Is your SOC below the AI poverty line? | The Security Strategist Podcast

Podcasts · Olivia Garrison · TAGS: SOCaaS

The “AI poverty line” may end up being more consequential than the security poverty line that’s defined the industry for years. In this episode of The Security Strategist podcast, Expel CTO Greg Notch joins host Brad LaPorte to unpack what the AI poverty line actually means for security teams, where automation belongs in the SOC, why risk—not fear—should drive every security leadership decision, and what the future of human-AI collaboration looks like in practice. If your organization is wrestling with how to wield AI without losing control, this conversation is worth your time.

Video: Watch the full episode

Originally published on: em360tech.com

Featuring:

  • Brad LaPorte, Host, The Security Strategist Podcast; Gartner Veteran and Advisor, Lionfish Tech Advisors
  • Greg Notch, Chief Technology Officer, Expel

Additional resources

Introduction

The security industry has long talked about the “security poverty line”—the growing divide between organizations that can afford robust security programs and those that can’t. But according to Expel CTO Greg Notch, a new version of that divide is emerging, and it may be even more consequential.

Greg Notch: The AI poverty line will be even crazier in some ways because you will either have the ability to understand and wield AI properly, or you will not. That gulf is going to be interesting.

In this episode of The Security Strategist podcast, host Brad LaPorte, Gartner veteran and advisor at Lionfish Tech Advisors, sits down with Notch to dig into what the AI poverty line means for security operations, where automation actually belongs in the SOC, and how enterprises can build the right balance between human judgment and machine speed.

What is the AI poverty line?

The traditional security poverty line describes the gap between organizations with mature, well-funded security programs and those struggling to cover the basics. The AI poverty line introduces a new dimension to that divide—one defined not just by budget but by skill.

Greg Notch: While a security poverty line has existed for a long time, an AI version will begin appearing. It could be more complex and niche. Security teams may face difficulties defining their roles and responsibilities. Only those who can wield AI skillfully and effectively will be positioned to compete.

Consider the advantage held by large enterprises—a CrowdStrike, a Palo Alto, a Microsoft—that can employ teams of AI-skilled professionals and invest deeply in AI-native tooling. For these organizations, AI becomes a force multiplier that extends the reach of every analyst and automates the work that used to require headcount they couldn’t hire.

Greg Notch: If you can’t hire enough people to manage the operation, you may have to outsource that to an AI-skilled professional.

But the gap isn’t just about resources. It’s about sophistication. As attackers grow more capable—using AI to accelerate reconnaissance, craft more convincing phishing, and automate exploitation—defenders need to match that pace. Automation alone isn’t enough. What’s required is a team equipped to actively use AI-backed security tools: to monitor, manage, and respond to threats in ways that support human decision-making rather than replace it.

Where does AI actually belong in the SOC?

The debate about AI’s role in security operations often gets framed as a binary: AI replaces analysts, or AI is useless. The reality is more nuanced—and more interesting.

Both LaPorte and Notch agree that the right model is collaborative. AI and human analysts working together in a hybrid model where humans maintain meaningful control.

Brad LaPorte: It’s like a motorcycle with a sidecar. The human is riding the motorcycle, but the AI is along for the ride. It adds additional capability, additional storage and functionality. It’s a new world, but it’s a hybrid world.

Notch pushes this further by asking a rhetorical question: What would a SOC without analysts actually look like? Even in a world where AI intermediates most of the alert processing and investigation, he doesn’t see humans leaving the equation.

Greg Notch: I believe we’ll have more humans in the loop.

This might seem counterintuitive given how much automation is entering security operations. But the reasoning is sound: as AI scales the volume and complexity of work a SOC can handle, the judgment calls that require human context become more important, not less. The analysts aren’t gone—they’re working at a different level.

Why automation is essential—and where risk fits in

Automation isn’t optional anymore. As attackers become more sophisticated and the volume of threats continues to climb, security teams that rely purely on manual processes are operating at a structural disadvantage.

Some use cases for automation are relatively straightforward: blocking known malicious IPs, containing compromised devices, isolating infected endpoints before an attacker can move laterally. These are high-speed, high-stakes actions where the window to respond is often minutes—not the hours it might take to get a human in the loop and get approval.

But Notch frames the case for automation in terms that security leaders can take directly to their stakeholders: risk.

Greg Notch: All security leadership decisions should be grounded in risk. What is the risk of not doing a particular task versus the risk of doing it—for instance, automation? We’re accepting different risks, but we believe the risk of not being able to stop an active attacker in our environment is worth that. That’s the trade-off you have to make.

This reframe matters. The question isn’t “Is automation risky?” The question is “Which risk is greater: the risk of automation acting incorrectly, or the risk of an attacker operating unimpeded while we wait for a human to approve a response?” In most cases, the math isn’t close.

Automation also addresses a second operational challenge that’s less dramatic but equally real: alert fatigue. When security teams are drowning in alerts—most of which turn out to be benign—the mental overhead of constant triage erodes both effectiveness and analyst retention. Automation that filters, triages, and handles the routine frees analysts to focus on the investigations that actually require judgment.

How Expel built trust in automation before AI was a buzzword

Expel’s experience with automation predates the current wave of AI hype by nearly a decade—and that history offers some useful lessons about what it actually takes to operationalize automated response.

Greg Notch: Expel launched an auto-remediation feature about seven or eight years ago, based on heuristics. It wasn’t driven by AI back then.

The challenge at the time wasn’t technical—it was trust. Customers had to become comfortable letting a third-party security provider take automated action in their environment: isolating infected laptops, shutting down compromised cloud systems, stopping malicious programs, responding to attacks without waiting for internal approval.

That trust wasn’t assumed. It was earned through transparency, track record, and clear communication about what the automation would and wouldn’t do. Over time, Expel discovered that customers were willing to extend that trust—because the alternative was slower response times and more exposure.

Greg Notch: Today, many enterprises would rather let the system stop or contain an attack immediately and investigate what happened afterwards.

That shift in posture—act first, investigate second—represents a meaningful change in how security operations work. It’s only possible when there’s sufficient trust in the automation layer. And building that trust takes time, clear boundaries, and demonstrated results.

This is also why Expel developed the Trust vs. Impact framework: a structured way for security teams to think through which tasks are candidates for automation, which require human oversight, and which shouldn’t be automated at all—at least not yet. The goal is intentional AI adoption, not automation for its own sake.

The hype versus the reality

No conversation about AI in cybersecurity would be complete without addressing the gap between what vendors promise and what actually works in production environments.

The AI hype cycle in security has generated plenty of bold claims—autonomous SOCs, zero-analyst operations, AI that detects threats humans can’t. Some of these claims have merit directionally but overstate where the technology actually is today. Others are marketing dressed up as product capability.

Notch’s position throughout this conversation is grounded: AI is genuinely transforming security operations, but it’s not a silver bullet. False positives remain a significant challenge. Implementation requires care. And the organizations that benefit most from AI are the ones that approach it thoughtfully—asking where it fits, what trust it needs to earn, and what risks they’re accepting when they deploy it.

The organizations that struggle are the ones that bolt AI on top of broken processes and expect it to fix problems that are fundamentally operational, not technical.

What the future of AI in security operations looks like

LaPorte and Notch close the conversation by looking ahead at where AI in security operations is headed—and what enterprises need to do to stay on the right side of the AI poverty line.

A few themes emerge:

AI will keep accelerating attack speed: The same tools that help defenders move faster also help attackers. The pace of AI-driven attacks will continue to increase, which means the window for human response in many scenarios will keep shrinking. Automation isn’t optional—it’s a competitive necessity.

Human-AI collaboration will define the winning teams: The organizations that pull ahead won’t be the ones that automate the most—they’ll be the ones that figure out the right division of labor between humans and machines. That requires understanding what AI does well, where humans add irreplaceable value, and how to build systems that make that collaboration work in practice.

Trust is built incrementally: Whether you’re deploying auto-remediation or standing up AI-assisted triage, the path to effective automation runs through trust. That trust has to be earned—through transparency, testing, feedback loops, and demonstrated results. Organizations that try to skip this step tend to end up with automation they don’t use or automation that causes more problems than it solves.

Risk management, not fear, should drive decisions: Every decision to adopt or not adopt automation is a risk decision. The right frame isn’t “Is this scary?” It’s “What’s the risk of doing this versus not doing this?” Security leaders who can answer that question clearly will make better decisions than those who default to either uncritical adoption or reflexive skepticism.

Frequently asked questions about AI in security operations

What is the AI poverty line in cybersecurity?

The AI poverty line describes the emerging divide between organizations that can effectively understand and wield AI in their security operations and those that cannot. Unlike the traditional security poverty line—which is largely about budget—the AI poverty line is also about skill, sophistication, and organizational readiness. As AI becomes more central to both attack and defense, this gap is expected to grow.

Should AI replace SOC analysts?

No—and security leaders who frame the question that way tend to make worse decisions about AI adoption. The more useful question is: What should AI do, and what should humans do? In practice, AI handles speed and scale—processing large volumes of alerts, automating routine responses, enriching investigations with context. Humans handle judgment, relationship management, and the situations AI hasn’t seen before. The future SOC has more human-AI collaboration, not fewer humans.

How does Expel approach automation?

Expel has been building automated response capabilities since before AI became a mainstream conversation in security. The core principle is risk-based: the risk of an active attacker operating unimpeded is often greater than the risk of automated action taken incorrectly. Expel’s auto-remediation capabilities act on threats in real time—containing compromised devices, isolating infected systems, blocking malicious activity—and customers can see exactly what was done and why through the Workbench platform.

What is the Trust vs. Impact framework?

Trust vs. Impact is a framework Expel developed for thinking through AI deployment decisions in security operations. It maps tasks against two axes: how bad would it be if the automation got it wrong (impact), and how much do you trust the system to get it right (trust). The intersection tells you whether to automate fully, keep humans in the loop, or hold off. It’s designed to make AI adoption intentional rather than reactive. You can access the framework and interactive tool at expel.com/trust.

How can smaller organizations stay above the AI poverty line?

Partnering with an MDR provider that has AI capabilities built into their platform is one of the most practical paths for smaller organizations. Rather than building AI expertise in-house—which requires significant investment in talent and tooling—they can benefit from the AI-driven detection, triage, and response capabilities their MDR provider has already developed at scale. The key is choosing a provider that’s actually using AI operationally, not just marketing it.

Is AI a silver bullet for cybersecurity?

No. AI is a genuinely powerful tool for security operations, but it doesn’t fix broken processes, eliminate the need for skilled analysts, or make threat detection foolproof. False positives remain a real challenge. Implementation requires care and intentionality. Organizations that treat AI as a magic solution tend to be disappointed; those that treat it as a powerful capability requiring thoughtful deployment tend to see real results.

Key takeaways

  • The AI poverty line is real and growing: The divide between organizations that can effectively wield AI and those that can’t will be as consequential as the traditional security poverty line—possibly more so.
  • Automation is essential, but so is human judgment: The winning model is collaborative—AI handling speed and scale, humans handling context and judgment. Neither replaces the other.
  • Risk management should drive automation decisions: The question isn’t whether automation is risky. It’s whether the risk of automation is greater or less than the risk of not automating. In most active-attack scenarios, the math favors acting fast.
  • Trust is earned, not assumed: Effective automation requires customers and organizations to trust the system. That trust has to be built incrementally through transparency, testing, and demonstrated results.
  • AI hype often outpaces reality: The organizations that benefit most from AI are the ones that approach it with clear eyes—understanding what it can and can’t do, and deploying it intentionally rather than reactively.
  • The future SOC has more human-AI collaboration, not fewer humans: As AI scales the volume of work a SOC can handle, the judgment calls that require human expertise become more important, not less.
  • Security decisions should be grounded in risk: Every decision—to automate or not, to adopt a new AI capability or wait—is a risk decision. Leaders who frame it that way consistently make better calls.

This summary has been adapted from the original episode abstract and edited for clarity and readability. Watch the full episode at em360tech.com.

To learn more about how Expel’s AI and automation engine and managed detection and response services help organizations stay ahead of evolving threats, schedule a demo today.

Resources home