Revolutionizing the SOC for the Future Threat Landscape
RSA Conference 2024 · West Stage Keynote
Overview
In this insightful talk from RSAC 2024, Gary Steele, Executive Vice President and General Manager at Splunk (recently having joined forces with Cisco), presented a compelling vision for the future of the Security Operations Center (SOC). Steele argued that current SOC models are often "frozen in time" and ill-equipped to handle the escalating complexity and scale of modern cyber threats. His presentation outlined a revolutionary approach centered on a distributed architecture, AI-driven automation, and a unified platform, aiming to empower security practitioners to regain the advantage against increasingly sophisticated adversaries.

Key moments
- 0:00 Rethinking the SOC and current threat landscape
- 2:00 Visibility is crucial: Security as a data problem
- 3:30 The fragmented security environment and tool chaos
- 4:40 Paradigm shift: Moving analytics to the data
- 5:15 Three fundamental pillars of the future SOC
- 5:40 Pillar 1: Single integrated platform & SIM/XDR convergence
- 6:10 Pillar 2: AI-driven automation elevating the analyst
Revolutionizing the SOC for the Future Threat Landscape
Speakers: Gary Steele, Executive Vice President and General Manager, Splunk
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=fO3YKkEwZhQ
Overview
In this insightful talk from RSAC 2024, Gary Steele, Executive Vice President and General Manager at Splunk (recently having joined forces with Cisco), presented a compelling vision for the future of the Security Operations Center (SOC). Steele argued that current SOC models are often "frozen in time" and ill-equipped to handle the escalating complexity and scale of modern cyber threats. His presentation outlined a revolutionary approach centered on a distributed architecture, AI-driven automation, and a unified platform, aiming to empower security practitioners to regain the advantage against increasingly sophisticated adversaries.
The talk underscores the critical need for change, highlighting that despite ongoing efforts, threat actors continue to hold the upper hand. Steele posits that true progress hinges on enhanced visibility and a fundamental shift in how security operations are structured and executed. This reimagined SOC is not merely an incremental improvement but a paradigm shift designed to address the challenges of fragmented data, tool sprawl, and the growing attack surface, ultimately striving for a state of digital resilience across the entire enterprise.
This article will delve into Steele's proposed framework, exploring the foundational problems plaguing contemporary SOCs, the three core pillars of his revolutionary vision, and the practical implications for security professionals seeking to build more effective, sustainable, and future-proof defenses.
Background
▶ Watch: Rethinking the SOC and current threat landscape (0:00)
The contemporary threat landscape is characterized by an unprecedented level of complexity and risk, making the traditional SOC model increasingly unsustainable. Gary Steele opened by acknowledging the unfortunate reality that "threat actors continue to have the advantage." This disadvantage stems from several intertwined factors: a continuously expanding attack surface driven by digital transformation, a volatile geopolitical environment influencing cyber warfare, a broad spectrum of threats ranging from insider threats to sophisticated external campaigns, and a convoluted regulatory environment with diverse privacy rules globally. A recent study cited by Steele revealed that roughly three-quarters of respondents anticipate experiencing a cyber incident within the next two years, starkly illustrating a pervasive lack of confidence in current security postures.
At its core, security is fundamentally a data problem. Modern organizations grapple with an immense and ever-growing volume of data originating from disparate sources: network traffic (including massive netflow files), endpoint logs, cloud environments, and increasingly, Operational Technology (OT) devices. The sheer scale of this data often becomes insurmountable for analysts. Compounding this challenge is the highly fragmented nature of enterprise environments. Organizations typically operate across multiple clouds (whether by design or acquisition), alongside critical on-premise footprints. Furthermore, data privacy regulations often dictate that data must remain within specific geographies, creating data gravity issues that prevent easy centralization.
The security industry, while innovating, has also contributed to fragmentation through a proliferation of specialized point solutions. Steele noted that SOC analysts, on average, utilize up to 25 different tools to perform their duties, leading to significant context switching, inefficiencies, and blind spots. Adding another layer of complexity, IT organizations also require access to much of this same data for application uptime and system management, often resulting in silos and a lack of unified visibility across security, IT, and DevOps teams. This historical model of centralizing all data into a single log aggregation system for analysis is, according to Steele, "fundamentally gone." The necessity to move analytics to the data, rather than the costly and cumbersome reverse, is the foundational shift required.
Key Findings
▶ Watch: The fragmented security environment and tool chaos (3:30)
Gary Steele's presentation outlined a revolutionary blueprint for the future SOC, built upon the premise that current centralized models are obsolete. The core finding is that the future of security operations must be highly distributed, capable of handling all data at machine speed and scale, wherever that data resides. This fundamental shift, moving analytics to the data rather than moving data to the analytics, unlocks unprecedented potential for faster detection and more effective outcomes.
This distributed vision is underpinned by three fundamental pillars:
- A Single Platform for Threat Detection, Investigation, and Response (TDIR): Instead of a fragmented array of point solutions, the future SOC requires an integrated environment that delivers context, insights, and AI-driven actions. Steele highlighted a crucial convergence of SIEM and XDR functionalities, combining the rich analytics capabilities traditionally found in Security Information and Event Management (SIEM) with the advanced detection and response capabilities of Extended Detection and Response (XDR). This unified platform aims to reduce tool sprawl and streamline analyst workflows.
- Automation Delivered Through AI: The talk emphasized that Artificial Intelligence (AI) will be integral to elevating the role of the human analyst, not replacing it. AI's primary function is to eliminate noise and automate repetitive tasks, allowing analysts to focus on higher-value activities requiring human ingenuity and critical decision-making. Steele explicitly rejected the notion of an "autonomous SOC," asserting that "there's always an expert in the driver's seat," but one profoundly aided by AI.
- Federation for Data Access: This pillar is central to the distributed model. It dictates that the ideal SOC must have the ability to access and analyze data across the broad enterprise, irrespective of its physical location – whether in multiple clouds, on-premise systems, or at the edge. Federated analytics allows for pre-processing and immediate insights directly where the data lives, eliminating the need to move massive datasets and providing a foundation for enhanced visibility and defense capabilities. This also introduces significant economic advantages by enabling data storage in low-cost locations.
Ultimately, these findings converge on a broader concept: digital resilience. This means protecting the business from all forms of threats and outages, ensuring system uptime, and enabling rapid recovery from any incident. Steele argued that security, IT operations, and DevOps teams increasingly rely on the same data to diagnose issues, making a unified platform for digital resilience a logical and essential evolution.
Technical Deep Dive
▶ Watch: Paradigm shift: Moving analytics to the data (4:40)
The technical foundation of Steele's proposed SOC revolution lies in a complete re-architecture of how security data is managed, analyzed, and acted upon. The central dogma is "move analytics to the data versus moving data to the analytics." This paradigm shift directly addresses the challenges of data volume, data gravity, and regulatory constraints that make centralized data aggregation increasingly impractical and expensive.
The first pillar, a single integrated environment, represents a significant departure from the siloed toolsets prevalent today. This platform aims for a convergence of SIEM and XDR. Historically, SIEM systems excelled at ingesting and correlating logs from diverse sources for compliance and threat hunting, while XDR focused on deep telemetry from specific domains (endpoints, networks, cloud) for advanced detection and response. The unified platform envisioned by Steele would combine the strengths of both, providing rich analytics and correlation capabilities across a broader spectrum of data, alongside robust, automated detection and response actions. This environment would be open and extensible, allowing for integration with existing tools where necessary, but fundamentally reducing the "plethora of tools" to a more manageable, tightly integrated set. The goal is to establish the platform as "the center of the SOC," where insights are rapidly generated, and actions can be taken swiftly.
The second pillar, automation delivered through AI, is not about replacing human analysts but augmenting their capabilities dramatically. Steele outlined several critical areas where AI would be embedded directly into workflows to streamline traditional SOC tasks:
- Alert triage: Automatically prioritizing and filtering high-volume, low-fidelity alerts.
- Case management: Assisting with the organization and progression of security incidents.
- Incident response: Providing recommendations and automating initial response actions.
- Incident summaries: Generating concise, accurate summaries of complex incidents.
- Vulnerability management: Aiding in the identification, prioritization, and remediation of vulnerabilities.
- Coordination of workflows: Orchestrating actions across different security tools and teams.
- Correlations and anomalies: Leveraging machine learning to identify subtle patterns and deviations indicative of threats.
- Root cause analysis: Expediting the determination of underlying causes for security events.
- Action recommendations: Suggesting the next best steps for analysts during investigations.
Crucially, this AI would be context and domain-specific, meaning it would be trained over time to understand the unique operational environment and threat landscape of a particular organization. An open and extensible AI environment would also ensure that organizations can continuously leverage state-of-the-art AI tools as they evolve, keeping their defenses current. The emphasis remains on a "human in the loop" model, where AI provides powerful assistance, but critical decisions and final actions are guided by expert analysts.
The third and arguably most transformative pillar is federation. This refers to the ability to perform analytics and drive detections on data wherever it lives, without the necessity of physically moving it to a central repository. In environments with multiple cloud providers, on-premise infrastructure, and edge devices, this capability is paramount. Pre-processing data at the edge—where it originates—allows for immediate insights, detections, or alerts to be generated without the latency and cost associated with transferring massive datasets. For instance, analyzing netflow files directly at the network edge can identify lateral movement or unusual traffic patterns much faster than if those enormous files had to be shipped to a central SIEM. This concept of analytics to the edge is facilitated by modern technology that allows distributed computational power to be applied close to the data source. Beyond technical efficiency, federation offers significant economic benefits. Organizations can store data in low-cost storage locations and make independent decisions about data retention, reducing the overall cost burden of security operations while still achieving comprehensive visibility.
Demo / Proof of Concept
▶ Watch: Pillar 1: Single integrated platform & SIM/XDR convergence (5:40)
The provided transcript for this talk does not include a description of a live demonstration or a proof of concept. The speaker, Gary Steele, focused on articulating the vision and strategic framework for revolutionizing the SOC rather than showcasing specific product capabilities or technical implementations.
Defensive Implications
▶ Watch: Pillar 2: AI-driven automation elevating the analyst (6:10)
The revolution outlined by Gary Steele carries significant implications for how organizations approach their defensive strategies, demanding a fundamental shift in mindset and architecture.
Firstly, defenders must abandon the outdated notion of a fully centralized security data lake. The new imperative is to embrace a federated and distributed data architecture. This means designing systems that can perform analytics at the edge, processing data where it resides (e.g., in specific cloud regions, on-premise data centers, or OT environments) to generate immediate insights and detections. This approach not only enhances detection speed but also addresses data gravity, regulatory compliance, and cost challenges associated with moving vast quantities of data.
Secondly, the talk strongly advocates for a move away from disparate point solutions towards single, integrated platforms. Security teams should prioritize solutions that converge SIEM and XDR capabilities, providing a holistic view across the entire digital footprint. This consolidation reduces tool sprawl, improves context for analysts, and streamlines workflows, enabling faster Threat Detection, Investigation, and and Response (TDIR). When evaluating new technologies, the emphasis should be on openness and extensibility to ensure interoperability and future adaptability.
Thirdly, organizations must strategically integrate AI into their SOC operations to augment human capabilities. This involves leveraging AI for tasks such as alert triage, case management, incident summaries, and vulnerability management, freeing up analysts for more complex, cognitive tasks requiring human judgment. However, it is crucial to maintain a "human in the loop" model, ensuring that AI acts as a powerful assistant rather than an autonomous decision-maker, especially for critical actions like network reconfiguration or user disruption. Defenders should invest in AI solutions that are context and domain-specific to their unique environment, allowing the AI to learn and adapt over time.
Finally, the broader vision of digital resilience requires defenders to break down traditional silos between security, IT operations, and DevOps. Recognizing that the data needed to diagnose both cyber incidents and operational outages is often the same, fostering cross-functional collaboration and working towards a unified platform for visibility and response becomes paramount. This holistic approach ensures that the business can not only withstand cyber threats but also recover rapidly from any form of disruption, ultimately protecting core business functions and enhancing customer experience. The statistics cited in the talk — nearly three-quarters of respondents reporting closer collaboration between security and IT operations, up from roughly half last year — indicate that this integration is already gaining traction and should be actively pursued.
Key Takeaways
- The traditional, centralized SOC model is outdated and struggles against the escalating complexity, fragmentation, and scale of modern cyber threats, leading to a persistent advantage for threat actors.
- The future of the SOC is distributed, fundamentally shifting from moving data to analytics to moving analytics to the data, wherever it resides across clouds, on-premise, and edge environments.
- A revolutionary SOC is built on three core pillars: a single, integrated platform for TDIR (converging SIEM and XDR), AI-driven automation that augments human analysts, and federated data access for comprehensive visibility.
- AI is critical for enhancing analyst productivity by automating tasks like alert triage, incident summaries, and workflow coordination, but always maintains a "human in the loop" for critical decision-making, rejecting the notion of a fully "autonomous SOC."
- Federated analytics allows for efficient data processing at the source, reducing data movement costs, addressing data gravity, and enabling faster detection across diverse and geographically distributed data sets.
- The ultimate goal is digital resilience, fostering seamless collaboration and unified visibility across security, IT operations, and DevOps to protect the business from all forms of outages and ensure rapid recovery.
About the Speaker(s)
Gary Steele is the Executive Vice President and General Manager at Splunk, a leading data platform for security and observability. His extensive career in cybersecurity leadership spans over two decades, including a significant tenure as the CEO of Proofpoint for more than 20 years prior to joining Splunk. Steele's deep experience in tackling complex cybersecurity problems informs his vision for transforming security operations. His current role at Splunk has recently seen the company join forces with Cisco, an integration he expressed great excitement about, highlighting the potential for their combined capabilities to deliver substantial benefits to security practitioners.