惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hacker News - Newest:
Hacker News - Newest: "LLM"
Google DeepMind News
Google DeepMind News
N
News and Events Feed by Topic
N
News and Events Feed by Topic
T
Troy Hunt's Blog
PCI Perspectives
PCI Perspectives
W
WeLiveSecurity
N
News | PayPal Newsroom
Recent Commits to openclaw:main
Recent Commits to openclaw:main
V2EX - 技术
V2EX - 技术
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Threat Research - Cisco Blogs
L
LINUX DO - 热门话题
Cloudbric
Cloudbric
S
Secure Thoughts
Microsoft Azure Blog
Microsoft Azure Blog
H
Help Net Security
Y
Y Combinator Blog
L
LangChain Blog
Recorded Future
Recorded Future
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
博客园 - 聂微东
Attack and Defense Labs
Attack and Defense Labs
Blog — PlanetScale
Blog — PlanetScale
WordPress大学
WordPress大学
Microsoft Security Blog
Microsoft Security Blog
P
Proofpoint News Feed
小众软件
小众软件
H
Hacker News: Front Page
The Hacker News
The Hacker News
T
Tailwind CSS Blog
The Register - Security
The Register - Security
Hacker News: Ask HN
Hacker News: Ask HN
P
Privacy & Cybersecurity Law Blog
P
Palo Alto Networks Blog
S
Securelist
腾讯CDC
雷峰网
雷峰网
G
Google Developers Blog
The Cloudflare Blog
Google DeepMind News
Google DeepMind News
P
Privacy International News Feed
H
Hackread – Cybersecurity News, Data Breaches, AI and More
A
Arctic Wolf
www.infosecurity-magazine.com
www.infosecurity-magazine.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
阮一峰的网络日志
阮一峰的网络日志
AI
AI

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget Beyond the perimeter: The shift to data-centric protection | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization Researchers build autonomous AI worm that can reason and adapt How to secure data at rest, in use and in motion How to find cyber-risk data sources for a FAIR analysis Lost in translation: Cybersecurity board reporting for CISOs How to prepare security controls for future AI regulations EO 14390 raises stakes for enterprise cybersecurity First month of Mythos Preview testing exposes 10K flaws OT attacks shift from recon to physical control, raising stakes For CISOs, dawn of OpenAI Daybreak brings good and bad news Gartner Security & Risk Management Summit 2026: Adapting for AI | TechTarget Inside business email compromise attacks: Real-world examples Verizon 2026 DBIR: 6 key takeaways for CISOs Identity security for AI agents: The proliferation challenge How to build a business impact analysis checklist Taking care of business: The CISO's role in a cyber crisis What CISOs need to know about AI audit logs SOC vs. MDR: What CISOs need to consider Instructure cyberattack reignites ransom payment debate Transform SIEM rules with behavior-based threat detection CISO's guide: How to test an incident response plan How to implement zero trust for AI Data after the breach: Economics of the dark web The breakup: Why CISOs are decoupling data from their SIEMs | TechTarget News brief: Security worries and warnings as AI use expands How to construct an effective security controls evaluation 5 leading enterprise password managers to consider Claude Mythos changes the AI security threat matrix Buyer 6 things to check in your cyber insurance policy fine print How cyber insurance helped with breach recovery -- or not News brief: Critical infrastructure, OT cybersecurity attacks Tape's strategic role in modern data protection Top zero-trust use cases in the enterprise What every CISO should consider before a SIEM migration CISO's guide to centralized vs. federated security models Shadow code: The hidden threat for enterprise IT How to fix cybersecurity's agentic AI identity crisis 5 top SIEM use cases in the enterprise Top 8 e-signature software providers for 2026 How do digital signatures work? News brief: AI woes continue for security leaders Deepfake era demands proof-based security, not just awareness Is SOAR dead or alive? Sort of The push for digital sovereignty: What CISOs need to know Beyond awareness: Human risk management metrics for CISOs Cybersecurity in the age of AI means bigger, faster threats At RSAC 2026, AI optimism and anxiety -- and an MIA U.S. government Inside the SOC that secured RSAC 2026 Conference How to roll out an enterprise passkey deployment How contact centers detect and prevent fraud News brief: Iranian cyberattacks target U.S. water, energy CISO checklist: Cybersecurity platform or marketing ploy? RSAC 2026 Conference: Key news and industry analysis | TechTarget Next-generation firewall buyer's guide for CISOs Contact center monitoring best practices for CX leaders RSAC 2026: Cyber insurance and the rise of ransomware Agentic AI's role in amplifying and creating insider risks RSAC 2026 recap: AI security and network security trends Identity security at RSAC 2026: The new enterprise dynamics Meaningful metrics demonstrate the value of cyber-resiliency What to know about red team testing and the law News brief: Iran cyberattacks escalate, U.S. targets named 5 top SOC-as-a-service providers and how to evaluate them Cloud security architecture: Enterprise cloud blueprint for CISOs Contact center compliance checklist for modern workforces How AI caught a malicious North Korean insider at Exabeam Watch your words: Tim Brown's advice for CISOs News brief: U.S. absence at RSAC sparks leadership concerns Network security management challenges and best practices 10 enterprise secure remote access best practices
How to improve the SOC analyst experience -- and why it matters
2026-04-15 · via Search Security Resources and Information from TechTarget

Sean Michael Kerner

By

Published: 14 Apr 2026

Security Operations Center analysts stand on the front lines between their organizations and countless cyberthreats. How effectively an analyst reacts to any given security alert could mean the difference between a contained, minor incident and a full-on data breach.

Too often, however, SOC analysts suffer from poor workflows, outdated tools and overwhelming workloads. The resulting burnout fuels high turnover -- something organizations can't afford, given the cybersecurity talent shortage. Worse, these conditions create environments where security incidents go undetected or take longer to contain. For CISOs, improving analysts' working conditions is a security imperative that directly impacts organizational risk.

Why analyst experience matters in the SOC -- and beyond

Forrester first coined the term "analyst experience," or AX, with analysts Allie Mellen and Jeff Pollard defining it as, "Security analysts' perception of their interactions with a particular security product, service and process across various workstreams."

Organizations, Mellen and Pollard noted, rely on analysts to recognize, classify, investigate and respond to cyberthreats that pose enormous risk to their organizations. Tools in the SOC, however, often fail to reflect the importance of their work. Siloed data, clunky integrations and poorly functioning user interfaces, they argued, make it unnecessarily challenging and unpleasant for analysts to do their jobs.

"Security teams are regularly forced into a reactive state by too many alerts, too little time and a fragmented security stack, leading to increased employee stress and burnout," agreed Nicole Carignan, field CISO and senior vice president of security and AI strategy at Darktrace, a multinational cybersecurity firm based in Cambridge, England.

Consequences of neglecting the security analyst experience in the SOC include the following, according to experts and practitioners.

Talent attrition

Most, if not all, CISOs have grappled with understaffing in the SOC -- a chronic problem that poor analyst experience makes worse. "Many organizations struggle to provide a good AX, which leads analysts to burn out or look for a role elsewhere," Mellen said.

When unhappy analysts do inevitably quit, remaining team members inherit heavier workloads, further fueling problems and creating a vicious cycle.

Compounding coverage gaps

The effects of talent attrition compound over time. When an organization loses a trained analyst, it also loses months of domain understanding and muscle memory, said Heath Renfrow, co-founder and CISO at cyber disaster recovery firm Fenix24, based in Chattanooga, Tenn.

"That churn creates gaps in coverage, slower response times and greater risk during critical incidents," Renfrow added. "At scale, it becomes a vicious cycle: overworked teams make more mistakes, which increases pressure, which drives more attrition."

For many, the emotional and mental toll quickly becomes untenable, according to Tom Levi, field CISO and director of cyber-risk strategy at CYE, a cybersecurity company based in Herzliya, Israel. "When there are staffing shortages in addition to the fear of getting something wrong, it becomes emotionally exhausting work that cannot be sustained long-term," he said.

Incident outcomes

Poor analyst experience can lead to worse outcomes during security incidents, according to Mellen. "Analysts who don't have the information they need for investigation are not able to respond as quickly and effectively," she said. "They also may spend excessive amounts of time chasing false positives, which prevents them from investigating true incidents."

Operational impact

Poor analyst experience creates operational drag. When analysts must contend with cumbersome tooling, alert noise and handoff friction to do their jobs, investigations slow, and case quality becomes more difficult to standardize. This hurts staff morale and reduces time for proactive work, such as threat hunting.

"Many SOC analysts spend their days triaging endless low-fidelity alerts, fighting noisy tooling and working in reactive mode," Renfrow said. "That grind creates a sense of futility. Analysts feel like they're clicking buttons instead of defending organizations."

What makes a good SOC analyst experience

Poor analyst experience is marked by chaos, tedium, frustration and a sense of futility. In contrast, good analyst experience has the following defining characteristics:

  • Purpose. Analysts understand why they're investigating alerts, not just what they're investigating, and why the outcomes of SOC investigations matter to the organization.
  • Context. Rather than drowning in false positives and noise, analysts work with high-quality alerts that provide the context they need to take action.
  • Consolidated tools. Instead of a plethora of disconnected systems, tools are consolidated so analysts don't need to constantly switch among systems to investigate security events.
  • Respect. Analysts feel their organizations, managers and colleagues respect them as professionals and value their input.
  • Career paths. Analysts see clear opportunities for professional growth, with career paths beyond endless alert triage.

"What has worked for us is treating analyst experience as an operational priority, not a perk," said Craig Jones, chief security officer at managed detection and response (MDR) provider Ontinue, which has headquarters in Zurich and Redwood City, Calif. "We focus heavily on detection hygiene, tuning noisy rules, rapidly fixing false positives and raising the quality bar so alerts arrive with the context needed to act."

According to Renfrow, Fenix24 achieved similarly positive results through a three-pronged approach: reducing alert noise so analysts can focus on substantive, high-value problems; giving analysts meaningful ownership of cases, so they see how their work restores the ability of the company's customers to do business; and defining clear career paths that encourage skill development beyond basic triage.

How CISOs can improve the SOC analyst experience

To improve the security analyst experience in the SOC, CISOs should consider the following steps:

  • Include analysts in technology purchases. "CISOs must bring security analysts into the buying decision process and trust their judgment on what will be most effective for the team," Mellen said. "In many cases, there are nuances to how the technology works in practice that practitioners see when they use the software day in and day out, but others might not. Trust your practitioners and compromise where possible."
  • Invest in alert engineering. Prioritize regularly tuning noisy rules and fixing false positives so that meaningful alerts reach analysts, and low-signal noise that leads to alert fatigue doesn't. If budgets permit, consider upgrading SOC technology to maximize signal, minimize noise and automate repetitive workflows.
  • Connect alerts to business risk. Help analysts understand the "why" behind investigations by linking alerts to organizational impact. Tag alerts with business priority levels, provide asset context and show how SOC investigations connect to concrete risks.
  • Integrate platforms. Reduce tool fragmentation by condensing signals, context and workflows within fewer systems. Unified security platforms minimize the manual work of piecing together investigation data across disconnected tools.
  • Deploy AI and automation strategically. AI can help companies augment their current cybersecurity workforce, expand situational awareness and accelerate mean time to action. But implementation matters, Mellon warned. It's important to evaluate investigative AI agents to determine how accurate they are, and what kind of testing and validation the vendor performs to ensure that accuracy.
  • Consider managed services. Organizations struggling with understaffing can consider outsourcing threat detection and investigation to MDR providers, reducing the load on in-house analysts.
  • Create growth opportunities. Develop clear career progression paths for SOC analysts, with continuous training and opportunities to rotate through security disciplines. Help them build expertise beyond basic triage work.
  • Empower analyst voices. Build a security culture where analysts can speak up, challenge assumptions and contribute to decisions. Provide visible leadership support during incidents and set reasonable on-call expectations.

Improving the analyst experience is a strategic investment that yields measurable returns in retention, security effectiveness and operational resilience. According to experts and practitioners, CISOs who view positive analyst experience as a security control, rather than a people perk, better position their organizations to defend against increasingly sophisticated threats.

"What has worked for us is treating analysts like elite operators, not interchangeable labor," Renfrow said. "When people feel trusted, skilled and impactful, performance rises and turnover drops."

Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer. He has pulled Token Ring, configured NetWare and been known to compile his own Linux kernel. He consults with industry and media organizations on technology issues.

Dig Deeper on Security operations and management