← All writing

How AI Changed the SOC, Part 1: An Alert Machine Is Not a SIEM

Fluency Security12 min read

How AI Changed the SOC, Part 1: An Alert Machine Is Not a SIEM article illustration

What does a SOC actually deliver for what it costs? In Part 1 of our webinar How AI Changed the SOC, Henry Denner of ASI Connect lays out the frustrations every MSSP recognizes: the pressure to do more with less, MDR competing for the same budget, and clients who receive five emails a week and ask what they are paying for. Chris Jordan, CEO of Fluency Security, answers from first principles. A SIEM is decision-making software, not hindsight analysis. Noise is reduced by moving from events to notable events, alerts, clusters and cases, and if your SIEM is not generating cases, you have an alert machine. AI needs that clustered context to be useful, just as you cannot name a song from one note. And the real value of a managed service is that the client no longer has to worry about false positives at all. The goal, as Henry puts it, is a SOC that helps a business get better rather than one that only tells it what happened.

Transcript

Patrick Evans: So good day, everybody. My name is Patrick Evans. I'm the moderator today. And today we're looking forward to having a, let's call it an honest conversation about something that quietly frustrates almost everyone in security operations. And that is my words. Those are the words of people we talk to. The gap between what a SOC costs us and the value we can actually see deriving from it are very different.

Too often we're sold the platform, some pile of dashboards, and then left to figure out what it all means for the business. Today, we want to flip that around and start with a question that really matters. What are you actually trying to achieve? To help us unpack that, I'm delighted to be joined by two people who think about this very differently. Chris is the CEO of Fluency Security, and notably one of the very few CEOs who personally gets on a call to listen to what a customer actually needs.

And Henry from ASI Connect is being on the front line, turning a SOC from an alerts factory into a genuine insight engine that helps clients make decisions. Henry is going to set the scene with the real frustrations we all recognize. Cost, complexity, effectiveness. And then put Chris on the spot to answer them. I'll keep us on track and make sure we're getting the value, not just the technology.

Henry, I think you're going to be kicking it off. So, over to you, my friend. Thanks.

Henry Denner: Thanks, Patrick. And, hello, Chris. Nice to talk to you across the waters. It felt like only yesterday we had a conversation. Oh, wait, we did. Every day. So, let me put the scene. First of all, so the audience stands for joining us as well. I've been in the SOC game for a while, actually, in a managed services space for a while. And the one thing that I often get a challenge of is, how does security deliver value to a client?

How does security really help a client to grow? And I see that as a pivotal point for a SOC. A SOC shouldn't just be something that gives you an alert and an email that says, oh, you had this user logged in from Amsterdam and it's supposed to be in Cape Town. Or, hang on, somebody's trying to break into your firewall. What does it really mean? And how does it really help your clients to actually become better?

So, if you batch all of this together with being an MSSP and you've got multiple clients to keep happy, that whole thing just escalates. So, the challenges that we all face from a SOC perspective are basically a few things in my mind. Number one is efficiency. So, we are pressed to do more with less. So, what often happens, we've grown the client base with a thousand endpoints or 10,000 endpoints.

Now, we have to appoint people, but people cost money. Does it make us more efficient? In my view, no, it doesn't. It makes us more effective because we've got more hands. So, secondly, if you look at what's happening in the MDR space, MDR is eating into the SOC space at an average rate of about 17% year on year, which means that SOCs are coming under pressure to deliver more.

Now, if you look at what a SOC costs you, if you look at the people behind it's very difficult to compare from a financial perspective what the SOC can do versus MDR. And then if you look at the output of your average SOC, it doesn't really differ much from a normal MDR solution. So, you pay $5 per device for the MDR versus $20 per device for a SOC, just stirring some fingers around.

What is the actual value that you get? And that is really what I struggle with. So, the last thing from setting the scene is how does the SOC actually create that value? I often face a question where a client says to me, but I pay all of this money. I get five emails a week. Are you doing your job? What am I getting out of it? They often can compare a SOC with a service desk.

And you can't really because it's two very different services. But in a client's mind, they see it as just another service desk, but a security service desk. So, when I started this journey with Fluency, those were the key things that I asked. How do we become more efficient? I want to do more with less. I don't necessarily just want to appoint more people for the sake of dealing with alerts quicker.

I want to have a system that's more efficient. I want that system to be able to give me actionable intel that I can take to my clients and say, Mr. Client, here are the five key things you need to focus on. Not here are your top alerts for the month, because that's past. How do we prevent the same things happening going forward? So, how do we deal with the risks?

And how do we deal with opportunities to actually help the client become better? And that's really where the big thing for me sat, is how do we get a system that actually helps us drive that whole context forward? So, Chris, I don't know if you want to forge in there, or we can dive into the rest. Well, I think we can break it up piece by piece,

Chris Jordan: But I think one of the first things we can talk about, which is really important, is understanding what is, with the product, like a lot of times people think a SOC is just a SIEM. So, what is a SIEM? What does it really do for you? And what does a SOC really do? And that will help us understand value. But I think one of the most important things that we can talk about is just that when we look at a thing like a SIEM, it's more than just alerts and events.

It's a, it's a decision-making piece of software. It's not a hindsight analysis. It's designed to help us make decisions. And I think when you take a look at what is the value in today's world of AI, the value is the human expertise. So I think that we can start off around, efficiency and stuff like that, and we can work our way to actually coming up with what is the value for an MSSP or what's the value of a SIEM?

Henry Denner: Yeah, makes sense. So when we talk about efficiency, if we can then dive in, one of, one of your strengths in my view is your AI capability and how you actually filter out alerts to reduce the noise. So a big problem in any SOC is reducing the noise. The more noise you have, the more people you need to deal with the noise. The more false positives you share with clients.

So how are you dealing with, or how should the software be dealing with that noise, becoming more efficient, using better AI to actually improve things? Wow.

Chris Jordan: I'd say actually like two different things we need to answer on that. One is how do we get through data so well? And the first piece is that we have to look at the world before AI, because it's important to understand AI is not changing anything in the fact of how do we reduce noise? So to reduce noise, we go from what we call events to notable events, from notable events to have alerts, to what we call clusters, UEBA clustering.

That type of technology helps us reduce the amount of stuff that we need to look at, because from a cluster, we can score a cluster and say, this cluster needs to be analyzed. That cluster can have thousands of events and hundreds of alerts in it. And so when we take a look at it, a lot of times people talk about the reduction of alerts, but it's not, it's the reduction of cases.

And so the first piece is if your SIEM is not generating cases, you don't have a SIEM, you have an alert machine. And that's the reason why there's so much pushback. Now we can add AI to that level and AI can then evaluate and say on this cluster, what do I see? And it's really important because it's like name that tune. If you only have one note, there's no way in the world you can name that song.

You need a bunch of notes. And it's the same thing that if I have a cluster, I have a bunch of data. And if a human struggles with one note, think what an AI does, it struggles worse. Okay. So the context is really important. Clustering is very important in the AI world. And a lot of people skip that. They think that if I grab all my data and throw it to AI, it will work.

That's just going to crush one token. So the first thing we have to do is say, here's this reduction. Now, the second part to that answer is, what does it mean to the end customer? And it's fascinating because you're an MSSP, you deliver a service. What I like to tell salespeople when they're selling MSSP services is that, if you go on the internet, it's the number one thing people talk about noise, false positives.

You bought a service. That is actually not your worry anymore. It's no longer your concern. When you, if your customer is asking you that question, they have no clue the value you just added, because that's the real value of the MSSP is it's no longer their concern about false positives and volume. You're taking care of that. And that's the part people miss. They get involved trying to solve what they're buying.

Right? But people don't go into an engine and examine everything about an engine. Yes, there's motor heads, but when people buy a car, they look at the stats and they look at the results. And right now, people aren't looking at the results of an MSSP. They're trying to do the MSSP's job.

Henry Denner: That is very true. Often I see that we actually have more of a process failure than actually a system failure. In wanting a system to do what a system is not designed to do. And I think for me, that is a key aspect when you evaluate a SIEM to design. This is something that's fit for purpose. So when we dive into the actual architecture of what makes Fluency better or what makes it different, I think better is probably a very subjective term because what's better for me is not always better for you.

But in your view, the architecture of Fluency allows for a bunch of things that were different. You talked about pages and that kind of stuff. How does that architecture of Fluency actually play into building that crisis and to actually help with efficiency?

Chris Jordan: So the strange thing about how Fluency is built, it's built based upon a coder's way of looking at the universe. And so what I mean by that is that we're not trying to build a database and give you access to data. A real program, a real coding is about taking processes and implementing those processes and logic into the system. So that the person doesn't need to know that logic.

Right. Charles is listening to this right now. There's like over 200 tables in Microsoft. Do you know that? Do I know that? No. I ask a query. It distributes that query. Does it map reduce? And we get answers across that grid of all those tables. And that's a big difference is that, we need to realize that the complexity is not the issue anymore. So from an architecture point of view, so we have all this complexity, but from an architectural point of view, what we're trying to do is put that complexity into the system.

And when you do that, I'm no longer saying, look at this table, run this query, do this. What I'm beginning to do is realize that my questioning and how I interact is more aimed towards what I need. Now, the other thing that's, we really came to as a, as a light bulb moment in this year is that we have always fought really hard about maintaining the best detection and the best speed.

And we do everything in real time. To tell you the truth, the system is designed to answer. But the weird part of all of this is that it's the other things that make a difference. And you're noticing it in the work you do, Henry, which is that your customers just aren't asking you to close tickets. They want to know their health and status. They want to know what's going on in the configurations, what they need to do.

And it changes the question of what you want a SIEM or what you want an MSSP to do. Do you want an MSSP to be hindsight and review prevention? That's what MDR is doing. Most people, when they turn to the MSSP, they're looking at you as a partner to answer questions about how can they move forward as an organization. I'm tired of being told what happened. Help me solve it and help me, my company get better.

And that's where expertise outside of closing a ticket is really what's missed by people. And that's what we've tried to build is a system that helps decision-making, not just to close an event, but understand what I need to do to run my system better. Absolutely.


About the webinar

How AI Changed the SOC aired live on September 16, 2026. It was a conversation between Henry Denner of ASI Connect, who runs security operations on the managed services front line, and Chris Jordan, CEO of Fluency Security, moderated by Patrick Evans. The session set out to answer one question: what are you actually trying to achieve with a SOC? Across four parts it covers how AI changes detection and response, what an MSSP should deliver beyond closing tickets, how data pipelines and infrastructure shape cost and compliance, and how buyers should evaluate vendors.

This post is Part 1, The Value Problem. The transcript has been lightly edited for readability. Watch the full episode and the rest of the series on the Fluency Security YouTube channel, or book a demo to see how Fluency turns alerts into cases.

Continue the thread

Get the next Fluency article.

Practical security operations, agentic workflows, new reports, and the engineering decisions behind The Unbounded SIEM.

Join the newsletter

The Unbounded SIEM

This is the thinking. The product is the proof.

Bring the question this post made you want to ask, and we will run it live.