How GM Financial took control with AI SOC
Watch on demand
Financial services SOCs don't get the luxury of "good enough." Regulatory pressure is constant, alert volume is relentless, and one missed escalation can turn into a compliance headache or worse.
In this episode of AI SOC Live, Intezer Field CISO Mitchem Boles sits down with David Barron, AVP of Cybersecurity at GM Financial, for a candid look at what it takes to bring AI SOC into a financial services environment. With more than 14 years at GM Financial, David shares how his team uses AI SOC to catch early attack signals, accelerate investigations, and give analysts more time for threat hunting and detection engineering.
What you'll learn
- How AI SOC finds threats hiding in low-severity alerts
During purple team testing, GM Financial saw the AI SOC take a bottom-of-the-barrel informational alert and escalate it to critical minutes before a higher-severity detection fired. For David, that early catch is the real value. If a sophisticated attacker evades the high-severity detections, the AI SOC can still flag the activity from the weaker signals. - Why investigation reasoning speeds up triage
Traditional tools deliver a blob of correlated data. An AI SOC delivers the story behind it, including the decision it made and why. Analysts start from a complete picture with host activity, network traffic, and user behavior already analyzed, so they can quickly confirm or challenge the conclusion. - How AI SOC fits alongside in-house teams and MDR
There is no one-size-fits-all model. David sees AI SOC as a universal augmentation layer that triages every alert at machine speed with full context, whether the reviewer is a tier 1 analyst or an MDR provider. - The metrics that matter as coverage grows
When far more alerts are evaluated and time to respond drops sharply, traditional metrics like MTTD and MTTR start to lose meaning. David and Mitchem discuss shifting toward outcome-based metrics and how to explain a sudden jump in evaluated alert volume to leadership and the board. - Advice for teams adopting AI SOC
Turning it on is only the first step. David recommends treating the AI like a new analyst by giving it your playbooks, the correlative data your team would pull, and the tribal knowledge unique to your environment. Then refine prompts and validate the results with attack simulation. - How to build trust in AI SOC
Skepticism is healthy. David explains how continuous purple teaming and attack simulation help validate AI SOC results, and how teams can keep humans in the loop while letting AI-escalated alerts jump to the top of the queue. - The future of SOC analysts
AI SOC is shifting where analysts spend their time. David explains why organizations still need tier 1 analysts to build the next generation of senior talent, and why he still sees a strong cybersecurity career path, including for his own son.
Watch the full conversation
Whether you're evaluating AI SOC for the first time or looking to mature an existing rollout, this session offers practical lessons from a security leader running AI SOC in one of the most regulated and most targeted industries.
Speakers
More webinars

webinar
AI SOC Live Episode 3: 2026 AI SOC Report for CISOs
Episode 3 — Key findings from the 2026 AI SOC Report for CISOs and what they mean for security operations.
See Intezer in Action
Discover how AI-powered endpoint triage can eliminate alert fatigue and supercharge your SOC's efficiency.



.jpg)


