Follow the White Rabbit - IT Security Podcast - English Edition
Right now, everyone's selling AI-powered security operations. The pitch sounds great: faster detection, smarter triage, and less noise. However, if your logging is disorganized, your playbooks don't exist, and no one is responsible for the process, AI won't improve your SOC. It'll just make it faster at doing the wrong thing. In this episode of Follow the White Rabbit, Link11 CISO Kofi Osae-Attah sits down with Erik Van Buggenhout, NVISO co-founder and SANS instructor, to cut through the hype and discuss what AI in the SOC looks like in practice. Erik is an AI optimist but, more importantly, he's a realist. He has spent years building security operations at scale and knows exactly where automation succeeds and where it falls short. His take? Up to 70% of incoming alerts can be automated without AI. Static playbooks, when built and maintained properly, do most of the heavy lifting, cheaply and reliably. AI earns its place where context matters, such as in dynamic environments, nuanced triage, and situations where a rigid playbook runs out of answers. The sweet spot isn't AI everywhere. It's AI where judgment is needed and automation everywhere else. However, the conversation goes deeper than tools. Who's accountable when an AI agent makes a wrong decision? What will happen to the career path of junior analysts when L1 work disappears? Why does the security industry keep rebranding the same problems with new buzzwords every three years? Erik doesn't sugarcoat any of it, which is exactly what makes this episode worth your time. TAKEAWAYS: 1. AI won't fix a broken SOC. Garbage in, garbage out—faster. Before buying any AI tooling, first sort out your log sources, processes, and ownership. 2. Seventy percent automation is already possible without AI. Static playbooks that are properly maintained can handle most of the alert volume. AI is the next layer, not the foundation. 3. AI genuinely adds value through context. Managed service providers can't know every customer environment in detail. AI coupled with retrieval-augmented generation can provide that context on a large scale without requiring humans to memorize everything. 4. Humans remain accountable. AI agents operate with identities and permissions, but responsibility ultimately rests with the person operating them. Having a human in the loop isn't optional; it's a structural necessity. 5. The industry's buzzword cycle is exhausting and confusing. SIEM became XDR, and now XDR is becoming AI SOC. Same problem, new name. Erik argues for a more pragmatic and less dramatic approach to what's actually changing. Listen in and subscribe to Follow the White Rabbit. If this episode made you think twice about that AI SOC pitch in your inbox, good! Subscribe on your preferred platform and leave a review. It only takes 30 seconds, and it helps us reach those who need to hear this the most. Share it with your security team, your CISO, or anyone who's been handed an AI tool without a plan. LINKS: You'll find Erik on Linkedin [https://www.linkedin.com/in/erikvanbuggenhout/]and here more about NVISO [https://www.nviso.eu/]. If you want to dive deeper: SOC-CMM – SOC Capability Maturity Model [https://www.soc-cmm.com/] SANS Institute – Purple Teaming & SOC Courses [https://www.sans.org] MITRE ATT&CK – Detection & Response Framework [https://attack.mitre.org] Gartner on AI in Security Operations (2024) [https://www.gartner.com/en/security-risk-management/topics/ai-in-security]
9 episoder
Kommentarer
0Vær den første til at kommentere
Tilmeld dig nu og bliv en del af Follow the White Rabbit - IT Security Podcast - English Edition-fællesskabet!