S ecurity Operations Centres are being reshaped by expanding attack surfaces, hybrid environments, AI-powered threats and relentless alert volumes. As security teams struggle to keep pace, the traditional model of manual monitoring and reactive response is giving way to a more integrated, automated and intelligence-driven approach. Industry leaders explain how the modern SOC is evolving, why human judgement remains critical and which metrics now define success.
The traditional SOC was largely built around perimeter-based monitoring, siloed security tools and analysts manually investigating alerts. That model is increasingly difficult to sustain as enterprise environments stretch across cloud, SaaS, endpoints, identities and operational technology.
Kalle Bjorn, Sr Director Systems Engineering at Fortinet, said:“ A modern SOC is designed to manage today’ s distributed attack surface with greater speed, context and efficiency. Unlike traditional SOCs that often rely on siloed tools and manual processes, modern SOCs integrate security operations across on-premises, cloud, hybrid and operational technology environments. They leverage AI, automation and actionable threat intelligence to improve detection and response while reducing operational complexity. The emphasis has shifted from simply monitoring alerts to proactively managing risk, accelerating investigations and enabling analysts to focus on the most critical threats and strategic security outcomes.”
Kalle Bjorn, Sr Director Systems Engineering at Fortinet
The modern SOC moves from alert management to proactive defence.
Vibin Shaju, VP – EMEA Solutions Engineering at Trellix, sees the transition towards unified visibility and machine-speed defence as equally significant.
“ Traditional SOCs relied on perimeter-bound monitoring, manual alert triage, and reactive firefighting. Modern SOCs, on the other hand, are built on adaptive, machine-speed defense and unified visibility. The key shift lies in moving from siloed point tools to an open, telemetry fabric that correlates signals across endpoints, cloud, identity, and network in real time. By combining predictive analytics with automated workflows, modern SOCs continuously assess exposures, uncover subtle behavioral anomalies, and execute automated
Vibin Shaju, VP – EMEA Solutions Engineering at Trellix
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 25