The Value of Cybersecurity Operations by Christopher Crowley points to a timely operational question: what changes when artificial intelligence enters the security operations center, and what does not? AI can change the speed and scale of analysis. It does not change the central purpose of cybersecurity operations - preventing or reducing losses from compromise, disruption, fraud, data exposure, and unsafe system behavior.
That distinction matters because security teams are often asked to justify new technology in terms that obscure their mission. A security operations center is not a revenue engine. Its value is found in disciplined loss prevention: identifying meaningful threats, containing incidents before damage expands, protecting essential services, and providing leaders with defensible information when decisions matter.
Christopher Crowley’s work on the value of cybersecurity operations remains useful in an AI-heavy market because it directs attention back to operations. Tools matter, but the mission, operating model, people, processes, and measures determine whether tools make the organization safer.
Cybersecurity Operations Is a Business Protection Function
A mature security operation converts technical signals into protective action. Logs, alerts, endpoint telemetry, cloud events, vulnerability findings, and threat intelligence have little inherent value when they remain disconnected data. Their value emerges when the organization can use them to recognize risk, investigate efficiently, make a decision, and act within the time available.
This is why security operations should be evaluated as a capability rather than a collection of products. A company can own an advanced SIEM, endpoint platform, and AI assistant while still missing incidents because ownership boundaries are unclear, alert logic is weak, escalation paths are undefined, or responders lack authority to contain a threat.
The operational questions are direct. What assets and business processes require protection? Which threats are most consequential? What evidence will reveal those threats? Who investigates? Who can isolate a host, disable an account, or take a service offline? How is the incident communicated to executives, legal teams, customers, or regulators? Those answers define the practical value of the operation.
The Value of Cybersecurity Operations in an AI Era
AI can improve several demanding parts of security work. It can help analysts summarize a long investigation, normalize information from multiple sources, propose search queries, translate technical findings for nontechnical stakeholders, and identify patterns worth reviewing. Used carefully, these capabilities can reduce friction in repetitive analytical tasks.
But AI is not a security operation. It does not establish accountability, understand the full business consequence of a decision, or validate its own conclusions. A model may produce a plausible explanation for an alert without possessing the evidence needed to support containment. It may also inherit blind spots from incomplete data, flawed detections, or incorrect assumptions in the prompt.
The trade-off is straightforward. The more aggressively an organization automates action, the more confidence it must have in the data, logic, guardrails, and recovery process behind that action. Automatically enriching an alert with context may carry limited operational risk. Automatically disabling a privileged account, blocking network traffic, or shutting down a production workload requires a higher standard of validation.
For that reason, AI should be introduced according to the consequence of error. Low-risk assistance can be adopted early, while high-impact automated response should be constrained, tested, monitored, and reversible. Human judgment remains essential when an action affects patient care, financial transactions, industrial processes, defense operations, or customer-facing services.
Better Triage, Not Blind Triage
Alert volume is a persistent SOC problem. AI can assist by grouping related alerts, highlighting unusual sequences, and preparing a concise case narrative. This may help analysts spend less time moving between consoles and more time evaluating evidence.
However, alert reduction is only valuable when it preserves meaningful detection coverage. A quieter dashboard can indicate better prioritization, but it can also indicate that important events are being filtered out. Teams should test AI-assisted triage against known incidents, simulated adversary behavior, and representative production data. The goal is not fewer alerts by itself. The goal is faster recognition of the alerts that require action.
Faster Investigation, With Evidence Intact
Investigation quality depends on evidence: timestamps, identities, affected assets, process behavior, authentication activity, network connections, and relevant business context. AI can organize this material and suggest investigative paths. Analysts must still verify source records and document why a conclusion is sound.
That discipline protects the organization in two ways. It improves technical accuracy, and it produces an audit trail that can support leadership decisions, legal review, insurance discussions, regulatory obligations, and lessons learned after an incident. A polished AI-generated narrative is not a substitute for verified evidence.
Measure Protective Outcomes, Not Tool Activity
Security leaders need measures that explain whether operations are becoming more capable. Counting tickets closed, alerts ingested, or AI prompts submitted may describe workload, but those figures do not reliably describe protection.
More useful measures connect the SOC to operational readiness and loss prevention. They can include the percentage of critical systems covered by actionable telemetry, the time required to validate and contain high-severity incidents, the quality of detection testing, the age and recurrence of critical weaknesses, and the completion of corrective actions after incidents. Measurement should also show where visibility or response authority is missing.
No single metric can represent the value of cybersecurity operations. A faster time to close may be positive, unless cases are being closed without sufficient investigation. Broad coverage may be positive, unless the resulting signal quality overwhelms the analysts responsible for review. Metrics need context, trend analysis, and a clear connection to the organization’s most important assets and risks.
This is also where AI requires its own operating measures. Leaders should know which workflows use AI, what data enters those workflows, whether sensitive information is retained or exposed, how output is validated, and when an analyst overrode or rejected the recommendation. These controls turn AI from an informal convenience into a managed capability.
Build AI Into a Defined Operating Model
Before adding AI to a SOC workflow, establish the conditions for responsible use. Define the intended task, the available data sources, the person accountable for the outcome, the validation method, and the permitted actions. If those elements cannot be stated clearly, the workflow is not ready for automation.
Data handling deserves particular attention. Security operations often process information that is highly sensitive: credentials, internal architecture, customer records, legal material, vulnerability details, and incident evidence. Teams need clear rules for what may be submitted to an AI service, how it is protected, where it is processed, and how long it is retained. Convenience cannot override confidentiality or contractual obligations.
Adversaries also adapt. They may attempt to manipulate data that models summarize, exploit weaknesses in automated decision paths, or use AI themselves to generate convincing phishing content and accelerate reconnaissance. A SOC that uses AI should include AI-related failure scenarios in tabletop exercises and detection engineering. The technology is part of the environment that must be defended.
Organizations do not need identical AI programs. A small team may gain the most from analyst assistance, standardized investigation templates, and better documentation. A large enterprise with mature engineering, extensive telemetry, and formal change control may safely pursue more advanced orchestration. The appropriate level depends on mission criticality, team maturity, data sensitivity, and the organization’s tolerance for an incorrect automated action.
Keep the Mission in Charge
The strongest case for AI in security operations is not that it replaces analysts or makes difficult decisions disappear. Its value is that it can help capable people apply their attention where it has the greatest protective effect. That requires a functioning operating model first.
Montance® offers The Value of Cybersecurity Operations in formats suited to professional learning, including digital, audio, print, and webcast-based study. For security leaders and practitioners, the enduring lesson is practical: build the people, processes, authority, evidence, and measures that enable protection. Then apply AI where it strengthens that mission without weakening accountability.