Cover art for the blog "AI To Handle 60% of SOC Work By 2028. It Had Better Be Robust." by D3 Security

AI To Handle 60% of SOC Work By 2028. It Had Better Be Robust.

If you’re trying to separate real AI-SOC capability from hype, you’ll love this: we’re making the 2025 AI SOC Market Landscape report available as a download. Produced by Software Analyst Cyber Research (SACR), it’s the most comprehensive snapshot of this emerging category. The report features 13 vendors, architectural guidance, risk frameworks, implementation roadmaps, and a capabilities matrix that places D3 Morpheus in the top-right “Robust Solutions” quadrant.

How SACR Plots the Market: All 13 Vendors by Robustness

SACR’s positioning is driven by two axes. The Y-axis represents Overall Product Maturity (operational readiness, trust, QA, real-world deployments). The X-axis represents Capability Depth (breadth and sophistication across triage, orchestration, integrations, deployment options, explainability, and more). Vendors are also scored quantitatively against criteria like investigation speed and performance under load. The framing matters because it rewards repeatable outcomes, scale, and control, the qualities buyers feel in production.

The AI SOC Vendor Critical Capabilities Matrix by Software Analyst Cyber Research
13 AI SOC vendors mapped to SACR’s Critical Capabilities Matrix, Maturity by Capability Depth, Morpheus first.
Vendor SACR Quadrant Capability Read
D3 Morpheus Robust Solutions Mature, full-stack: orchestration, agentic investigation, on-prem and air-gapped deployment, multi-tenant for MSSPs.
Torq Robust Solutions Cited by SACR as the “most feature-rich” platform in the cohort.
Intezer Robust Solutions Mature across triage, investigation, and orchestration depth.
Radiant Robust Solutions Cited by SACR as the “most unique value proposition” in the cohort.
Prophet AI Specialist Solutions Mature within a focused scope, less breadth across the SOC stack.
Dropzone AI Specialist Solutions Mature within a focused scope, less breadth across the SOC stack.
Qevlar AI Specialist Solutions Mature within a focused scope, less breadth across the SOC stack.
Sekoia Performers Capable in specific domains, with maturity and capability depth still developing relative to the Robust quadrant.
Exaforce Performers Capable in specific domains, with maturity and capability depth still developing relative to the Robust quadrant.
CMD Zero Performers Capable in specific domains, with maturity and capability depth still developing relative to the Robust quadrant.
Crogl Performers Capable in specific domains, with maturity and capability depth still developing relative to the Robust quadrant.
Legion Unique Rising Stars Distinct value proposition with earlier maturity, a promising approach worth tracking.
Mate Unique Rising Stars Distinct value proposition with earlier maturity, a promising approach worth tracking.

Why D3 Sits in the Robust Quadrant

Morpheus triages up to 95% of incoming alerts in under two minutes at L2-plus depth. The investigation engine, Attack Path Discovery, traces East-West across the stack and North-South through 90 days of telemetry to assemble a chronological view of each incident. The platform is architected for Fortune 100-scale throughput. Over 800 bidirectional integrations connect SIEM, EDR, cloud, identity, and ticketing tools, and a multi-tenant architecture lets MSSPs investigate more clients without adding staff.

D3’s decade as a SOAR vendor shows in the operational layer. Playbooks publish to GitHub for version control, peer review, and CI/CD promotion. Automated validation catches regressions before a playbook touches production. Full-lifecycle case management runs from evidence intake through closure, audit-ready by design. Reporting converts every investigation into MTTI, MTTR, escalation rates, and coverage metrics. Deployment options include fully isolated on-premises and air-gapped environments for government and regulated buyers. Analysts see step-by-step reasoning and can adjust the underlying investigation logic, with hallucination checks and an auditable decision path. Alerts from across the stack normalize into a single data model that powers reliable cross-tool automation, and analysts query the platform in plain English instead of KQL.

A preview of the The AI SOC Market Landscape 2025 report by Software Analyst Cyber Research

Why This Report Matters (and Why We’re Sharing It)

SACR’s research captures the reality practitioners live daily:

  • Teams face ~960 alerts/day on average; large enterprises exceed 3K/day across ~28 tools.
  • 40% of alerts are never investigated; 61% of teams admit ignoring alerts that later proved critical.
  • Mean time to investigate is ~70 minutes, while phishing-led breaches can succeed in <1 hour.
  • CISOs expect AI to handle ~60% of SOC tasks by 2028.

The report helps you evaluate which vendors can change those numbers by comparing 13 AI SOC platforms across functional domains (automation/orchestration (SOAR+) and agentic SOC, pure-play agentic alert triage, analyst co-pilot/investigation, and workflow/knowledge replication) and architectural approaches (overlay, integrated, and workflow emulation). The need to spell out and categorize these approaches reveals the industry’s lack of shared terminology for AI in the SOC. The report also surfaces risks and considerations (benchmarks, accountability, and data governance) when it comes to AI adoption.

The report’s author Francis Odum joined Amy Tom in a podcast earlier this year where he gave an overview of the history of automation in cybersecurity, from security orchestration, automation, and response (SOAR) tools to low-code/no-code solutions, highlighting how previous promises of automation fell short. The discussion explores terms used to describe the new wave of security automation tools, from the AI SOC, to autonomous SOC, to the AI-augmented SOC. It also discusses the potential implications of AI in the SOC and how analyst roles might change. Odum says he doesn’t believe a fully autonomous SOC is feasible. “I still think we need humans in the loop,” he says.

Get the Report

We’re offering The AI SOC Market Landscape 2025 report as a download so you can benchmark strategies, ask the right questions, and see why D3 Morpheus is recognized as one of the category’s most robust AI SOC solutions. Grab your copy, share it with your team, and use it as a checklist for your next proof-of-concept.

If you’d like a guided walkthrough of how GitHub-published, autonomously tested playbooks plus reporting, dashboarding, and case management come together, we’re happy to tailor a demo to your stack.

Learn More About Morpheus

Powering the World’s Best SecOps Teams

Ready to see Morpheus?