General Cybersecurity

This Is What Happens When Analysts Rely on AI

Your AI flagged the threat. Your analyst escalated it. Nobody in the room can tell you why it was suspicious. You think that’s a win. I’m telling you it’s a slow-motion disaster.

I’ve been teaching and working in this field for thirty years. And one of the most consistent things I’ve watched happen over the last few years isn’t a technical failure — it’s a cognitive one. Analysts are losing the ability to think through a problem without a platform telling them where to look first.

That’s not a small thing. That’s the foundation of what makes a good analyst.

WHAT I’M ACTUALLY SEEING
Ask a junior analyst to walk you through an alert they just escalated. A lot of them will point at the dashboard. They’ll show you the severity score. They’ll read you the description the tool generated.

Push harder. Ask them what happened before the alert fired. Ask them what they ruled out. Ask them why this particular behavior looked suspicious to them personally.

Blank stare.

That’s not the analyst’s fault. That’s what happens when we build workflows that reward fast ticket closure and never ask people to demonstrate their reasoning. The tool becomes the answer, and the analyst becomes the hand that moves the ticket from “open” to “closed.”

I tell my students this all the time: the alert is not the analysis. The alert is the starting gun.

THE SKILL THAT’S QUIETLY DYING
The thing AI detection tools are eroding isn’t speed or coverage — it’s adversary reasoning. The ability to look at a sequence of events and ask, “If I were trying to do something bad here, what would I actually be doing? Does this fit that pattern?”

That kind of thinking doesn’t come from a confidence score. It comes from practice. From getting it wrong, reconsidering, and building up a mental model of how attacks actually unfold over time — not just how they look at the moment of detection.

When analysts stop exercising that muscle, it atrophies. Fast. And because it happens gradually, nobody notices until the tool misses something. Then you find out your whole team has been riding the platform so long they’ve forgotten how to drive.

Sophisticated threat actors already know this. They know what detection tools are tuned to catch. They operate just below those thresholds on purpose. The only thing that catches that behavior is an analyst with enough pattern recognition to feel like something is off — even before the alert fires.

You cannot automate that instinct. But you can absolutely train it out of people.

THIS IS A LEADERSHIP PROBLEM
Stop blaming the tools. AI detection platforms aren’t the issue. How you’ve integrated them into your analyst workflow is.

If your metrics reward ticket velocity, you’ve already told your team that speed matters more than thinking. If you’ve never run an exercise where analysts have to work without the platform, you’ve never found out how dependent they are on it. If you promote the analysts who close the most alerts and not the ones who ask the most useful questions, you’ve built exactly the culture you deserve.

I’ve watched SOC leaders build teams that are, technically, very efficient. They process high alert volumes. Mean time to respond looks great on paper. And then something genuinely novel comes through and the whole operation goes quiet because nobody knows what to do without the playbook.

That’s the gap. And it didn’t come from a staffing shortage. It came from years of letting the platform do the thinking.

WHAT TO DO ABOUT IT BEFORE IT COSTS YOU
Require documented reasoning, not just documented actions. When an analyst escalates an alert, they should be able to explain what they looked at, what they considered and ruled out, and why they made the call they made. If they can’t, that’s the gap showing itself.
Run tabletop exercises without the tools. Give analysts a scenario and make them work through it on a whiteboard. No platform, no playbook. You’ll find out very quickly how much of the thinking has been outsourced.
Make questioning alerts a valued behavior, not an inefficiency. The analyst who pushes back on a false positive and explains their reasoning is doing exactly what you need. If your culture treats that as slowing down the queue, fix the culture.
Reframe AI output as input. A detection is a hypothesis, not a verdict. Train your team to treat it that way from day one. The tool noticed something. Now your analyst’s job is to figure out what it actually means.
Get your experienced analysts teaching, not just doing. The tradecraft that catches sophisticated threats lives in people’s heads. If it’s never being transferred to junior staff because everyone’s too busy closing tickets, it’s going to walk out the door when those people leave.
THE REAL COST OF GETTING THIS WRONG
Skill atrophy in a SOC isn’t like a slow server or an outdated signature. It doesn’t throw an error. It just means that when something genuinely dangerous and genuinely novel comes through, the people you’re counting on don’t have the foundation to catch it.

You won’t know the gap exists until you need there not to be one.

The best analysts I’ve ever worked with got suspicious when everything looked clean. They’d look at a quiet morning and say “something’s wrong.” That’s not a skill you buy in a platform subscription. It’s a skill you build — or destroy — through the environment you create.

If you’re building an analyst team and want a structured approach to developing that kind of foundational tradecraft, check out the resources at jrobertsonsecurity.gumroad.com. Less theory, more the things that actually matter in a real SOC.

← Threat Intel Programs That Can't Answer Who's Targeting YouWhat 125,336 People Had to Say About Breaking Into Cybersecurity →
← Back to Blog

Want to Go Deeper?

Browse online courses that cover these topics with the depth and clarity you need to apply them.