Connect with us

Business & Technology

AI changes detection engineering – but only if you fix your context problem

Published

on


Artificial intelligence is powerful. That much is a given. AI doesn’t aid detection engineering, but it can expose its biggest weakness: a lack of organizational and threat context. 

Most detection engineering was built around human limits. Analysts could not investigate everything, so SOC teams tuned detections to reduce volume, suppress noise, and escalate only the alerts most likely to matter. 

However, in an AI-driven SOC, every alert can be investigated. And that makes detection quality even more important. If you feed AI weak detections, incomplete context, and poorly scoped logic, you just get bad decisions faster.

According to Prophet Security, an agentic AI SOC platform that investigates every alert rather than triaging a sampled few, detection engineering in an AI-driven SOC still depends on the same basic lifecycle: define hypotheses, write logic, test detections, tune performance, and retire what no longer works. What changes is what that lifecycle optimizes for. 

The old model optimized for fewer alerts, but the new model optimizes for richer, higher-quality signals. 

Why Detection Engineering Traditionally Focused on Analyst Capacity

Traditional detection engineering was developed to deal with limited analyst time. 

Traditional SOCs suffer from too many alerts, false positives, and suspicious-looking signals that had no operational impact. Detection teams tune aggressively because the alternative is an unmanageable queue. 

As a result, most SOCs aim to reduce alerts, investigations, and interruptions. While there’s nothing wrong with reducing noise, alert reduction shouldn’t be the main goal of detection engineering. 

Not every noisy detection is useless. Some alerts are noisy because the logic is bad. Others are noisy because the behavior is ambiguous and needs better context. Suppressing the second type just removes uncertainty from view.

When SOCs become AI-driven, however, the goal becomes making sure each alert contains enough context to support useful reasoning. 

How AI SOCs Shift Detection Engineering to Machine Investigation

AI compresses investigation time by collecting related events, summarizing activity, comparing behavior across systems, and generating an initial assessment far faster than a human analyst moving manually between tools. 

For SOC teams, that creates space to focus on judgment, escalation, and response – not gathering basic evidence. Detection engineers, specifically, can spend more time improving detection fidelity instead of firefighting alert noise. 

Those time savings matter. IBM’s 2025 Cost of a Data Breach Report found that the global average breach cost fell to $4.4 million, driven by faster identification and containment, and that security teams using AI and automation saw $1.9 million in cost savings compared with organizations that did not use those solutions.

The problem is that AI only has the knowledge the SOC give it access to. 

In the traditional model, an alert lacking sufficient context could still work if an experienced analyst knew how to interpret it. The alert might say that a user accessed an unusual resource, but the analyst knew the user, the application, the business process, and the likely exceptions. Much of the real context lived outside the detection itself.

That means an alert that made sense to a human analyst might be underpowered for AI. It may identify the event but not explain why it matters. It may lack asset criticality, identity context, expected behavior, known exceptions, recent changes, or relevant threat activity.

You can’t assume that AI can simply sit on top of existing detection logic and fix the SOC. It cannot reason well from incomplete inputs. 

This is why one of the leading AI SOC platforms, Prophet, backed by Accel and Bain Capital Ventures, pushes organizations to improve detection engineering. Because used correctly, AI can amplify detection quality. Just don’t fall into the trap of believing AI is a shortcut around detection quality. 

The Context Gap in AI-Driven Context Engineering

The context gap has two sides: organizational context and threat context. 

  • Organisational context tells the SOC what’s normal, important, unusual, or acceptable inside its own environment. That includes critical assets, privileged users, service accounts, standard workflows, expected access patterns, and known exceptions. 
  • Threat context tells the SOC what is relevant from an attacker’s perspective. That includes current adversary behavior, common attack paths, active exploits, and the difference between theoretical risk and likely attack activity. 

Most SOCs have this knowledge. The problem is that it lives in analysts’ heads, incident notes, ticket comments, Slack threads, and one-off tuning decisions. It rarely exists in a structured format that AI can use.

Without organizational context, AI struggles to separate abnormal behavior from unfamiliar but legitimate behavior. Without threat context, it struggles to separate weak signals from meaningful early indicators. The result is noise, missed threats, or low-confidence decisions at machine scale.

AI Raises the Bar for Detection Engineers

AI makes the work of detection engineers more vital than ever. Their role now is to translate human understanding into machine-usable signals. 

That means they need to ask harder questions:

  • Does this detection give AI enough context to reason from?
  • Does it explain what normal looks like?
  • Does it distinguish suspicious behavior from expected exceptions?
  • Does it reflect current threat activity?
  • Does it fire at the right moment in the attack timeline?
  • Does it support a better decision, or just a faster one?

These questions matter because AI amplifies whatever detection quality it receives. Strong detections become more valuable. Weak detections become more damaging.

AI Does Not Fix Bad Detection

AI-driven SOCs will expose where detection engineering depends on undocumented human knowledge, weak tuning decisions, and alerts that lack context. 

The best teams will treat detection engineering as context engineering: documenting normal behavior, linking detections to business risk and attacker activity, and measuring quality against latency.

AI can investigate everything. That is exactly why every detection needs to be worth investigating.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business & Technology

£7 billion East West Rail Oxford to Milton Keynes row reignites

Published

on


The dispute that halted the much-anticipated introduction of new trains to Milton Keynes looked to be coming to be coming to an end.

The Government has been pushing for ‘Driver-Controlled’ or ‘Driver-Only Operation’—a cost-saving method introduced widely on London commuter lines in the 1980s, a move widely condemned by trade unions.

The Department for Transport’s (DfT) plan for trains to be staffed by a driver and a customer service inspector seemed to solve the dispute.

But this did not meet the The National Union of Rail, Maritime and Transport Workers (RMT)’s demands.

The union has been opposing plans to use driver-only trains between Oxford and Milton Keynes Central.

Although the line between Bicester and Bletchley has technically been open since 2024, it has only been used by freight, charter, and test trains.

Chiltern Railways was chosen as the operator and has been advertising for customer service inspectors, instead of guards.

However, these inspectors would not be considered ‘safety-critical,’ meaning the driver would be responsible for opening and closing the doors.

Chiltern Railways stated it has made significant progress in preparing for the line to open to scheduled passenger trains, but no date has been announced.

READ MORE: Cruz Beckham pokes fun at brother Brooklyn amid bitter family fallout

East West Rail Action Group protesting outside Bletchley stationEast West Rail Action Group protesting outside Bletchley station (Image: Diana Blamires)

The company said it is continuing to work closely with the The Department for Transport, trade unions, and industry partners.

The National Union of Rail, Maritime and Transport Workers general secretary Eddie Dempsey insisted on the necessity of a guaranteed safety-critical second person aboard trains, citing their essential role in handling a wide range of duties and responding appropriately to ‘dangerous and fast-moving’ situations.

He said: “We need a clear commitment from Chiltern that East West Rail services will not be Driver Only Operation and that a second safety-critical member of staff will be guaranteed.”

Chiltern Railways is set to be renationalised on September 20, when it will be taken over by DfT Operator in preparation for Great British Railways.

45 drivers have been recruited for the new service, but no guards.

The project delays have already taken a significant financial toll.

Six two-carriage trains have accumulated £2.6m in costs due to delays in their lease.

Currently idle in a Bletchley depot, these units are costing the Department for Transport money without generating any fare income.

The Government previously said trains from Oxford to Milton Keynes are being lined up to appear in the December rail timetable.

In a written statement, rail minister Lord Peter Hendy said: “Chiltern worked with Network Rail, the Department for Transport and other operators on the December 2026 timetable and services have been timetabled between Oxford, Winslow, Bletchley and Milton Keynes.”





Source link

Continue Reading

Business & Technology

Tech firms back Boycott Your Bed sleepout across UK

Published

on



SOFIAH NICHOLE SALIVIO

News Editor

More than 100 technology companies have signed up for Boycott Your Bed 2026, a charity sleepout expected to bring together more than 500 participants across four UK cities.

Participants from companies including Accenture, PwC, Hewlett Packard Enterprise, Siemens and Barclays are due to spend a night outdoors as part of the annual fundraiser for Action for Children. The event will take place in London, Glasgow, Manchester and Leeds.

Now in its 29th year, Boycott Your Bed has become a longstanding fixture in parts of the UK technology sector. Organisers say it has raised GBP £14.6 million for Action for Children since launching in 1998.

The sleepout aims to raise both money and awareness for vulnerable children, young people and families across the UK. Action for Children operates 342 services in communities, schools and online, and says it helped more than half a million children, young people and families in the last year.

Recent government figures cited by organisers show that more than four million children in the UK are growing up in poverty. Against that backdrop, the event asks participants to spend one night outside as a reminder of the insecurity some families face.

Although the fundraiser is open to individuals and teams from any industry, it has attracted strong backing from the technology community for nearly three decades. This year’s participating businesses also include Capgemini, Red Hat, Burberry, Specsavers, Irwin Mitchell, Kier Group and Sparta Global.

Organisers present the event as both a fundraising effort and a meeting point for people across the sector. Its mix of senior leaders, partners, customers and technology professionals has helped give the sleepout a profile beyond that of a conventional charity initiative.

Sector gathering

The level of corporate involvement suggests companies still see value in cause-led events that also create space for professional networking. In a market where firms face pressure to show social impact while maintaining industry ties, Boycott Your Bed has carved out a role that does both.

That dual purpose appears to be part of the event’s staying power. With registrations still open for a limited period, organisers expect further sign-ups before the sleepout takes place.

For Action for Children, the event provides a significant fundraising channel linked to a business audience with long-standing ties to the charity. For participating companies, it offers a visible way to support a national children’s charity while bringing staff and contacts together in an informal setting.

The format is simple: individuals and teams commit to one night outdoors in organised sleepouts staged simultaneously across the four cities, with fundraising tied to participation.

Long record

Boycott Your Bed began as a campaign to raise awareness and funds and has grown into one of the larger recurring charity gatherings associated with the UK technology industry. Organisers say more than 100 companies have already registered for this year’s edition.

The range of names on the participant list points to support from consulting firms, financial services groups, industrial businesses and software companies. That gives the event a broader corporate base than a niche sector fundraiser, even though its roots remain closely tied to the technology industry.

Ken Deeks, vice president and founder of Boycott Your Bed, commented on the scale of support and the purpose behind the event. “Understanding the reality of these challenges has been both eye-opening and deeply moving. Boycott Your Bed raises awareness of issues that can often remain hidden from view. The response from the technology community continues to be incredible, with more than 100 companies already signed up and many more expected to join before October. We anticipate more than 500 sleepers on the night, creating a fantastic opportunity for people from across the sector to come together. Importantly, sleepers will play a direct role in supporting Action for Children’s work with vulnerable children, young people and families across the UK,” Deeks said.



Source link

Continue Reading

Business & Technology

Morrisons to clean up overgrown land at Bicester store

Published

on


The UK supermarket chain is working to clean up land at its Bicester store in Villiers Road, after residents raised concerns about overgrown vegetation and litter.

The issues were highlighted by local resident Jamie Jessett, who said parts of the property appeared neglected and in need of maintenance.

Concerns focused on the permeable paving area at the front of the store, where weeds have reportedly spread across much of the surface.

Morrisons Daily to clear overgrown vegetation and litter at a ‘below acceptable standards’ Oxfordshire site (Image: Jamie Jessett)

He also raised issues about the rear yard and garage area, including overgrown brambles and weeds, as well as accumulations of litter and debris.

He said: “There is a duty to keep land clear of litter and reasonably tidy and the current condition falls well below acceptable standards, affecting public safety.”

Further concerns were expressed about discarded needles, suspected drug use and anti-social behaviour in the rear area, which borders a public play area used by children and families.

“I am very concerned”, he added, “Families and their young children are leaving or entering the play area behind the shop, which is about 20 footsteps into the tree area where I found a needle in 2023. The safety of the public needs to be taken more seriously.”

The freehold of the Morrisons Daily premises is held by Alliance Property Holdings Limited, a subsidiary of Morrisons.

Responding to concerns about the site, a Morrisons spokesperson said action was already underway.

They said: “We are already working with our maintenance team to clean up the land owned by Morrisons.

“Please note that the area behind the shops is private property and strictly off-limits to the public.”





Source link

Continue Reading

Trending