Connect with us

Business & Technology

AI changes detection engineering – but only if you fix your context problem

Published

on


Artificial intelligence is powerful. That much is a given. AI doesn’t aid detection engineering, but it can expose its biggest weakness: a lack of organizational and threat context. 

Most detection engineering was built around human limits. Analysts could not investigate everything, so SOC teams tuned detections to reduce volume, suppress noise, and escalate only the alerts most likely to matter. 

However, in an AI-driven SOC, every alert can be investigated. And that makes detection quality even more important. If you feed AI weak detections, incomplete context, and poorly scoped logic, you just get bad decisions faster.

According to Prophet Security, an agentic AI SOC platform that investigates every alert rather than triaging a sampled few, detection engineering in an AI-driven SOC still depends on the same basic lifecycle: define hypotheses, write logic, test detections, tune performance, and retire what no longer works. What changes is what that lifecycle optimizes for. 

The old model optimized for fewer alerts, but the new model optimizes for richer, higher-quality signals. 

Why Detection Engineering Traditionally Focused on Analyst Capacity

Traditional detection engineering was developed to deal with limited analyst time. 

Traditional SOCs suffer from too many alerts, false positives, and suspicious-looking signals that had no operational impact. Detection teams tune aggressively because the alternative is an unmanageable queue. 

As a result, most SOCs aim to reduce alerts, investigations, and interruptions. While there’s nothing wrong with reducing noise, alert reduction shouldn’t be the main goal of detection engineering. 

Not every noisy detection is useless. Some alerts are noisy because the logic is bad. Others are noisy because the behavior is ambiguous and needs better context. Suppressing the second type just removes uncertainty from view.

When SOCs become AI-driven, however, the goal becomes making sure each alert contains enough context to support useful reasoning. 

How AI SOCs Shift Detection Engineering to Machine Investigation

AI compresses investigation time by collecting related events, summarizing activity, comparing behavior across systems, and generating an initial assessment far faster than a human analyst moving manually between tools. 

For SOC teams, that creates space to focus on judgment, escalation, and response – not gathering basic evidence. Detection engineers, specifically, can spend more time improving detection fidelity instead of firefighting alert noise. 

Those time savings matter. IBM’s 2025 Cost of a Data Breach Report found that the global average breach cost fell to $4.4 million, driven by faster identification and containment, and that security teams using AI and automation saw $1.9 million in cost savings compared with organizations that did not use those solutions.

The problem is that AI only has the knowledge the SOC give it access to. 

In the traditional model, an alert lacking sufficient context could still work if an experienced analyst knew how to interpret it. The alert might say that a user accessed an unusual resource, but the analyst knew the user, the application, the business process, and the likely exceptions. Much of the real context lived outside the detection itself.

That means an alert that made sense to a human analyst might be underpowered for AI. It may identify the event but not explain why it matters. It may lack asset criticality, identity context, expected behavior, known exceptions, recent changes, or relevant threat activity.

You can’t assume that AI can simply sit on top of existing detection logic and fix the SOC. It cannot reason well from incomplete inputs. 

This is why one of the leading AI SOC platforms, Prophet, backed by Accel and Bain Capital Ventures, pushes organizations to improve detection engineering. Because used correctly, AI can amplify detection quality. Just don’t fall into the trap of believing AI is a shortcut around detection quality. 

The Context Gap in AI-Driven Context Engineering

The context gap has two sides: organizational context and threat context. 

  • Organisational context tells the SOC what’s normal, important, unusual, or acceptable inside its own environment. That includes critical assets, privileged users, service accounts, standard workflows, expected access patterns, and known exceptions. 
  • Threat context tells the SOC what is relevant from an attacker’s perspective. That includes current adversary behavior, common attack paths, active exploits, and the difference between theoretical risk and likely attack activity. 

Most SOCs have this knowledge. The problem is that it lives in analysts’ heads, incident notes, ticket comments, Slack threads, and one-off tuning decisions. It rarely exists in a structured format that AI can use.

Without organizational context, AI struggles to separate abnormal behavior from unfamiliar but legitimate behavior. Without threat context, it struggles to separate weak signals from meaningful early indicators. The result is noise, missed threats, or low-confidence decisions at machine scale.

AI Raises the Bar for Detection Engineers

AI makes the work of detection engineers more vital than ever. Their role now is to translate human understanding into machine-usable signals. 

That means they need to ask harder questions:

  • Does this detection give AI enough context to reason from?
  • Does it explain what normal looks like?
  • Does it distinguish suspicious behavior from expected exceptions?
  • Does it reflect current threat activity?
  • Does it fire at the right moment in the attack timeline?
  • Does it support a better decision, or just a faster one?

These questions matter because AI amplifies whatever detection quality it receives. Strong detections become more valuable. Weak detections become more damaging.

AI Does Not Fix Bad Detection

AI-driven SOCs will expose where detection engineering depends on undocumented human knowledge, weak tuning decisions, and alerts that lack context. 

The best teams will treat detection engineering as context engineering: documenting normal behavior, linking detections to business risk and attacker activity, and measuring quality against latency.

AI can investigate everything. That is exactly why every detection needs to be worth investigating.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business & Technology

UK retail giant set to open new store in Oxfordshire

Published

on


The cards, gifts and celebration retailer has applied for planning permission to install signage at the old Claire’s Accessories store at Banbury Gateway.

Both of the Claire’s Accesories shops shut down last year in Banbury, with one at Castle Quay Shopping Centre and the other at Banbury Gateway Shopping Park.

Card Factory already has stores at Banbury Cross Retail Park and the one in the Castle Quay Shopping Centre.

READ MORE: Oxfordshire e-bike and e-scooter scheme to be significantly expanded

Shoppers enter a Card Factory store in Newcastle-under-Lyme, Staffordshire.Card Factory store in Newcastle-under-Lyme, Staffordshire. (Image: Barrington Coombs, PA Wire)

The gift retailer has shops also has shops in Headington, Cowley, Kidlington, Abingdon, Bicester, Witney, Didcot and Wantage.

The gift shop has over 200 shops across the UK, with the first Cardfactory store opening in Wakefield in 1997.

Last year Card Factory acquired personalised greetings card business Funky Pigeon from WH Smith for £24m.

Claire’s permanently closed in April after the major UK fashion brand collapsed into administration.

The high street chain was put into administration back in January 2026 alongside The Original Factory Shop (TOFS).

The two retailers had already undergone restructuring and were bought by investment firm Modella Capital last year.

Oxford Mail has asked the retailer if they have an opening date for the Banbury Gateway site and whether the opening will affect either of their other two Banbury stores.





Source link

Continue Reading

Business & Technology

EcoOnline & J.S. Held join forces on workplace safety

Published

on



SOFIAH NICHOLE SALIVIO

News Editor

EcoOnline has formed a global partnership with risk advisory firm J.S. Held, combining software tools with advisory services for workplace safety and crisis response.

The agreement focuses on three areas: environmental, health and safety management; crisis management; and lone worker protection. Both groups say employers face widening operational risks and fragmented oversight.

New survey data from EcoOnline points to a sizeable gap between worker concerns and employer preparedness. Nearly half of workers surveyed said they had experienced a workplace accident or illness, while 74% said more digital tools would make them feel safer at work.

The findings also suggest crisis planning remains poorly understood in many organisations. Only 31% of respondents said their employer had a crisis management plan they fully understood.

Lone worker safety emerged as another concern. EcoOnline said 32% of workers identify as lone workers, but only 56% believe their employer takes responsibility for their safety. One in three also said they had an accident while working alone in the past year.

Shared offer

Under the partnership, EcoOnline will provide software for incident reporting, safety management, crisis planning and lone worker monitoring, while J.S. Held will add field-based advisory services in risk assessment, preparedness and response.

The arrangement is intended to give organisations a more joined-up way to manage safety and operational disruption, linking digital reporting and oversight with support for implementation and field response.

The initial focus will be on the three areas outlined in the agreement, with scope expected to expand across EcoOnline’s broader software portfolio over time.

The tie-up reflects a wider trend in corporate risk management as companies try to connect compliance systems, workforce communication and emergency planning. Employers in sectors with dispersed staff, hazardous environments or isolated roles have faced growing scrutiny over how they monitor risk and respond to incidents.

EcoOnline’s survey also suggests worker expectations are shifting. Some 77% of respondents said an unsafe workplace could prompt them to change employer, placing safety alongside pay and flexibility as a retention factor.

Risk pressure

For crisis readiness, the partnership aims to improve access to plans and co-ordination during disruption. For lone worker protection, it focuses on oversight, communication and escalation when an employee is operating alone in a higher-risk setting.

Both companies argue that risk has expanded faster than the systems many employers use to manage it, leaving some organisations reliant on disconnected processes for workplace safety, emergency response and employee protection.

Kris McKenzie, chief revenue officer at EcoOnline, linked the partnership to the survey findings. “Workers are already aware of how broad operational risk has become. What they’re less confident in is whether their employer has the plans, processes, and visibility to deal with it,” said McKenzie. “J.S. Held’s hands-on advisory expertise amplifies the impact of our intelligent automation, giving organisations a clearer path to future-proof their readiness and protect their people.”

J.S. Held said the partnership fits its approach to advising businesses on connected operational risks, particularly where safety, resilience and supply chain issues overlap.

Andrea Korney, vice president of sustainability and supply chain at J.S. Held, said businesses were dealing with increasingly intertwined threats across day-to-day operations.

“We work with businesses facing more complex, connected risks across safety and operations,” said Korney. “Our role is to help them understand that complexity in context and act with confidence. EcoOnline’s comprehensive suite of out-of-the-box safety and sustainability software gives customers a practical foundation to implement faster, strengthen oversight, and build a more unified operational picture.”

The partnership gives EcoOnline a way to pair its software with consultancy support at a time when employers are under pressure to show that safety systems are understood in practice, not just documented in policy. For J.S. Held, it adds a software layer to advisory work for clients seeking more consistent visibility over incidents, staff exposure and emergency procedures.

Both companies present the alliance as a response to a workplace risk landscape that no longer sits neatly within separate departments. The data they cite suggests many workers already see that shift, with accident rates, lone working concerns and weak understanding of crisis plans pointing to the same problem: employers may have tools or procedures in place, but staff do not always trust that they are connected or effective.



Source link

Continue Reading

Business & Technology

International investors back Oxford-based AI work

Published

on


Japanese owned Aioi R&D Lab uses artificial intelligence and advanced data science to turn cutting‑edge academic research into real‑world commercial applications.

By combining Japanese expertise with British research excellence, the Lab is developing solutions to major global challenges and emerging risks, including those arising from AI data privacy, fraud, autonomous driving, ageing populations and supply chain disruptions.

Since 2020, Aioi has invested nearly £50M in Oxford-based AI and technology ventures.

Around 40 people are currently employed at its R&D Lab in Oxford, with its workforce expected to double by the end of the year, creating highly skilled roles in AI, data science and engineering.

Former chief scientific adviser Sir Patrick Vallance, during a media briefing in Downing Street on (Image: PA)

In April, the foreign secretary visited Japan to discuss opportunities to work on joint priorities, including economic growth.

Collaboration on fast‑growing technology sectors was also at the centre of conversations between prime minister Sir Keir Starmer and Japanese prime minister Sanae Takaichi this weekend.

During the visit, the leaders agreed a new UK-Japan Frontier Tech Partnership which will see British research translated into scalable technology with Japanese investment, from AI to robotics, quantum, space and defence tech.

The UK’s total bilateral trade with Japan is now worth £34.6 billion., with over 1,200 Japanese companies in the UK in 2022, providing over 150,000 UK jobs.

Minister for the Indo-Pacific, Seema Malhotra, said: “Aioi R&D Lab in Oxford is a powerful example of how the UK’s international partnerships support growth at home – attracting investment, creating high‑skilled jobs, and translating world‑class research into real‑world impact.

“By strengthening collaboration with Japan in priority sectors like AI and data science, this work supports our growth mission and reinforces the UK’s position as a partner of choice for global innovation.”

Originally launched as a partnership between Japanese insurer Aioi Nissay Dowa and Mind Foundry, an Oxford University spin-out, Aioi fully acquired the AI consulting business from Mind Foundry last year.

The Oxford Lab’s expansion has been backed by the UK Government, including support from the British Embassy in Tokyo, which has helped showcase its work to major Japanese corporates at a number of large-scale events.

Following introductions from the UK Government, Aioi has also invested in several other Oxford spinouts, including Natcap, a nature intelligence provider; OXA, a world-leading autonomous driving software developer; and Macrocosm, a complexity economics modelling company.

Junichi Ikagami, chief executive of Aioi R&D Lab, said: “One of the UK’s key strengths is its world-class AI and research capability.

“Combining this with our extensive client base across industries creates a powerful opportunity for innovation.

“Supported by the strong and stable relationship between the UK and Japan, we have successfully turned emerging technologies into real-world solutions, and we look forward to delivering even greater impact in the years ahead.”

UK science minister Lord Vallance said: “Aioi is demonstrating what is possible when you combine world-class British research with international expertise, and this expansion will bring a further boost to jobs and create opportunities for new spinouts in Oxfordshire.”





Source link

Continue Reading

Trending