At the FutureCrime Summit 2026, a workshop titled “AI-Driven SOC Capabilities for Threat Detection and Response” examined how artificial intelligence is reshaping the role of Security Operations Centres and helping cybersecurity teams detect, analyse and respond to threats at greater speed.
The workshop was led by Aritra Roy, Information Systems Head at Pyramid Cyber Security, and focused on the growing importance of AI-enabled capabilities within modern security operations. As organisations contend with expanding digital infrastructure, increasingly sophisticated attacks and enormous volumes of security alerts, the ability to distinguish genuine threats from background activity has become a critical operational challenge.
AI Is Transforming Security Operations Centres
Security Operations Centres sit at the heart of an organisation’s defensive capabilities. They are responsible for continuously monitoring systems, identifying suspicious activity, investigating alerts and coordinating responses when a security incident occurs.
The challenge is scale. Modern organisations generate vast quantities of security data across networks, applications, endpoints and cloud environments. Traditional approaches that rely heavily on manual review can make it difficult for analysts to identify the most serious incidents quickly enough.
The workshop theme highlighted how artificial intelligence can strengthen this process by helping security teams analyse large volumes of information, recognise unusual patterns and prioritise alerts that may require immediate investigation. Rather than replacing security professionals, AI-driven SOC capabilities can support analysts by reducing repetitive work and allowing them to focus on complex incidents where human judgement remains essential.
Faster Detection Can Strengthen Incident Response
Threat detection is only one part of effective cybersecurity. Once malicious activity has been identified, organisations must determine the nature of the incident, assess its potential impact and take appropriate action before the threat spreads further.
AI-enabled capabilities can assist security operations by correlating information from different systems and helping analysts develop a clearer picture of an attack. In environments where cyber incidents may develop within minutes, faster analysis can significantly improve the ability of response teams to contain malicious activity.
The workshop led by Aritra Roy, Information Systems Head at Pyramid Cyber Security, therefore placed detection and response within the same operational framework. A stronger SOC is not simply one that generates more alerts, but one that can identify which alerts matter and translate that information into timely action.
Human Expertise Remains Central To AI-Driven Defence
The increasing use of artificial intelligence also raises an important operational consideration: automated systems must operate alongside skilled security professionals. AI can process large quantities of information and identify patterns at speeds difficult to achieve manually, but cybersecurity investigations often involve context, uncertainty and rapidly changing circumstances. Analysts must still evaluate evidence, understand organisational priorities and decide how an incident should be handled. This makes the development of AI-driven SOC capabilities a combination of technology, processes and human expertise.
The broader message of the “AI-Driven SOC Capabilities for Threat Detection and Response” workshop was that modern cyber defence increasingly depends on the ability to convert enormous volumes of security data into meaningful and actionable intelligence.
As cyber threats become faster and more sophisticated, organisations will need Security Operations Centres capable not only of monitoring their environments continuously, but also of recognising emerging threats quickly and coordinating an effective response. AI is increasingly becoming an important part of that capability, while experienced cybersecurity professionals remain central to making those systems effective.
