Thinking Fast and Slow in the SOC (The Hacker News, 2026-07)
lital-asher-dotan‘s argument for splitting the SOC into an autonomous triage tier and a human judgment tier, borrowing Kahneman’s System 1 / System 2. Published on The Hacker News as contributed content; the author is CMO at intezer, which sells the autonomous tier — so this is T3 vendor material, and the page treats its numbers accordingly.
The claim
- Across 25 million enterprise alerts, ~98% are resolvable autonomously; under 2% warrant human review. The stated parallel is Kahneman’s 95/5 split of human cognition, which is an analogy doing rhetorical work rather than evidence.
- The fast brain investigates every incoming alert without human initiation — memory scans, file analysis, cross-signal correlation across endpoint, identity, network and cloud — reaching verdicts at a claimed 98% accuracy in under two minutes, and escalates the ~2% with evidence attached.
- The slow brain is analysts plus copilots (Claude, Codex and Cursor are named) doing complex cases, detection-rule engineering, incident reporting and threat hunting. Analyst decisions feed back into the autonomous layer.
- Scale illustration: an organization handling 450,000 alerts a year should expect roughly 54 real threats hidden in low-severity noise.
The part worth keeping
Two things survive the vendor discount. First, the assignment argument — that SOCs put humans on pattern-matching work and machines nowhere, which is backwards — is independent of whose product does the triage. Second, the knowledge-layer point: outsourcing investigation to an MDR provider means the detection rules, case history and triage logic accumulate on someone else’s platform, so a later attempt to layer analyst copilots on top has no organization-specific corpus to reason over. It’s a strategic-lock-in argument dressed as a technical one, and it’s the piece’s most interesting claim precisely because it’s about a decision made years before the AI question arrives.
The part to discount
Every number is the vendor’s, unaudited, and the two headline figures — 98% autonomously resolvable and 98% verdict accuracy — are suspiciously the same number for two different quantities. No false-negative rate is given, which is the figure that matters for an autonomous triage tier: what fraction of the 98% closed without a human were real. A SOC that auto-closes a true positive has failed in the one way that counts, and this source doesn’t say how often that happens.
Related
security-operations-center · defensive-security · intezer · lital-asher-dotan