2030 SOC Strategy and the Integration of AI and Security Expertise
- Pyo Kwon

- Jun 5
- 4 min read
PAGO Gartner Security & Risk Management Summit On Site Report
PAGO attended the 2026 Gartner Security & Risk Management Summit in National Harbor, Maryland, and sharing key insights from the security sessions shaping the future of cyber defense. As the fourth report in this series, we examine the session "Staffing the SOC in 2030" presented by Pete Shoard.

Executive Summary
One of the most common questions surrounding AI in cybersecurity is whether security teams will become smaller as automation continues to advance. According to Pete Shoard, the answer is no.
During the session, Shoard argued that Security Operations Centers will not become smaller by 2030. In fact, Gartner's broader discussions at the summit suggested that organizations may require more security personnel in the coming years, particularly in engineering and offensive security functions.
The central message of the session was that the SOC is evolving into a hybrid operating model that combines AI and human expertise. Rather than replacing security professionals, AI will take over a growing portion of repetitive operational tasks while analysts, engineers, and specialists focus on validation, engineering, and proactive security activities.
Three major changes were highlighted as defining characteristics of the SOC in 2030:
Alert triage shifts to AI, while analysts focus on validating AI generated cases.
Detection engineering adopts software development principles through Detection as Code and automated CI/CD workflows.
Security operations move toward proactive exposure management through continuous offensive security testing and ongoing validation activities.
Rather than planning for workforce reduction, security leaders were encouraged to redesign their teams around new roles, new workflows, and new operating models.
AI: Threat or Opportunity?
Shoard opened the session with a provocative question: "Will organizations still need Level 1 triage analysts next year? What about in 2030?" Many of the skills that SOC teams have spent years developing, including threat intelligence analysis, data queries, and playbook creation, are now being influenced by AI.
At the same time, AI creates opportunities for less experienced analysts to access advanced capabilities and contribute value more quickly. Tasks that once required years of experience can now be supported by AI driven analysis, recommendations, and workflow assistance.
The discussion was framed less as a replacement of people and more as a transformation of roles.
The future SOC, according to Shoard, is best understood as a combination of human expertise and AI capabilities working together.

Key Change 1: From Alert Triage to Validation
One of the first areas expected to change significantly is alert triage.
According to Gartner survey data referenced during the session, organizations are already using contextualized alerts for a large portion of investigative activities, while time spent on routine operational tasks has declined substantially.
Historically, analysts needed to examine individual logs and determine what happened, who performed an action, whether it was legitimate, and whether further investigation was required. AI is beginning to assemble fragmented alerts into contextualized cases that provide a more complete view of activity. As this capability matures, the emphasis shifts away from manually connecting individual events and toward validating AI generated findings.
Shoard described this future role as a validator. The analyst remains a critical part of the process, but their responsibility centers on confirming conclusions, reviewing context, and ensuring decisions align with operational and business requirements.
He also noted that when a process becomes fully automated from beginning to end, it effectively moves outside the scope of SOC operations. Security operations remain an operational function where human oversight and decision making continue to play an essential role.

Key Change 2: Detection Engineering Adopts a Developer Mindset
While AI may reduce repetitive analyst tasks, the session suggested that demand for security engineering skills will continue to grow.
Gartner predicts that by 2028, many Security Operations Centers may employ more engineers than analysts. One reason is the growing complexity associated with maintaining, testing, and validating AI driven systems, detection logic, and operational workflows. To address this challenge, Shoard emphasized the adoption of software development practices within security operations.
Detection as Code (DaC) was presented as a key concept. Detection rules and queries are treated similarly to software code, managed through version control systems, tested automatically, and deployed through CI/CD pipelines. As a result, the responsibilities of future detection engineers extend beyond rule creation.
Prompt design, data pipeline management, AI workflow development, operational feedback management, and testing become important parts of the role. This evolution requires a stronger engineering mindset across SOC teams.

Key Change 3: From Incident Response to Exposure First Security Operations
Shoard identified proactive exposure management as one of the most important themes of the session.
As cloud adoption expands and digital assets continue to grow, attack surfaces become larger and more complex. Security programs built primarily around responding after an incident face increasing challenges.

The session emphasized the importance of continuously identifying weaknesses before attackers can exploit them. This approach moves beyond traditional annual penetration testing and toward continuous, automated security validation activities. Gartner refers to this model as Continuous Offensive Security Testing (COST).
Under this framework, organizations continuously test their environments whenever new threat intelligence emerges, infrastructure changes occur, or new technologies are introduced. The role of the Exposure Specialist becomes a lot more important. Beyond identifying issues, these specialists help connect findings to business impact, provide context, and support stakeholder decision making.

Conclusion
The message delivered throughout the session was consistent with Gartner's broader position that fully autonomous SOC operations remain unlikely. Human expertise continues to play a critical role in security operations, even as AI becomes embedded throughout workflows.

Key recommendations from the session included:
Reconsider workforce reduction plans and prepare for increased demand in engineering and offensive security roles.
Move beyond calendar based security assessments and adopt continuous exposure validation practices.
Develop threat experts capable of evaluating AI generated results through a business and operational lens.
Apply software engineering principles to detection development through Detection as Code and automated testing workflows.
The SOC of 2030 is expected to combine the speed, consistency, and scale of AI with the judgment, validation, and risk assessment capabilities of experienced security professionals. The result is not an autonomous SOC. It is a collaborative operating model where AI and security experts work together to strengthen security operations and improve organizational resilience.

Written by: Pyo Kwon CPTO | DeepACT MDR Center



