four assets: a broad telemetry layer, a normalised security data store, an entity and attack graph, and an automation layer. SIEM, XDR, SOAR, user and entity behaviour analytics, threat intelligence and case management increasingly appear as capabilities inside a platform rather than separate markets.

This does not mean SIEM is dead or that XDR replaces every tool. SIEM remains valuable where customers need open ingestion, long retention, custom analytics, audit evidence and investigation across heterogeneous systems. XDR is strongest when a vendor has rich native telemetry and can deliver high-quality detections and response with less integration work. The competitive battle is over which architecture can combine both without recreating the complexity it claims to remove.

The evolution of SIEM and security operations

Stage 1: log management and compliance

The first problem was collection. Firewalls, servers, directories and applications produced separate logs, making investigation slow and audit evidence difficult to assemble. Early SIEM brought those records into one repository, added search and retention, and allowed security teams to write correlation rules. It created a common operating surface, but value depended heavily on manual configuration and specialist administrators.

Stage 2: correlation and the alert-centric SOC

As telemetry expanded, SIEM became the detection engine. Rules connected events across systems and produced centralised alerts for analysts. This improved visibility, but it also exposed the model’s weakness: more data and more rules often created more alerts rather than better decisions. Teams spent increasing amounts of time tuning detections, enriching cases and separating real incidents from false positives.

Stage 3: SOAR adds workflow and response

SOAR emerged because detection was not the same as resolution. It connected alerts to ticketing, enrichment, case management and response tools through repeatable playbooks. Routine steps could be automated, but the architecture remained integration-heavy: SIEM found the signal, SOAR coordinated the process, and separate products performed containment. Automation improved consistency without fixing weak telemetry or low-confidence detections.

Stage 4: EDR becomes XDR

EDR changed the centre of gravity by combining deep endpoint telemetry, behavioural detection and direct response through one agent. XDR extended that model across identity, email, network and cloud signals. Instead of asking customers to build every correlation, vendors supplied native analytics and joined related activity into attack-level incidents. XDR reduced time to value, but its effectiveness was strongest inside the vendor’s own telemetry estate.

Stage 5: cloud-native SIEM and security data platforms

Cloud-scale storage and compute separated retention from real-time analytics. The security data layer became more open, with tiered storage, normalised schemas and multiple ways to query the same evidence. Modern SIEM therefore moved in two directions at once: down into a lower-cost security data platform and up into incident management, graph analytics and automation. This is why SIEM is being re-architected rather than simply replaced.

Stage 6: the AI-assisted and agentic SOC

The latest stage applies AI to investigation and action. Copilots translate natural-language questions into searches, summarise incidents and recommend next steps. Agents go further by gathering evidence, running tools and executing multi-step workflows within defined permissions. The architecture is moving from systems that present alerts to systems that assemble decisions. Human analysts remain essential for ambiguous, high-impact and irreversible actions.

The direction of travel is therefore not SIEM to XDR in a straight line. It is convergence: SIEM contributes openness, history and flexible analytics; XDR contributes high-fidelity native signals and response; SOAR contributes workflow; security data platforms improve economics; and AI reduces the manual work connecting them.

What the SOC actually does

A SOC operates a continuous loop: collect, detect, investigate, contain and learn. Telemetry arrives from endpoints, identities, networks, email, SaaS, cloud workloads, applications and data systems. Analytics convert those events into detections; context joins them into incidents; analysts or automation decide what is material; response controls isolate devices, disable identities, block traffic or change policy.

Every layer is necessary. Missing telemetry creates blind spots. Poor normalisation makes correlation unreliable. Weak detections create noise. Incomplete context slows investigation. Automation without confidence can disrupt the business. The mature SOC is therefore a system of evidence and controlled action, not merely an alert queue.

The operating stack

LayerPrimary jobStrategic role
Security data platformIngest, normalise, retain and query telemetry across vendors.Provides the evidence base for detection, hunting, audit and AI.
SIEMRun analytics, correlate events, manage incidents and support investigation.Acts as the open control point for heterogeneous environments.
EDR and XDRDetect attack behaviour across endpoint and adjacent security domains.Supplies deep native telemetry and direct response actions.
SOAR and automationExecute repeatable enrichment, triage and containment workflows.Converts analyst decisions into consistent machine-speed action.
Behaviour and graph analyticsModel relationships among identities, devices, workloads and events.Reconstructs attack paths and provides context for prioritisation.
Threat intelligence and exposure contextAdd adversary, vulnerability and asset importance signals.Connects proactive risk reduction with active incident response.
MDRProvide monitoring, investigation and response as an external service.Supplies expertise and operating capacity where customers cannot staff a SOC.
The operating stack

From SIEM to a security operations platform

First-generation SIEM centralised logs and rules. It solved visibility and compliance problems but often left customers with expensive ingestion, extensive engineering and large alert queues. SOAR added playbooks and case workflows. EDR then produced richer endpoint telemetry and direct containment. XDR extended that model across identity, email, network and cloud signals, packaging analytics around native product data.

The next architecture combines these layers. Storage is separated from high-cost analytics so customers can retain more evidence without processing everything in real time. Security graphs model relationships instead of treating events as isolated rows. Detection content arrives from the platform but remains extensible. Automation sits inside the incident workflow. The goal is an incident-centric system that can support both packaged detections and open-ended hunting.

Competitive landscape

The market is converging from several directions.

  • Palo Alto Networks combines endpoint, XDR, SIEM, SOAR, cloud detection, attack-surface context and automation in Cortex XSIAM. Its advantage is broad native security telemetry and a platform designed around automated operations.
  • CrowdStrike expands from its endpoint data and threat graph into next-generation SIEM, identity, cloud and managed response. Its strategic question is how far endpoint-led distribution can displace incumbent log-management workflows.
  • Microsoft unifies Defender XDR, Sentinel, identity and cloud telemetry. Its distribution and data access are powerful, while customers still judge cross-platform openness, operating complexity and detection quality.
  • Cisco’s Splunk begins with the broadest traditional SIEM and observability position and is integrating that data layer with network, security and response products. The challenge is simplifying architecture and economics without weakening openness.
  • Google Security Operations, Elastic, SentinelOne, Rapid7 and specialist platforms compete through cloud-scale search, open ingestion, differentiated analytics or simpler operations.

There is no universal winner because environments differ. A Microsoft-heavy enterprise, a cloud-native company, a regulated bank and a mid-market customer using MDR have different telemetry, retention and staffing requirements. Platform consolidation is real, but customers still resist architectures that turn one vendor’s blind spots into the SOC’s blind spots.

Where the moat sits

The durable asset is the feedback loop among telemetry, detections, investigations and response. Broad data improves context. More investigations reveal which signals matter. Better detections reduce analyst workload. Direct enforcement increases the value of every correct decision. Managed services strengthen this loop by adding human outcomes and operating knowledge.

Data volume alone is not a moat. Much security telemetry is commoditised, and open storage lowers switching friction. Defensibility comes from high-fidelity native signals, a useful entity graph, proprietary detection content, response reach, workflow adoption and trust. Once a platform becomes the system through which incidents are investigated and closed, displacement becomes operationally risky.

AI and the agentic SOC

Generative AI first improved search, summarisation and investigation guidance. The newer shift is toward agents that can assemble evidence, run queries, enrich indicators, propose conclusions and execute multi-step playbooks. This can compress routine triage and allow experienced analysts to supervise more incidents.

The constraint is not language generation; it is permissioned action under uncertainty. A useful security agent needs grounded access to trustworthy telemetry, a clear audit trail, scoped tools, approval boundaries and rollback. Platforms that own both the data context and response controls are best placed to build agents, but they also carry the greatest responsibility when an automated decision is wrong.

The investment debate

The bull case is that rising telemetry, faster attacks and limited human capacity force customers toward integrated, automated SecOps platforms. Vendors can consolidate budgets previously split among SIEM, SOAR, EDR, analytics and services, while expanding through data retention and additional modules.

The bear case is that storage and search become cheaper, AI features converge, and platform claims outrun actual product integration. Large migrations are difficult, security data can be expensive to move, and customers may use lower-cost data lakes beneath multiple detection tools. Bundling can win distribution without producing superior security outcomes.

The most useful indicators are not headline AI announcements. Watch competitive replacements, data-ingestion growth, retention expansion, detection quality, incident compression, automated resolution, MDR adoption and the number of legacy tools genuinely retired. The best platform should improve outcomes while lowering the labour and infrastructure required to achieve them.

Bottom line

Security Operations is becoming the decision layer of the cyber stack. SIEM supplies openness and evidence; XDR contributes native telemetry and response; automation turns decisions into action; AI reduces the human work between them. The winning architecture will not be the one that stores the most alerts or carries the most acronyms. It will be the one that finds real incidents earlier, explains them clearly and contains them safely with fewer manual steps.