ExtraHop named a leader in the Gartner® Magic Quadrant™ for Network Detection and Response

Search
  • Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

The SOC Needs a New Operating Model

Share blog icon

Back to top

Back to top

July 22, 2026

The SOC Needs a New Operating Model

Every security leader I talk to is running the same calculation. If an AI-driven attack hit tonight, moving at machine speed, discovering a weakness, exploiting it, and spreading across the environment faster than anyone could pick up the phone, would the SOC catch it in time? Or would it become the incident you explain to the board, the regulator, and the press? That question is no longer hypothetical, and the honest answer for most enterprises is uncomfortable. It is not a staffing problem or a tooling problem. It is that the SOC itself was built for a threat that no longer exists.

For twenty years, the security operations center has been organized around one assumption: that a human sits at the center of every decision that matters. Collect the logs. Route them to a SIEM. Queue the alerts. Let an analyst triage, enrich, investigate, and decide. The SIEM was the center of gravity and the analyst was the engine, and that model held for two decades because it matched the speed of the threat. The budgets you have spent, the teams you have built, the processes your auditors have come to expect. All of it assumes that human judgment can keep pace with the attack. That assumption just broke.

Mythos changed the math. Frontier models in the hands of adversaries have collapsed the time it takes to find a vulnerability, write an exploit, and move laterally to minutes, sometimes less. Reconnaissance, exploitation, and fan-out now happen while your best analyst is still reading the first alert. When the attacker operates at machine speed and the defender operates at human speed, the outcome is not in question. The only variable is how long the gap takes to surface, and how bad it looks when it does.

The reflex across the industry has been to bolt AI onto the SOC we already have. Add a copilot to the SIEM. Put a language model in front of the alert queue. Automate a few playbooks and call it transformation. I understand the reflex. It protects the investment you have already made. But it does not work, and the reason is structural. You cannot solve a machine-speed problem by making a human-speed operating model slightly faster. Queue, enrich, triage, investigate, escalate: that sequence assumes time you no longer have. Speeding up one step in a chain designed for a slower era does not close the gap. It just relocates the bottleneck.

So the question in front of every CISO is not which AI product to buy. It is what the SOC should be organized around now that no human is fast enough to sit at the center of every decision. That is an architecture question, and it deserves an architecture answer, one you can take to your board with conviction rather than hope.

A new center of gravity

The answer is an operating model built for autonomy from the ground up. At ExtraHop we've come to describe it in three layers: Context, Harness, and Model. I want to be precise about what each one does, because the value is in how they fit together, not in any one of them alone.

Context is the evidence an agent reasons on. Not yesterday's logs shipped to cold storage, but a real-time, ground-truth view of what is actually happening across the network, endpoint, identity, and cloud, assembled the instant the wire produces it. This is the layer the entire model lives or dies on. An autonomous agent fed fragmented logs will reach fragile conclusions, confidently and at scale. That is exactly how you get an AI SOC that floods analysts with false positives and misses the one thing that mattered. Complete context produces defensible conclusions. Fragmented context produces expensive noise. There is no model good enough to reason its way out of missing evidence.

Harness is the layer most people underestimate. Context tells an agent what is happening. A model decides what it thinks that means. Neither one decides what the agent is actually allowed to do about it. That is the harness, the governed control plane that mediates every action an agent takes, scopes what it can read and what it can execute, enforces guardrails and permissions, and keeps a complete audit trail. It's the reason a CISO can grant an autonomous agent real authority without re-earning trust every time the underlying model changes. Without a harness, an agent with production access is a liability. With one, it's an operator.

Model is the specialized, multi-model AI layer that does the work of triage, investigation, and response. I say multi-model deliberately. The teams winning here aren't betting on a single model to be right about everything. They're building an architecture where the best model for each task plugs in, does its job inside the harness, reasons on shared context, and gets swapped out the moment something better comes along. The model is important. It is not the foundation.

Put those three layers together and something changes about the SOC that no copilot bolted onto a SIEM can replicate: the loop closes at machine speed, and it closes with evidence, governance, and accuracy built in rather than bolted on. Detect, decide, and respond at the speed the threat actually moves.

Read the diagram from the bottom up and you’re reading the operating model in the order it actually executes. Federated sources, network and wire, endpoint, identity, and any Alliance data lake a customer plugs in, feed a real-time context graph, the integration point where fragmented telemetry becomes a semantic map of every entity, identity, and connection. Agents don’t query the raw feeds directly. They query that graph, through a Graph API and MCP, to collect more accurate, higher-fidelity context that supports better reasoning before they decide how to investigate or respond.

When the initial context from the graph isn’t enough, an agent can go deeper, pulling the underlying data elements the graph points to: time series, packet capture, metadata, endpoint detail, delivered live by Alliance members over API or MCP. And because the graph is field-integrable, context engineers can wire in new sources in situ, extending what agents can reason over without waiting on a product release.

Above the graph sits the harness: orchestration, workflow execution, memory, human approvals, governance, the control plane every agent action runs through. Above that, the agents themselves: platform co-pilots, AI SOC platforms, AI-native MDR, and custom agents, each calling one or more models to reason. Running underneath the entire stack, continuous adversarial validation keeps asking the only question that matters: are we secure? Human oversight brackets the whole loop, from analysts in the loop on containment to a manager of agents on the loop across the system.

There’s a reason the model sits on top, not underneath. Context and harness are the water and the pipes, the deep infrastructure that has to be right before anything flows: the evidence agents reason on, and the governed runtime that decides what they’re allowed to do about it. The Agent and Model drink the water. That separation is deliberate. It means a better model, a cheaper model, a more specialized model for a given task, can be swapped in as the field moves, without digging up the pipes the entire city of agents depends on. Model evolution is a design element, not an afterthought: perfect the model over time, continuously, without re-architecting the infrastructure underneath it every time a better one ships.

Why this can't be one company's product

Here's the part that matters most, and it's the reason we didn't just ship a product and call it a category. No single vendor delivers this operating model. Enterprises have spent a decade and enormous budgets building out their security stacks, and the future isn't ripping that out for one company's closed platform. The future is an open architecture where the best context sources, the best harness, and the best models interoperate, and where a security leader can choose each layer on its merits and trust that the pieces fit.

That is why we launched the Agentic SOC Alliance. It brings together network detection, endpoint, identity, threat intelligence, AI-native SOC platforms, orchestration frameworks, and adversarial validation. These are companies that compete in some places and cooperate in others, aligned around a shared architecture and a shared set of requirements for how autonomous security should work. The Alliance is not a marketing coalition. It is the operating model made real, with named integrations and interoperable layers, so a customer can assemble an agentic SOC out of best-of-breed parts and hold each vendor to the same standard, rather than betting the entire program on one company's roadmap.

ExtraHop's role in that architecture is the one we have spent more than a decade earning: the real-time context layer. When an agent needs to know what actually happened on the wire, decrypted, protocol-level, attributed to an identity, and correlated across the environment, that is the evidence we produce and the ground truth the rest of the stack reasons on. I will make the case for that layer every day of the week. But the point of this piece is not our layer. It is that the operating model is bigger than any single vendor, and it only reduces risk if the whole architecture works together.

What security leaders should do now

If you run a SOC, the shift I'm describing is not a five-year horizon. The adversary already operates this way. Government agencies across the US and its allies have said as much in the past month, and the enterprises moving fastest are already redesigning around autonomy rather than automating the edges of a human-speed process.

You do not have to rebuild everything at once, and you should not. But you do have to change the question you are asking. Not “which AI tool speeds up my analysts,” but “what is my SOC organized around.” If the answer is still a SIEM and a queue, you are optimizing a model built for a threat that no longer exists. Start with context, because nothing downstream produces a defensible answer without it. Insist on a harness, because autonomy you cannot govern is autonomy you cannot deploy or defend to a regulator. And stay model-independent, because the day you lock into a single model is the day you cap how good your defense can get.

The SOC that outpaces the machine-speed adversary will not be the one with the largest team or the biggest budget. It will be the one built on the right operating model. That model exists today, it is open, and the industry is aligning behind it. I would rather every security leader adopt it deliberately, on their own timeline, than be forced into it by an incident. The opportunity in front of us is to get ahead of the adversary for the first time in a long time, and to help our customers reduce real risk while we do it. That is a future worth building, and it is one we intend to build together.

Read the press release announcing the Agentic SOC Alliance

blog image
Blog author
Greg Clark

CEO, ExtraHop

Greg Clark serves as CEO of ExtraHop and is co-founder and managing Partner of Crosspoint Capital Partners, a private equity investment firm focused on the cybersecurity, privacy and infrastructure software markets. Crosspoint has helped many of its platform portfolio companies scale across growth horizons through operational improvement and by combining with management, including taking on the role of CEO during critical inflection periods on the journey to profitable growth. Clark served as Executive Chair of DigiCert as well as CEO of Forescout Technologies to help those companies through critical inflection points.

Clark brings to ExtraHop decades of cybersecurity sector expertise, technology management expertise and a proven ability to scale businesses. He has led multiple companies through phases of innovation and growth, including Blue Coat Systems where he served as CEO from 2011 to 2016, prior to the company being acquired by Symantec Corporation. Following that transaction, Clark served as CEO and member of the Board of Directors of Symantec from 2016 through 2019. Earlier in his career, Clark served as CEO of Mincom (acquired by ABB Group), E2open and Dascom (acquired by IBM).

Share
LinkedIn logoX logoFacebook logo
Key Takeaways
  • In the age of AI threats, the traditional SOC model is obsolete.
  • Bolting AI onto existing SOC tools doesn't close the speed gap; it just moves the bottleneck.
  • A machine-speed SOC requires a three-layer operating model: Context, Harness, and Model.
  • No single vendor can deliver this operating model.
  • The Agentic SOC Alliance brings together network detection, endpoint, identity, threat intelligence, AI-native SOC platforms, orchestration frameworks, and adversarial validation vendors to accelerate autonomous SOC operations.

Experience RevealX NDR for Yourself

Schedule a demo