What actually changed in the security operations center between 2020 and 2026

DCDaniel C. · Head of Security Operations
SOC Modernization·11 min read

I ran SOC budget cycles across the whole 2020-to-2026 span, and the line items tell the story better than the vendor decks do. Five shifts were structural: the perimeter moved to identity, log economics broke, automation stopped being optional, detection engineering became a discipline, and AI triage reached production. One thing never moved. Someone still owns the alert at 2 a.m.

I ran security operations center (SOC) budget cycles through the entire 2020-to-2026 span, and the line items tell the story better than the vendor decks do. In 2020 I renewed an ingest-priced security information and event management (SIEM) platform without much argument, a tier-1 rotation handled alerts, and managed detection and response (MDR) remained supplemental.

By 2024 I was writing bigger checks to move logs out of the SIEM than into it, and by this year's renewals the conversation had become which triage verdicts a machine gets to render before my team sees anything.

Six years in the leader seat is enough time to sort structural change from relabeling. Five shifts were real: the perimeter moved to identity, log economics broke, alert volume outgrew headcount until automation stopped being optional, detection engineering became a discipline, and AI triage reached production. Human accountability stayed fixed the whole time, and it should anchor every buying decision.

In brief:

  • In CrowdStrike's 2025 telemetry, 82% of detections were malware-free, up from 51% in 2020. Attackers increasingly log in rather than break in, and most SOC architectures still watch endpoints first.
  • Telemetry keeps growing while legacy SIEMs charge per gigabyte. Worsening telemetry economics helped drive the 2024 consolidation involving QRadar and LogRhythm.
  • AI-assisted triage is in production at some SOCs, but autonomous AI SOC agents remain early: Gartner puts the category at 1% to 5% penetration and embryonic maturity, and many products sold under the label aren't agentic.
  • The SANS SOC Survey still reports staffing and alert volume among the problems carried over from 2019, and manual reporting persists in 2025.

The SOC in 2020, briefly, so the change is legible

The SOC I ran in 2020 was a tiered human pipeline wrapped around an ingest-priced SIEM. Tier 1 handled most alerts in minutes using runbooks and escalated the remainder to tier 2. Security orchestration, automation, and response (SOAR) was still a novelty, with Gartner projecting 15% adoption by 2020 among organizations with five or more security professionals, up from under 1%.

The 2020 Verizon Data Breach Investigations Report (DBIR) reported stolen or used credentials in 37% of breaches and phishing in 22%, with ransomware in 27% of malware incidents, and M-Trends 2021 put the global median dwell time at 24 days for incidents investigated in 2020, down from 56 the year before.

Endpoint malware still dominated many SOC workflows then, even though stolen credentials were already a leading breach path, and the job was to spot the intrusion before day 24. Both of those assumptions have since shifted.

What changed, and what only got rebranded

Five shifts separate that SOC from this one. Each was structural, and each also spawned a relabeling wave, so I'll flag where the sticker outran the substance.

The perimeter moved to identity

Malware-free detections rose from 51% of CrowdStrike's observations in 2020 to 82% in 2025, a shift toward valid credentials and trusted tools rather than proof that malware stopped mattering, and DBIR 2026 found credential abuse appeared somewhere in 39% of breaches even after pretexting was split into its own category.

The supply side explains it: stolen credentials, session cookies, and cloud tokens circulate on illicit markets at scale, harvested from infostealer-infected devices.

The Snowflake breach compromised roughly 165 organizations through infostealer credentials that were never rotated on tenants without mandatory multifactor authentication (MFA).

Voice phishing then surged to the second most common initial infection vector at 11% in M-Trends 2026 while email phishing fell to 6%, so the help desk is now an attack surface.

Identity threat detection and response (ITDR) is a legitimate category, but buying the acronym alone leaves the surface uncovered. Adoption is still partial, and most teams that have it cannot yet automate remediation. Treating failed-login SIEM rules as the full identity detection surface merely renames the rules.

Logs left the building, and SIEM economics broke

Enterprise telemetry keeps growing, while Splunk-style ingest pricing makes license cost track log growth directly. The market visibly consolidated in 2024: Cisco closed its Splunk acquisition in March, Thoma Bravo merged LogRhythm into Exabeam that May, and Palo Alto Networks acquired IBM's QRadar software-as-a-service (SaaS) assets and customer transition rights in September, with the stated aim of migrating customers to Cortex XSIAM.

The Gartner 2025 SIEM Magic Quadrant then excluded IBM, LogRhythm, Devo, Logpoint, and NetWitness for failing functional or commercial requirements. That consolidation narrowed the field of large SIEM vendors and pushed migration toward cloud-delivered platforms. It did not end on-prem SIEM, but in my view it made standalone, self-managed SIEM a much less common default for new buyers.

Object storage is usually far cheaper than SIEM ingest for long-term retention, though query, compute, egress, pipeline tooling, and engineering time still shape the total cost. Cribl became a pipeline layer between sources and destinations. I now spend more on routing and filtering logs than I spent on SIEM licensing in 2020, and for my team it is still the better trade. That changes what a SOC physically is, which goes well beyond a pricing negotiation.

Alert volume outgrew headcount, so automation stopped being optional

In the 2025 SANS SOC Survey, 85% of analysts still trigger response from endpoint alerts, and 42% of SOCs admit to routing all incoming data into the SIEM with no structured plan for retrieval. The alerts pile up faster than anyone works them, and the ones that go uninvestigated are where the real misses hide.

You can't hire out of that. 88% of respondents suffered at least one significant security consequence from a skills shortage in ISC2's 2025 workforce study. In 2020, automation was a roadmap slide I kept deferring. By 2024 it was the precondition for the SOC functioning at all, and the honest origin of the AI triage push was arithmetic.

Detection engineering became a job, not a side task

The 2023 SANS survey described detection engineering as a shared responsibility rather than a dedicated discipline. Two years later, the same survey found most practitioners favoring behavior-based detections and a large minority building detection-as-code.

The community infrastructure simply didn't exist in its current form in 2020: the Sigma specification shipped version 2.0 in August 2024, DEATHCon was founded around 2022, and Detection Engineering Weekly became an established newsletter.

Teams professionalized detection because renting someone else's logic was burning their analysts. A large share of false positives originates in vendor-shipped rules that were never tuned to the environment. The discipline is still fragile, though, and most detection teams I deal with are barely keeping pace.

AI moved from the pitch deck into tier-1 triage

This one is real and overhyped at the same time. AI appears in some SOC capacity at most organizations, but only a minority deploy it for triage, and current deployments are reducing trust for many leaders, who cite limited visibility, control, and explainability.

The vendor accuracy numbers are striking but self-measured: CrowdStrike states over 98% triage accuracy for Charlotte AI against its own Falcon Complete analysts' decisions, and Rapid7 claims 99.93% accuracy classifying benign alerts. Independent audit of figures like these is not yet common in this market.

Gartner rates the AI SOC agent category as immature even as attention pushes it up the hype curve, with penetration at 1% to 5%.

Why adopt anyway: attackers now operate below human queue speed. M-Trends 2026 measured a median of 22 seconds in 2025 from initial access to hand-off to a second threat group, which can happen before a human triage queue advances, and CrowdStrike put average eCrime breakout time at 29 minutes.

In every AI triage demo I've taken this year, I open with the same question: which verdicts does the system render before a human sees anything, and how does a wrong one surface? Vendors who can't answer are selling what Stellar Cyber's taxonomy calls a security-skinned chatbot, or a playbook engine with a large language model (LLM) summary bolted on.

What didn't change, whatever the category names did

Strip the labels, and the load-bearing facts of SOC work in 2026 look uncomfortably like 2019's. Human accountability is the through-line.

Someone still owns the alert at 2 a.m.

SANS's 2019 survey put lack of skilled staff at 57.7% and unmanageable alert volume at 32%. The 2025 edition finds 62% of respondents saying their organization isn't doing enough to retain talent and 69% still reporting metrics through manual or mostly manual processes.

Tines Field chief information security officer (CISO) Matt Muller read the same 2025 survey as evidence the core problems remain in place: teams are understaffed and tool sprawl keeps growing. Six years of SOAR, extended detection and response (XDR), and AI triage haven't displaced the same three items from the top of the survey.

The accountability never moved either. A Cybersecurity and Infrastructure Security Agency (CISA) red team assessment of a federal agency found that network defenders' daily procedures didn't include analysis of endpoint detection and response (EDR) alerts, so the red team ran longer than it should have at an organization with dedicated security resources.

Anton Chuvakin's 3 a.m. test for a detection still holds: if it fires, a person may be woken to respond. Even where automation closes routine alerts or executes pre-authorized containment, an accountable person still owns the escalation policy, the exceptions, and the incident decisions, and every contract I've negotiated still leaves the breach on my desk, not the vendor's.

What the modern SOC actually is now

The shape of the work changed far more than the responsibility for it.

A working definition, set against the 2020 version

The 2020 SOC was a tiered human pipeline watching endpoints and network from inside an ingest-priced SIEM. The 2026 SOC is an engineering function that treats identity as a first-class detection surface alongside endpoint, cloud, and SaaS, routes telemetry through a pipeline into decoupled storage, ships custom detections as code, lets machines close routine tier-1 verdicts, and reserves humans for judgment and accountability at the escalation boundary.

The operating model shifted with it, and Gartner peer data shows 63% now run hybrid internal-plus-external models against 34% internal-only.

The structural changes landed in a harder environment, one where ransomware climbed to 48% of breaches and vulnerability exploitation became the top initial access vector for the first time in 19 years of DBIR data. For my money, holding detection and response steady while the threat got worse is the case for having paid for them.

What this means if you're building or buying in 2026

If I were signing contracts this quarter, four questions would drive them. They test the cost model, coverage, decision boundary, and staffing plan, and each one exposes a different place where a rebrand can hide weak operations.

  • Model telemetry growth into the contract: Run your ingest pricing against multiple growth scenarios for the full contract term. If the number breaks in year two, negotiate a pipeline-and-lake architecture instead of a bigger SIEM commit.
  • Make identity coverage the criterion: Ask how the platform correlates session tokens with identity activity such as help desk resets and SaaS logins. Credential abuse is the through-line of the whole span, and coverage claims that stop at failed logins are the rebrand.
  • Put the AI decision boundary in the contract: Get the vendor to walk the path from alert to auto-close and show where a wrong verdict becomes visible. Vendor-stated accuracy without an inspectable evidence trail is a demo, not a control.
  • Hire a detection engineer before the next platform upgrade: Most of your false positives are coming from vendor rules. An engineer who tunes and ships your own detections pays back faster than most platform upgrades I've priced.

I've watched six years of decks claim the SOC has been reinvented, and I almost bought the reinvention more than once. Pay for the five structural changes, and don't pay twice for the rebrand. The contract still leaves the breach on your desk.

Frequently asked questions about the modern security operations center

What does a security operations center do in 2026?

A SOC combines a security team with the processes and tooling used to detect threats and carry investigations through to response across an organization's environment. In 2026 that scope spans identity, cloud, SaaS, and endpoint telemetry, and Gartner peer data shows 63% run hybrid internal-plus-external models while purely internal teams account for 34%. Human accountability stays at the escalation boundary even when machines close routine tier-1 verdicts.

How has the SOC changed since 2020?

Five structural shifts: identity displaced the network perimeter as the main attack surface, ingest-priced SIEM economics broke and consolidated the market in 2024, alert volume outgrew headcount and forced automation into tier-1 triage, detection engineering matured into a dedicated discipline with its own tooling and community, and AI-assisted triage entered production. The SOC is now an engineering function, where the tiered human pipeline defined the 2020 model.

Do you still need an in-house SOC in 2026?

Fully in-house is now the minority position, with most organizations running hybrid or managed models. For teams without the budget and runway to build 24/7 internal coverage, hybrid or managed coverage closes the gap faster. External coverage has moved from a supplemental role into the mainstream operating model rather than a fallback.

What does a modern SOC actually run?

A representative 2026 stack pairs a SIEM or query layer over decoupled storage with a telemetry pipeline, EDR, identity and cloud telemetry, detection-as-code tooling, and AI-assisted triage with human ownership of escalations. A mature environment keeps the SIEM as the central correlation layer over telemetry across endpoint, identity, cloud, network, email, and SaaS, and adds SOAR and ticketing. EDR is one response integration; identity and access management (IAM) and cloud controls are others.


About the author

DCDaniel C. is a security operations leader with over a decade of experience building and scaling SOC capabilities for cloud-native companies. He has led security teams through multiple stages of growth — from early-stage environments with minimal tooling to mature organizations operating 24/7 security operations with distributed teams. His experience includes designing SOC architectures, evaluating and managing MDR providers, and building internal detection and response capabilities. Daniel has been responsible for vendor selection across SIEM, EDR, and XDR platforms, as well as defining SLAs, response models, and escalation frameworks. He has also worked closely with executive leadership on budgeting, board reporting, and aligning security operations with broader business risk. He writes about the practical decisions security leaders face — including build vs buy tradeoffs, how to evaluate security vendors, and what it actually takes to run an effective security operations function at scale

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

What actually changed in the security operations center between 2020 and 2026 | Future of SecOps