The emergence of the tierless SOC

October 6, 2026

Written by

Zev Schonberg

A LinkedIn post made the rounds recently, recapping a talk by Jason Clinton, Anthropic's Deputy CISO, at the SANS Cloud Security Exchange Summit on August 18. It contained a line that would have sounded absurd two years ago. Anthropic's SOC has no tier one or tier two. AI ingests the alerts, runs the investigations, and routes the genuinely hard calls to humans.

‍

It would be easy to dismiss this as a stunt only an AI company could pull off. That would be a mistake. What Clinton described is a working example of an operating model the rest of the industry is moving toward. The tiered SOC has always been a workaround for a constraint, and that constraint is now disappearing.

Yesterday’s SOC pyramid was built around human limits

The classic SOC is shaped like a pyramid because investigation does not scale. A broad base of tier one analysts absorbs the alert flood, filtering false positives and escalating what survives. A narrower band of tier two analysts investigates. A small group of senior responders and specialists sits at the top. The whole structure exists to ration a scarce resource, which is human attention.

Everyone who has worked inside the pyramid knows its failure modes. Tier one is grueling, repetitive work that analysts try to escape as quickly as they can, taking their hard-won context with them when they go. Every handoff between tiers loses information. And the majority of the pyramid's capacity is consumed by alerts that turn out to be nothing.

Saying goodbye to the pyramid

AI removes the reason the base exists. Alert post-processing, false positive filtering, enrichment, and first-pass investigation are exactly the tasks AI now handles well, at machine speed and without fatigue. When that work moves to AI, the organization stops hiring as intensively for it, and the pyramid structure can change into whatever will work best for a particular organization. While there will always be a need for tier 1 type of work (e.g. looking into the small percentage of alerts that the AI SOC escalates), it won’t require the same amount of humans and much of tier 1 focus can shift upwards to tier 2 and 3 work. 

The same shift is happening to specialist skills. Work that once required dedicated experts, such as detection engineering or writing virtual patch rules, can now be done in real time by generalist security staff working with AI. The practical effect is dramatic. A team of eight to ten people can produce the operational output that used to require thirty or forty, and they can keep advanced functions in house instead of outsourcing them.

Where analyst time actually goes

Here is the part most SOC leaders underestimate. In a typical twenty minute ticket window, an analyst spends roughly 75% of the time looking things up. Pulling threat intelligence, checking asset ownership, gathering logs, reconstructing what happened. Only the remaining sliver is spent actually deciding.

AI agents invert that ratio. Enrichment and context gathering are finished before the analyst ever opens the ticket, which massively expands the real decision-making window. The analyst opens a case that already contains the evidence and reads like a narrative instead of a scavenger hunt. Multiply that across a relentless queue and you get the same people processing far more alerts with far less fatigue.

Prove it with numbers

None of this matters if you cannot measure it, and most SOCs cannot. Ask a security team for their mean time to detect and you will usually get an arbitrary figure that reflects a gut feeling rather than their actual threat landscape.

There is a more honest way to do this. Take your past severity 1 incidents and reverse engineer them. Map each one back to the MITRE ATT&CK techniques and the alerts that fired, and work out how long detection actually needed to take for that class of threat. Ransomware and insider threats have very different clocks, and treating them as one number hides both.

Once you have real baselines, AI-driven operations give you something security teams have rarely had, which is undeniable proof of impact. When your measured MTTD drops from say 32 minutes to 18, that is evidence you can put in front of a board, and it compounds as the system keeps learning.

Why you can't just wait for Anthropic to sell theirs

An obvious objection to all this is that if Anthropic built this, it will eventually be a product anyone can buy. Three things make that a risky bet.

A model is not a platform. What Anthropic built is a bespoke internal system, wired by their own engineers into their own telemetry and tuned for exactly one environment. Recreating it means an engineering project with integrations, detection content, guardrails, evaluation, and permanent maintenance. Most security teams are trying to escape that kind of build burden, and the industry's first reaction to the talk said as much. It's a cool build that only an AI company could pull off.

The economics don't transfer. Investigating 100% of alerts at forensic depth, including the low severity noise where real threats often hide, means running heavy AI reasoning millions of times a month. Anthropic gets its tokens at cost (which itself is not free as the underlying compute is expensive). But everyone else pays retail, and per-alert or per-token pricing punishes you for investigating everything. Making full coverage affordable requires an architecture where deterministic forensic engines do the expensive evidence collection cheaply and reproducibly, with AI reasoning on top of that evidence.

Supervision requires proof. LLM output is probabilistic, and a SOC verdict needs evidence a human, an auditor, or a regulator can inspect and reproduce. Intezer’s deterministic forensics return the same verdict on the same artifact every time, which is what lets humans supervise outcomes instead of re-checking the AI's homework.

The only two tiers left

Strip away the org-chart archaeology and a simpler model emerges. There are only two tiers that matter in an AI-native SOC. AI executes, and humans supervise.

Execution means every alert gets a full investigation, every time, with evidence attached. Supervision means humans review outcomes, tune detections, handle the novel cases that require judgment, and hold the system accountable. The people in this model do more interesting work than the pyramid ever offered them, and the SOC scales its outcomes without scaling its headcount.

Anthropic has shown that tierless SOC is a reality. At Intezer, we built the productized way to get there, with a decade of deterministic forensic technology doing the heavy investigative lifting, AI reasoning on top, and per-endpoint pricing that makes investigating every alert affordable. Your team supervises the results.

Learn more about Intezer AI SOC.

‍

Zev Schonberg

Zev Schonberg is a product marketing manager with years of experience in deep tech.

As a lead contributor at Intezer, Zev authors research-driven analysis and thought leadership that explores how modern security operations centers can better detect, investigate, and respond to threats at scale.

‍

In this article

Share article

Related Articles

AI SOC

The emergence of the tierless SOC

AI is retiring the SOC pyramid. Learn how a tierless AI SOC investigates 100% of alerts with forensic evidence while your analysts supervise outcomes.

Research

5 min

NinjaMare and the enterprise security epidemic hiding behind a harmless label

The PUA label, aka "potentially unwanted application" means nuisance. Adware, toolbars, and other things that change your settings without asking. Our research team's findings say this label is far more serious than a mere nuisance.

‍

Alert Triage

AI SOC

3 min

We let a fruit fly brain triage 12,716 real SOC Alerts. Here is what happened.

On behalf of people who run SOCs, we explore how a fly brain triages alerts compared with a boring linear model you could train in eleven seconds.

‍